| 
				
			 | 
			
			
				@@ -157,6 +157,9 @@ MAX_PHP_MEMORY=32 
			 | 
		
	
		
			
			| 
				157
			 | 
			
				157
			 | 
			
			
				 # default MariaDB password 
			 | 
		
	
		
			
			| 
				158
			 | 
			
				158
			 | 
			
			
				 MARIADB_PASSWORD= 
			 | 
		
	
		
			
			| 
				159
			 | 
			
				159
			 | 
			
			
				  
			 | 
		
	
		
			
			| 
				
			 | 
			
				160
			 | 
			
			
				+#list of encryption protocols 
			 | 
		
	
		
			
			| 
				
			 | 
			
				161
			 | 
			
			
				+SSL_PROTOCOLS="TLSv1 TLSv1.1 TLSv1.2" 
			 | 
		
	
		
			
			| 
				
			 | 
			
				162
			 | 
			
			
				+ 
			 | 
		
	
		
			
			| 
				160
			 | 
			
				163
			 | 
			
			
				 # list of ciphers to use 
			 | 
		
	
		
			
			| 
				161
			 | 
			
				164
			 | 
			
			
				 SSL_CIPHERS="EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA" 
			 | 
		
	
		
			
			| 
				162
			 | 
			
				165
			 | 
			
			
				  
			 | 
		
	
	
		
			
			| 
				
			 | 
			
			
				@@ -1636,7 +1639,7 @@ function install_owncloud { 
			 | 
		
	
		
			
			| 
				1636
			 | 
			
				1639
			 | 
			
			
				  
			 | 
		
	
		
			
			| 
				1637
			 | 
			
				1640
			 | 
			
			
				   echo '    ssl_session_timeout 5m;' >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1638
			 | 
			
				1641
			 | 
			
			
				   echo '    ssl_prefer_server_ciphers on;' >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1639
			 | 
			
				
			 | 
			
			
				-  echo '    ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive' >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				
			 | 
			
				1642
			 | 
			
			
				+  echo '    ssl_protocols $SSL_PROTOCOLS; # not possible to do exclusive' >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1640
			 | 
			
				1643
			 | 
			
			
				   echo "    ssl_ciphers '$SSL_CIPHERS';" >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1641
			 | 
			
				1644
			 | 
			
			
				   echo '    add_header X-Frame-Options DENY;' >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1642
			 | 
			
				1645
			 | 
			
			
				   echo '    add_header X-Content-Type-Options nosniff;' >> /etc/nginx/sites-available/$OWNCLOUD_DOMAIN_NAME 
			 | 
		
	
	
		
			
			| 
				
			 | 
			
			
				@@ -1987,7 +1990,7 @@ function install_wiki { 
			 | 
		
	
		
			
			| 
				1987
			 | 
			
				1990
			 | 
			
			
				   echo '    ssl_session_timeout 5m;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1988
			 | 
			
				1991
			 | 
			
			
				   echo '    ssl_prefer_server_ciphers on;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1989
			 | 
			
				1992
			 | 
			
			
				   echo '    ssl_session_cache  builtin:1000  shared:SSL:10m;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1990
			 | 
			
				
			 | 
			
			
				-  echo '    ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				
			 | 
			
				1993
			 | 
			
			
				+  echo '    ssl_protocols $SSL_PROTOCOLS; # not possible to do exclusive' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1991
			 | 
			
				1994
			 | 
			
			
				   echo "    ssl_ciphers '$SSL_CIPHERS';" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1992
			 | 
			
				1995
			 | 
			
			
				   echo '    add_header X-Frame-Options DENY;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				1993
			 | 
			
				1996
			 | 
			
			
				   echo '    add_header X-Content-Type-Options nosniff;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME 
			 | 
		
	
	
		
			
			| 
				
			 | 
			
			
				@@ -2364,7 +2367,7 @@ quit" > $INSTALL_DIR/batch.sql 
			 | 
		
	
		
			
			| 
				2364
			 | 
			
				2367
			 | 
			
			
				   echo '    ssl_session_timeout 5m;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2365
			 | 
			
				2368
			 | 
			
			
				   echo '    ssl_prefer_server_ciphers on;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2366
			 | 
			
				2369
			 | 
			
			
				   echo '    ssl_session_cache  builtin:1000  shared:SSL:10m;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2367
			 | 
			
				
			 | 
			
			
				-  echo '    ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				
			 | 
			
				2370
			 | 
			
			
				+  echo '    ssl_protocols $SSL_PROTOCOLS; # not possible to do exclusive' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2368
			 | 
			
				2371
			 | 
			
			
				   echo "    ssl_ciphers '$SSL_CIPHERS';" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2369
			 | 
			
				2372
			 | 
			
			
				   echo '    add_header X-Frame-Options DENY;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2370
			 | 
			
				2373
			 | 
			
			
				   echo '    add_header X-Content-Type-Options nosniff;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME 
			 | 
		
	
	
		
			
			| 
				
			 | 
			
			
				@@ -2573,7 +2576,7 @@ quit" > $INSTALL_DIR/batch.sql 
			 | 
		
	
		
			
			| 
				2573
			 | 
			
				2576
			 | 
			
			
				   echo '    ssl_session_timeout 5m;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2574
			 | 
			
				2577
			 | 
			
			
				   echo '    ssl_prefer_server_ciphers on;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2575
			 | 
			
				2578
			 | 
			
			
				   echo '    ssl_session_cache  builtin:1000  shared:SSL:10m;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2576
			 | 
			
				
			 | 
			
			
				-  echo '    ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				
			 | 
			
				2579
			 | 
			
			
				+  echo '    ssl_protocols $SSL_PROTOCOLS; # not possible to do exclusive' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2577
			 | 
			
				2580
			 | 
			
			
				   echo "    ssl_ciphers '$SSL_CIPHERS';" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2578
			 | 
			
				2581
			 | 
			
			
				   echo '    add_header X-Frame-Options DENY;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME 
			 | 
		
	
		
			
			| 
				2579
			 | 
			
				2582
			 | 
			
			
				   echo '    add_header X-Content-Type-Options nosniff;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME 
			 |