SSL Ding
Dieser Commit ist enthalten in:
@@ -12,9 +12,11 @@ COPY nginx.conf /etc/nginx/nginx.conf
|
||||
# SSL-Zertifikate kopieren
|
||||
COPY ssl/fullchain.pem /etc/nginx/ssl/
|
||||
COPY ssl/privkey.pem /etc/nginx/ssl/
|
||||
COPY ssl/dhparam.pem /etc/nginx/ssl/
|
||||
|
||||
# Berechtigungen setzen
|
||||
RUN chmod 600 /etc/nginx/ssl/privkey.pem
|
||||
RUN chmod 644 /etc/nginx/ssl/dhparam.pem
|
||||
|
||||
EXPOSE 80 443
|
||||
|
||||
|
||||
@@ -3,10 +3,24 @@ events {
|
||||
}
|
||||
|
||||
http {
|
||||
# SSL-Einstellungen
|
||||
# Moderne SSL-Einstellungen für maximale Sicherheit
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
ssl_ciphers HIGH:!aNULL:!MD5;
|
||||
ssl_prefer_server_ciphers on;
|
||||
ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384';
|
||||
ssl_prefer_server_ciphers off;
|
||||
|
||||
# SSL Session Einstellungen
|
||||
ssl_session_timeout 1d;
|
||||
ssl_session_cache shared:SSL:10m;
|
||||
ssl_session_tickets off;
|
||||
|
||||
# OCSP Stapling
|
||||
ssl_stapling on;
|
||||
ssl_stapling_verify on;
|
||||
resolver 8.8.8.8 8.8.4.4 valid=300s;
|
||||
resolver_timeout 5s;
|
||||
|
||||
# DH parameters für Perfect Forward Secrecy
|
||||
ssl_dhparam /etc/nginx/ssl/dhparam.pem;
|
||||
|
||||
# Admin Panel
|
||||
server {
|
||||
|
||||
8
v2_nginx/ssl/dhparam.pem
Normale Datei
8
v2_nginx/ssl/dhparam.pem
Normale Datei
@@ -0,0 +1,8 @@
|
||||
-----BEGIN DH PARAMETERS-----
|
||||
MIIBCAKCAQEA3UNy/iKdzjC78mqJ39+w9uotmnI9yglBXI7N/+t42KSX19TCsE5I
|
||||
Dw+bToiUJHAqu+BG2ZNZhvB4+NStFVkPAnEm1I4UOXR9skWgOqwhqotPUpHduOLC
|
||||
wooKpMUe26dGszM/tQduYoupzfwbVU8ENamLKXOqrzz/CBmo8r1uvPNAM0AljVSO
|
||||
mOCMIu8C0KBm5u6I1USjp2xNi8xTeasBsLc1iRbxKLKNLNQW4dL9fO7NQIDPghOi
|
||||
5YTMiNoO14TsCrzzPIF4AFWnBW2XTGwYlx5CuAR/ZUmbzdEVD7ACka2MP6PSnjLK
|
||||
SIjlM7dTQQHASm81JazbNFqYBBk69/GuZwIBAg==
|
||||
-----END DH PARAMETERS-----
|
||||
In neuem Issue referenzieren
Einen Benutzer sperren