summaryrefslogtreecommitdiff
path: root/roles/nginx/base/files/snippets/tls.conf
blob: 9c4f7853808f8f13ab41f40a1716640d6244d6ba (plain) (blame)
1
2
3
4
5
6
7
8
9
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE+CHACHA20:ECDHE+AESGCM:DHE+CHACHA20:DHE+AESGCM:ECDHE+AES256:DHE+AES256:ECDHE+AES128:DHE+AES128:!ADH:!AECDH:!MD5:!SHA;
ssl_prefer_server_ciphers on;

ssl_dhparam /etc/ssl/dhparams.pem;

ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;
ssl_session_tickets off;