Pārlūkot izejas kodu

web: enable ssl_protocol TLSv1.2 only

netaskd 6 gadi atpakaļ
vecāks
revīzija
7c6c6bcefb
1 mainītis faili ar 1 papildinājumiem un 1 dzēšanām
  1. 1 1
      web/rootfs/defaults/ssl.conf

+ 1 - 1
web/rootfs/defaults/ssl.conf

@@ -16,6 +16,6 @@ ssl_certificate_key /config/keys/cert.key;
 {{ end }}
 {{ end }}
 
 
 # protocols
 # protocols
-ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
+ssl_protocols TLSv1.2;
 ssl_prefer_server_ciphers on;
 ssl_prefer_server_ciphers on;
 ssl_ciphers ECDH+AESGCM:ECDH+CHACHA20:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS;
 ssl_ciphers ECDH+AESGCM:ECDH+CHACHA20:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS;