summaryrefslogtreecommitdiffstats
path: root/roles/common-web
diff options
context:
space:
mode:
Diffstat (limited to 'roles/common-web')
-rw-r--r--roles/common-web/files/etc/nginx/ssl/config1
1 files changed, 1 insertions, 0 deletions
diff --git a/roles/common-web/files/etc/nginx/ssl/config b/roles/common-web/files/etc/nginx/ssl/config
index 7deef29..26a64f4 100644
--- a/roles/common-web/files/etc/nginx/ssl/config
+++ b/roles/common-web/files/etc/nginx/ssl/config
@@ -12,6 +12,7 @@ ssl_session_cache shared:SSL:5m;
# other weaknesses.
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers HIGH:!SSLv2:!aNULL:!eNULL:!3DES:!MD5:@STRENGTH;
+ssl_dhparam /etc/ssl/private/dhparams.pem;
ssl_prefer_server_ciphers on;
# Strict Transport Security header for enhanced security. See