Build a custom dhparam file once for nginx and include it as default
This commit is contained in:
@@ -26,6 +26,12 @@ esac
|
||||
|
||||
chmod 0440 /etc/sudoers.d/dokku-nginx
|
||||
|
||||
# if dhparam.pem has not been created, create it the first time
|
||||
if [[ ! -f /etc/nginx/dhparam.pem ]]; then
|
||||
openssl dhparam -out /etc/nginx/dhparam.pem 2048
|
||||
chown root:root /etc/nginx/dhparam.pem
|
||||
fi
|
||||
|
||||
# if dokku.conf has not been created, create it
|
||||
if [[ ! -f /etc/nginx/conf.d/dokku.conf ]]; then
|
||||
mkdir -p /etc/nginx/conf.d
|
||||
@@ -40,6 +46,7 @@ ssl_session_cache shared:SSL:20m;
|
||||
ssl_session_timeout 1d;
|
||||
ssl_session_tickets on;
|
||||
|
||||
ssl_dhparam /etc/nginx/dhparam.pem;
|
||||
ssl_ciphers ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS;
|
||||
|
||||
EOF
|
||||
|
||||
Reference in New Issue
Block a user