Last active
August 29, 2015 14:20
-
-
Save vicendominguez/b048ebfee1b4c36dfd72 to your computer and use it in GitHub Desktop.
my Global/site_sslgzip.conf for nginx ("A" in sslabs)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#Avoid Poodle | |
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; | |
#Enable ciphers | |
ssl_prefer_server_ciphers on; | |
ssl_session_cache shared:SSL:10m; | |
ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA'; | |
#ssl_ciphers 'AES128+EECDH:AES128+EDH:!aNULL'; | |
resolver 8.8.4.4 8.8.8.8 valid=300s; | |
resolver_timeout 10s; | |
# Avoid Logjam | |
ssl_dhparam /etc/ssl/certs/dhparams.pem; | |
# enable gzip compression | |
gzip on; | |
gzip_http_version 1.0; | |
gzip_disable "msie6"; | |
gzip_min_length 1100; | |
gzip_buffers 4 32k; | |
gzip_proxied any; | |
gzip_types text/plain application/javascript application/x-javascript text/javascript text/xml text/css; | |
gzip_vary on; | |
# end gzip configuration | |
#you-da-man-headers | |
add_header Strict-Transport-Security max-age=63072000; | |
add_header X-Frame-Options DENY; | |
add_header X-Content-Type-Options nosniff; |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment