ssl on;
ssl_certificate my_ssl.crt;
ssl_certificate_key my_ssl.key;
ssl_session_timeout 5m;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers EECDH+aRSA+AES256:EDH+aRSA+AES256:EECDH+aRSA+AES128:EDH+aRSA+AES128;
ssl_session_cache shared:SSL:50m;
ssl_prefer_server_ciphers on;
add_header Strict-Transport-Security max-age=63072000;
Our configuration doesn't support for IE6 or IE8 on Windows XP, but that's the only downside. Also, this configuration has 100% forward secrecy :)Finally, you can get an A+ rating for free with StartSSL's free option, then using the SHA2 intermediate certificate[2]. This is what I use for my pgp keyserver[3].
[1]: https://www.ssllabs.com/ssltest/analyze.html?d=utilityapi.co...
[2]: https://www.startssl.com/certs/class1/sha2/pem/
[3]: https://www.ssllabs.com/ssltest/analyze.html?d=sks.daylightp...
You might also consider disabling server tokens to hide your Nginx version (server_tokens off;) for a bit of 'security through obscurity' and enabling SPDY (listen 443 ssl spdy;) for a performance boost.
Also worth pointing out is the upcoming Let's Encrypt project[2] which will make domain validated certificates free soon.
[0]https://www.ssllabs.com/ssltest/analyze.html?d=brossmanit.co... [1]https://wiki.mozilla.org/Security/Server_Side_TLS [2]https://letsencrypt.org/
https://wiki.mozilla.org/Security/Server_Side_TLS#Modern_com...
Do you know exactly what problem you had? It might have been unrelated to debian's presets.
EDIT: a different server with a many-times-upgraded nginx package (but same version) has no `ssl_protocols` in /etc/nginx/nginx.conf and so had SSLv3 enabled. So i agree that this can happen. In my case it's probably a consequence of silent upgrades and `Dpkg::Options::=--force-conf{def,new,old}` choosing to preserve existing config files.
The server was installed quite some time ago on Digital Ocean, it could be that I just need the most recent default Nginx configs. I'll test. Btw, I have a startssl cert, should have choosen the www subdomain though, not "mail". I'll do an apt-get purge nginx before reinstalling and than manually add back the old settings.
It's still a helpful starting point though.
https://wiki.mozilla.org/Security/Server_Side_TLS
https://mozilla.github.io/server-side-tls/ssl-config-generat...
Does merely "!EXP" not work for this? The intent behind OpenSSL's groups is to avoid exactly this problem.
"We're providing builds that are patched to have better defaults" or "We're providing a git repository / config management host / something that has an always up-to-date config snippet" might also be okay, as would "Please check back to this blog post regularly". It's the static post that makes me sad.
ssl on;
ssl_certificate ssl.nginx;
ssl_certificate_key ssl.key;
ssl_dhparam dhparam.pem;
ssl_protocols TLSv1.2;
ssl_prefer_server_ciphers on;
ssl_ciphers '!ECDHE-RSA-AES128-GCM-SHA256:!ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:!DHE-RSA-AES128-GCM-SHA256:!DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:!ECDHE-RSA-AES128-SHA256:!ECDHE-ECDSA-AES128-SHA256:!ECDHE-RSA-AES128-SHA:!ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:!DHE-RSA-AES128-SHA256:!DHE-RSA-AES128-SHA:!DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:!AES128-GCM-SHA256:AES256-GCM-SHA384:!AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA:!AES128-SHA256:!DES-CBC3-SHA:!CAMELLIA128-SHA:!DHE-RSA-CAMELLIA128-SHA';
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;
https://www.ssllabs.com/ssltest/analyze.html?d=techdroid.comstart with this.
if you don't need the compat, use a cipher suite without RC4 (as in the parent post)
add_header Strict-Transport-Security "max-age=31536000; includeSubdomains";On each server, do the following:
sudo openssl dhparam -out /etc/nginx/ssl/dhparam.pem 2048
Then in nginx.conf set: http {
ssl_dhparam /etc/nginx/ssl/dhparam.pem;
}Bonus trivia: ssh-dss (SSH DSA keys) has vaguely similar problem, which they considered fixing but decided instead to simply not repeat the mistakes when writing the SSH ECDSA spec. This is why ssh-dss keys are effectively limited to 1024-bit.
IE8 on XP is basically totally busted:
https://www.ssllabs.com/ssltest/viewClient.html?name=IE&vers...