更改

跳到导航 跳到搜索
添加620字节 、 2017年7月13日 (四) 13:01
更新 cipher 。
<code>/etc/nginx/conf.d/ssl_security.conf</code><syntaxhighlight lang="nginx">
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers ECDH+AESGCMECDHE-ECDSA-CHACHA20-POLY1305:ECDH+ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:ECDH+DHE-RSA-AES128-SHA256:DHE-RSA+AESGCM-AES128-SHA:DHE-RSA+AES-AES256-SHA256:!RC4DHE-RSA-AES256-SHA:!aNULLECDHE-ECDSA-DES-CBC3-SHA:!eNULLECDHE-RSA-DES-CBC3-SHA:!LOWEDH-RSA-DES-CBC3-SHA:!3DESAES128-GCM-SHA256:!MD5AES256-GCM-SHA384:!EXPAES128-SHA256:!PSKAES256-SHA256:!SRPAES128-SHA:!DSSAES256-SHA:!ADHDES-CBC3-SHA:!AECDHDSS;
ssl_prefer_server_ciphers on;
ssl_dhparam /etc/nginx/ssl/dhparams.pem;# Run `openssl dhparam -out /etc/nginx/ssl/dhparams.pem 2048` beforehead
ssl_session_cache shared:SSL:10m;

导航菜单