From 5db4e58e16cde6d5dc6f8da9bf68db320f1ecb25 Mon Sep 17 00:00:00 2001 From: Jimmy Zelinskie Date: Fri, 22 May 2015 13:54:43 -0400 Subject: [PATCH] nginx: SSL config into server-base.conf --- conf/nginx.conf | 30 ++---------------------------- conf/server-base.conf | 14 ++++++++++++++ 2 files changed, 16 insertions(+), 28 deletions(-) diff --git a/conf/nginx.conf b/conf/nginx.conf index ca872b224..860ddae51 100644 --- a/conf/nginx.conf +++ b/conf/nginx.conf @@ -13,22 +13,9 @@ http { listen 443 default; ssl on; - ssl_certificate ./stack/ssl.cert; - ssl_certificate_key ./stack/ssl.key; - - ssl_ciphers "ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"; - - ssl_protocols TLSv1 TLSv1.1 TLSv1.2; - ssl_session_cache shared:SSL:10m; - ssl_session_timeout 5m; - - ssl_stapling on; - ssl_stapling_verify on; - - ssl_prefer_server_ciphers on; + # This header must be set only for HTTPS add_header Strict-Transport-Security "max-age=63072000; preload"; - add_header X-Frame-Options DENY; } server { @@ -38,21 +25,8 @@ http { listen 8443 default proxy_protocol; ssl on; - ssl_certificate ./stack/ssl.cert; - ssl_certificate_key ./stack/ssl.key; - - ssl_ciphers "ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"; - - ssl_protocols TLSv1 TLSv1.1 TLSv1.2; - ssl_session_cache shared:SSL:10m; - ssl_session_timeout 5m; - - ssl_stapling on; - ssl_stapling_verify on; - - ssl_prefer_server_ciphers on; + # This header must be set only for HTTPS add_header Strict-Transport-Security "max-age=63072000; preload"; - add_header X-Frame-Options DENY; } } diff --git a/conf/server-base.conf b/conf/server-base.conf index 3853fbccf..1ff261e6b 100644 --- a/conf/server-base.conf +++ b/conf/server-base.conf @@ -8,6 +8,20 @@ if ($args ~ "_escaped_fragment_") { rewrite ^ /snapshot$uri; } +# SSL +ssl_certificate ./stack/ssl.cert; +ssl_certificate_key ./stack/ssl.key; +ssl_ciphers "ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"; +ssl_protocols TLSv1 TLSv1.1 TLSv1.2; +ssl_session_cache shared:SSL:10m; +ssl_session_timeout 5m; +ssl_stapling on; +ssl_stapling_verify on; +ssl_prefer_server_ciphers on; +add_header X-Frame-Options DENY; + + +# Proxy Headers proxy_set_header X-Forwarded-For $proper_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Host $http_host;