User Tools

Site Tools


nginx-sample-configs

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
nginx-sample-configs [2023/03/20 17:38]
rklein created
nginx-sample-configs [2024/03/11 16:37] (current)
rklein
Line 21: Line 21:
  
 </code> </code>
 +file kc-certs.conf
 +<code>
 +ssl_certificate /etc/ssl/private/kc-server.crt;
 +ssl_certificate_key /etc/ssl/private/kc-server.key;
 +</code>
 +file kc-ssl-params.conf
 +<code>
 +# should be also TLSv1.3 if possible
 +ssl_protocols TLSv1.2;
 +ssl_prefer_server_ciphers on;
 +ssl_dhparam /etc/nginx/dhparam.pem; 
 +ssl_ciphers EECDH+AESGCM:EDH+AESGCM;
 +ssl_ecdh_curve secp384r1;
 +ssl_session_timeout  10m;
 +ssl_session_cache shared:SSL:10m;
 +ssl_session_tickets off;
 +ssl_stapling off;
 +ssl_stapling_verify off;
 +# replace follwing with local dns
 +resolver 8.8.8.8 valid=300s;
 +resolver_timeout 5s;
 +# Disable strict transport security for now. You can uncomment the following
 +# line if you understand the implications.
 +#add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
 +add_header X-Frame-Options DENY;
 +add_header X-Content-Type-Options nosniff;
 +add_header X-XSS-Protection "1; mode=block";
 +
 +</code>
 +
 +----
 +
 +ansible role for adding client certs to firefox/chrome on the clients
 +
 +https://warlord0blog.wordpress.com/2020/03/04/ansible-and-client-certificates/
nginx-sample-configs.1679330292.txt.gz · Last modified: 2023/03/20 17:38 by rklein