diff --git a/nginx/nginx/conf_split/ssl_protocol.conf b/nginx/nginx/conf_split/ssl_protocol.conf index df48bac..fd950e5 100644 --- a/nginx/nginx/conf_split/ssl_protocol.conf +++ b/nginx/nginx/conf_split/ssl_protocol.conf @@ -1,10 +1,9 @@ -# https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP - ssl_session_cache shared:SSL:10m; ssl_protocols TLSv1.3 TLSv1.2; -# A+ en max veilig: -ssl_ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305"; +# A+ met meer compatibiliteit: +ssl_ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256"; + ssl_prefer_server_ciphers on; ssl_stapling on;