YunoHost / packages_old

[not used anymore] YunoHost Debian package sources
http://yunohost.org
8 stars 7 forks source link

Update nginx security #46

Closed Roust closed 9 years ago

Roust commented 9 years ago

Update nginx cipher suites for more security Update HSTS configuration syntax

Roust commented 9 years ago

sry je passe en FR, mon niveau d'anglais est trop mauvais pour m'explimer.

Avec HIGH, on ne force pas l'utilisation de Diffie Hellman (DHE, ECDHE) et on utilise CAMELIA que je ne connais pas, donc auquel je n'ai pas complètement confiance. D'où cette proposition assez stricte, j'avoue.

taziden commented 9 years ago

Your proposal seems good to me, anyway. Let's increase YNH security ;)

jeromelebleu commented 9 years ago

Hi!

This repo is not used anymore. Please use this one for your pull requests regarding nginx: https://github.com/YunoHost/yunohost-config-nginx

And I agree that we should set a proper ssl_ciphers such as those suggested by https://mozilla.github.io/server-side-tls/ssl-config-generator/