From 36c8b90c4b486f6649a65c0bd4f36e0f67a750e2 Mon Sep 17 00:00:00 2001 From: Franziska Kunsmann Date: Mon, 1 Jun 2020 11:01:00 +0200 Subject: [PATCH] bundles/nginx: switch to TLS 1.2 and 1.3 only --- bundles/nginx/files/site_template | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/bundles/nginx/files/site_template b/bundles/nginx/files/site_template index 6517ce0..3c3064c 100644 --- a/bundles/nginx/files/site_template +++ b/bundles/nginx/files/site_template @@ -8,9 +8,9 @@ server { ssl_certificate /var/lib/dehydrated/certs/${domain}/fullchain.pem; ssl_certificate_key /var/lib/dehydrated/certs/${domain}/privkey.pem; - ssl_protocols TLSv1 TLSv1.1 TLSv1.2; - ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'; ssl_dhparam /etc/ssl/certs/dhparam.pem; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384; ssl_prefer_server_ciphers on; ssl_session_cache shared:SSL:10m; ssl_stapling on;