SSL stapling can reduce the overhead as well, simple nginx config:
http {
ssl_stapling on;
ssl_stapling_verify on;
ssl_trusted_certificate /etc/nginx/ssl/stapling.trusted.crt;
resolver 8.8.4.4 8.8.8.8 valid=300s;
resolver_timeout 15s;
}
We https://commando.io use GoDaddy SSL (sigh, face-palm), so the contents of stapling.trusted.crt is: http://pastebin.com/0H0i09Pn