diff options
Diffstat (limited to 'examples/nginx-alpine-ssl/default.conf')
| -rw-r--r-- | examples/nginx-alpine-ssl/default.conf | 25 |
1 files changed, 25 insertions, 0 deletions
diff --git a/examples/nginx-alpine-ssl/default.conf b/examples/nginx-alpine-ssl/default.conf index 22db0df..c3131f0 100644 --- a/examples/nginx-alpine-ssl/default.conf +++ b/examples/nginx-alpine-ssl/default.conf | |||
| @@ -3,8 +3,33 @@ server { | |||
| 3 | listen [::]:80 default_server; | 3 | listen [::]:80 default_server; |
| 4 | listen 443 ssl http2 default_server; | 4 | listen 443 ssl http2 default_server; |
| 5 | listen [::]:443 ssl http2 default_server; | 5 | listen [::]:443 ssl http2 default_server; |
| 6 | |||
| 7 | # SSL configuration | ||
| 8 | # SSL cert/key files | ||
| 6 | ssl_certificate /etc/ssl/certs/nginx-selfsigned.crt; | 9 | ssl_certificate /etc/ssl/certs/nginx-selfsigned.crt; |
| 7 | ssl_certificate_key /etc/ssl/private/nginx-selfsigned.key; | 10 | ssl_certificate_key /etc/ssl/private/nginx-selfsigned.key; |
| 11 | # For production regenerate this dhparam key by running: | ||
| 12 | # $> openssl dhparam -out dhparam.pem 4096 | ||
| 13 | ssl_dhparam /etc/ssl/private/dhparam.pem; | ||
| 14 | |||
| 15 | # SSL ciphers/protocols | ||
| 16 | ssl_protocols TLSv1.3 TLSv1.2; | ||
| 17 | ssl_prefer_server_ciphers on; | ||
| 18 | ssl_ecdh_curve secp521r1:secp384r1; | ||
| 19 | ssl_ciphers EECDH+AESGCM:EECDH+AES256; | ||
| 20 | |||
| 21 | # SSL misc | ||
| 22 | ssl_session_cache shared:TLS:2m; | ||
| 23 | ssl_buffer_size 4k; | ||
| 24 | |||
| 25 | # OCSP stapling | ||
| 26 | ssl_stapling on; | ||
| 27 | ssl_stapling_verify on; | ||
| 28 | resolver 1.1.1.1 1.0.0.1 [2606:4700:4700::1111] [2606:4700:4700::1001]; # Cloudflare | ||
| 29 | |||
| 30 | # Set HSTS to 365 days | ||
| 31 | # Note: Activate this on production usage | ||
| 32 | #add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload' always; | ||
| 8 | 33 | ||
| 9 | location /.well-known/webfinger { | 34 | location /.well-known/webfinger { |
| 10 | proxy_http_version 1.1; | 35 | proxy_http_version 1.1; |