summaryrefslogtreecommitdiff
path: root/roles/nginx/base/files/snippets/tls.conf
blob: 46d43ecb2cb4f502b5167050a33a6a16462b58e6 (plain) (blame)
1
2
3
4
5
6
7
8
9
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES128:!RSA:!ADH:!AECDH:!MD5;
ssl_prefer_server_ciphers on;

ssl_dhparam /etc/ssl/dhparams.pem;

ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;
ssl_session_tickets off;