Skip to content

Latest commit

 

History

History
21 lines (14 loc) · 613 Bytes

File metadata and controls

21 lines (14 loc) · 613 Bytes

This configuration gives A+ on ssllabs.com test and A+ on securityheaders.com

ssllabs

###Features :

  • TLS configuration using ca-intermediate and fullchain files
  • OCSP Must Staple / OCSP stapling enabled
  • Modern ciphersuites (TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256 is prefered)
  • Security headers enabled :
    • Gives an example of Content-Security-Policy (CSP)
    • X-Frame Options
    • X-Content-Type Options
    • X-XSS Protection
    • Referrer Policy
    • HSTS

nginx.conf