web: enable ssl_protocol TLSv1.2 only

This commit is contained in:
netaskd
2018-12-04 21:56:09 +03:00
committed by Saúl Ibarra Corretgé
parent 4b88a28fcc
commit 7c6c6bcefb

View File

@@ -16,6 +16,6 @@ ssl_certificate_key /config/keys/cert.key;
{{ end }} {{ end }}
# protocols # protocols
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_protocols TLSv1.2;
ssl_prefer_server_ciphers on; ssl_prefer_server_ciphers on;
ssl_ciphers ECDH+AESGCM:ECDH+CHACHA20:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS; ssl_ciphers ECDH+AESGCM:ECDH+CHACHA20:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS;