From 581d2fa4fcc36d3ebeb0e80e2c4b0d8dd4917092 Mon Sep 17 00:00:00 2001 From: Jimmy Zelinskie Date: Fri, 22 May 2015 16:25:28 -0400 Subject: [PATCH] nginx: move ssl config out of server-base --- conf/nginx.conf | 11 +++++++++++ conf/server-base.conf | 11 +---------- 2 files changed, 12 insertions(+), 10 deletions(-) diff --git a/conf/nginx.conf b/conf/nginx.conf index 860ddae51..5e49b1977 100644 --- a/conf/nginx.conf +++ b/conf/nginx.conf @@ -7,6 +7,16 @@ http { include hosted-http-base.conf; include rate-limiting.conf; + ssl_certificate ./stack/ssl.cert; + ssl_certificate_key ./stack/ssl.key; + ssl_ciphers "ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_session_cache shared:SSL:10m; + ssl_session_timeout 5m; + ssl_stapling on; + ssl_stapling_verify on; + ssl_prefer_server_ciphers on; + server { include server-base.conf; @@ -16,6 +26,7 @@ http { # This header must be set only for HTTPS add_header Strict-Transport-Security "max-age=63072000; preload"; + } server { diff --git a/conf/server-base.conf b/conf/server-base.conf index 1ff261e6b..bfa6c012f 100644 --- a/conf/server-base.conf +++ b/conf/server-base.conf @@ -8,16 +8,7 @@ if ($args ~ "_escaped_fragment_") { rewrite ^ /snapshot$uri; } -# SSL -ssl_certificate ./stack/ssl.cert; -ssl_certificate_key ./stack/ssl.key; -ssl_ciphers "ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"; -ssl_protocols TLSv1 TLSv1.1 TLSv1.2; -ssl_session_cache shared:SSL:10m; -ssl_session_timeout 5m; -ssl_stapling on; -ssl_stapling_verify on; -ssl_prefer_server_ciphers on; +# Disable the ability to be embedded into iframes add_header X-Frame-Options DENY;