Skip to content

Instantly share code, notes, and snippets.

@michiel
Created August 4, 2016 19:05
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save michiel/8cbd7bb302421f8eaad0bbb449fc8957 to your computer and use it in GitHub Desktop.
Save michiel/8cbd7bb302421f8eaad0bbb449fc8957 to your computer and use it in GitHub Desktop.
##
# SSL Settings
##
# # openssl dhparam 4096 -out /etc/nginx/dh4096.pem
ssl_dhparam /etc/nginx/dh4096.pem;
ssl_protocols TLSv1.2;
# ssl_ecdh_curve secp521r1;
ssl_ecdh_curve secp384r1;
# nginx 1.11.0+
# ssl_ecdh_curve sect571r1:secp521r1:brainpoolP512r1:secp384r1;
ssl_ciphers EECDH+AESGCM:EECDH+AES;
# ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA;
# ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;
ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 5m;
ssl_session_tickets off;
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment