NGINX
NGINX Trac
3rd Party Modules
Security Advisories
CHANGES
OpenResty
ngx_lua
Tengine
在线学习资源
NGINX 开发从入门到精通
NGINX Modules
ngx_echo
ondeay
V2EX  ›  NGINX

nginx ssl_protocols 配置问题请教

  •  
  •   ondeay · Oct 20, 2023 · 2143 views
    This topic created in 940 days ago, the information mentioned may be changed or developed.
    修改 nginx ssl_protocols 配置只支持 TLSv1.2 ,但是检查出域名还是有 TLSv1.1 ,配置如下,该配置文件还有很多其它域名配置

    listen 443 ssl;
    server_name XXX;
    allow all;
    ssl_certificate /etc/nginx/cert/xxx.com.pem;
    ssl_certificate_key /etc/nginx/cert/xxx.com.key;
    ssl_session_timeout 5m;
    ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4:!3DES;
    #ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
    ssl_protocols TLSv1.2;
    ssl_prefer_server_ciphers on;
    4 replies    2023-10-20 16:12:36 +08:00
    Girls
        1
    Girls  
       Oct 20, 2023 via iPhone
    其它域名配置也要同步改
    ysc3839
        2
    ysc3839  
       Oct 20, 2023 via Android
    ssl 配置建议放在 http 块里面,server 块里只配置证书
    ondeay
        3
    ondeay  
    OP
       Oct 20, 2023
    ssl_ciphers 密码套件去掉 ECDHE:ECDH:AES:HIGH 之后,TLSv1 TLSv1.1 就检测不到了
    ysc3839
        4
    ysc3839  
       Oct 20, 2023 via Android
    @ondeay
    ssl_ciphers 的配置可以参考 https://ssl-config.mozilla.org/
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   858 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 30ms · UTC 21:47 · PVG 05:47 · LAX 14:47 · JFK 17:47
    ♥ Do have faith in what you're doing.