|
@@ -2546,7 +2546,10 @@ server {
|
2546
|
2546
|
ssl_prefer_server_ciphers on;
|
2547
|
2547
|
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive
|
2548
|
2548
|
ssl_ciphers 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA';
|
2549
|
|
- add_header Strict-Transport-Security max-age=15768000; # six months
|
|
2549
|
+ add_header Strict-Transport-Security "max-age=0;";
|
|
2550
|
+ # Only uncomment one of the Strict-Transport-Security entries if you are
|
|
2551
|
+ # not using a self-signed certificate
|
|
2552
|
+ # add_header Strict-Transport-Security max-age=15768000; # six months
|
2550
|
2553
|
# use this only if all subdomains support HTTPS!
|
2551
|
2554
|
# add_header Strict-Transport-Security "max-age=15768000; includeSubDomains";
|
2552
|
2555
|
|
|
@@ -4987,9 +4990,12 @@ server {
|
4987
|
4990
|
ssl_prefer_server_ciphers on;
|
4988
|
4991
|
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive
|
4989
|
4992
|
ssl_ciphers 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA';
|
4990
|
|
- #add_header Strict-Transport-Security max-age=15768000; # six months
|
|
4993
|
+ add_header Strict-Transport-Security "max-age=0;";
|
|
4994
|
+ # Only uncomment one of the Strict-Transport-Security entries if you are
|
|
4995
|
+ # not using a self-signed certificate
|
|
4996
|
+ # add_header Strict-Transport-Security max-age=15768000; # six months
|
4991
|
4997
|
# use this only if all subdomains support HTTPS!
|
4992
|
|
- add_header Strict-Transport-Security "max-age=15768000; includeSubDomains";
|
|
4998
|
+ # add_header Strict-Transport-Security "max-age=15768000; includeSubDomains";
|
4993
|
4999
|
|
4994
|
5000
|
client_max_body_size 6m;
|
4995
|
5001
|
|
|
@@ -5527,7 +5533,10 @@ server {
|
5527
|
5533
|
ssl_prefer_server_ciphers on;
|
5528
|
5534
|
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive
|
5529
|
5535
|
ssl_ciphers 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA';
|
5530
|
|
- add_header Strict-Transport-Security max-age=15768000; # six months
|
|
5536
|
+ add_header Strict-Transport-Security "max-age=0;";
|
|
5537
|
+ # Only uncomment one of the Strict-Transport-Security entries if you are
|
|
5538
|
+ # not using a self-signed certificate
|
|
5539
|
+ # add_header Strict-Transport-Security max-age=15768000; # six months
|
5531
|
5540
|
# use this only if all subdomains support HTTPS!
|
5532
|
5541
|
# add_header Strict-Transport-Security "max-age=15768000; includeSubDomains";
|
5533
|
5542
|
|
|
@@ -7212,9 +7221,12 @@ server {
|
7212
|
7221
|
ssl_prefer_server_ciphers on;
|
7213
|
7222
|
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive
|
7214
|
7223
|
ssl_ciphers 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA';
|
7215
|
|
- #add_header Strict-Transport-Security max-age=15768000; # six months
|
|
7224
|
+ add_header Strict-Transport-Security "max-age=0;";
|
|
7225
|
+ # Only uncomment one of the Strict-Transport-Security entries if you are
|
|
7226
|
+ # not using a self-signed certificate
|
|
7227
|
+ # add_header Strict-Transport-Security max-age=15768000; # six months
|
7216
|
7228
|
# use this only if all subdomains support HTTPS!
|
7217
|
|
- add_header Strict-Transport-Security "max-age=15768000; includeSubDomains";
|
|
7229
|
+ # add_header Strict-Transport-Security "max-age=15768000; includeSubDomains";
|
7218
|
7230
|
|
7219
|
7231
|
client_max_body_size 6m;
|
7220
|
7232
|
|