mirror of
				https://github.com/mail-in-a-box/mailinabox.git
				synced 2025-10-25 18:00:54 +00:00 
			
		
		
		
	Update for better PCI compliance
We should disable TLSv1 completely for PCI compliance. Also, update list of accepted ciphers to be more compliant with PCI and HIPAA/NIST.
This commit is contained in:
		
							parent
							
								
									cb162da5fe
								
							
						
					
					
						commit
						f92d1e48ec
					
				| @ -27,12 +27,12 @@ | ||||
| #  | ||||
| # Reference client: https://www.ssllabs.com/ssltest/analyze.html | ||||
| ssl_prefer_server_ciphers on; | ||||
| ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS'; | ||||
| ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256'; | ||||
| 
 | ||||
| # Cut out (the old, broken) SSLv3 entirely.  | ||||
| # This **excludes IE6 users** and (apparently) Yandexbot. | ||||
| # Just comment out if you need to support IE6, bless your soul. | ||||
| ssl_protocols TLSv1.2 TLSv1.1 TLSv1; | ||||
| ssl_protocols TLSv1.2 TLSv1.1; | ||||
| 
 | ||||
| # Turn on session resumption, using a cache shared across nginx processes, | ||||
| # as recommended by http://nginx.org/en/docs/http/configuring_https_servers.html | ||||
|  | ||||
		Loading…
	
		Reference in New Issue
	
	Block a user