cmc/dotfiles

Using GNU Stow to manage my dotfiles. config dotfiles macos stow

Commit 565e8c2db8

565e8c2db8e79197ffb49554a70e209fa1ead16e

parent: 6783d54468

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-03 05:31 UTC

chore: cleanup

Layout: unified · split

linux/nginx/etc/nginx/conf.d/cleberg.dev.conf +1 −1
@@ -1,7 +1,7 @@
1 1
2 2
3server { 3server {
4 listen 10010; 4 listen 127.0.0.1:10010;
5 server_name cleberg.dev; 5 server_name cleberg.dev;
6 root /var/www/cleberg.dev/; 6 root /var/www/cleberg.dev/;
7 include custom.d/basic.conf; 7 include custom.d/basic.conf;
linux/nginx/etc/nginx/conf.d/cleberg.io.conf deleted −1
@@ -1 +0,0 @@
1
linux/nginx/etc/nginx/conf.d/cleberg.net.conf +7 −15
@@ -1,11 +1,14 @@
1server { 1server {
2 listen 10011; 2 listen 127.0.0.1:10011;
3 server_name cleberg.net paske4urhs6nttrtlkuwa5cowum3fjkc6yv6kl4ncx3mjxcd77764nqd.onion; 3 server_name cleberg.net paske4urhs6nttrtlkuwa5cowum3fjkc6yv6kl4ncx3mjxcd77764nqd.onion;
4 error_log /var/log/nginx/cleberg.net.error.log; 4
5 # No per-vhost error_log: it overrode the global "off" and wrote visitor
6 # IPs to disk.
7
8 # basic.conf now carries HSTS + Permissions-Policy. CSP stays explicit --
9 # the shared policy is written for this vhost (it allows img.cleberg.net).
5 include custom.d/basic.conf; 10 include custom.d/basic.conf;
6 include custom.d/security/strict-transport-security.conf;
7 include custom.d/security/content-security-policy.conf; 11 include custom.d/security/content-security-policy.conf;
8 include custom.d/security/permissions-policy.conf;
9 root /var/www/cleberg.net/; 12 root /var/www/cleberg.net/;
10 include custom.d/redirects/blog.conf; 13 include custom.d/redirects/blog.conf;
11 port_in_redirect off; 14 port_in_redirect off;
@@ -48,14 +51,3 @@ server {
48 try_files $uri =404; 51 try_files $uri =404;
49 } 52 }
50} 53}
51
52server {
53 listen 10012;
54 server_name hutch.cleberg.net;
55 include custom.d/basic.conf;
56 include custom.d/security/strict-transport-security.conf;
57 include custom.d/security/content-security-policy.conf;
58 include custom.d/security/permissions-policy.conf;
59 location = /privacy.html { return 301 https://zerolabs.sh/hutch/privacy-policy/; }
60 location = / { return 301 https://zerolabs.sh/hutch/; }
61}
linux/nginx/etc/nginx/conf.d/cleberg.net_wildcard.conf deleted −1
@@ -1 +0,0 @@
1
linux/nginx/etc/nginx/conf.d/cv.conf +2 −2
@@ -1,5 +1,5 @@
1server { 1server {
2 listen 10014; 2 listen 127.0.0.1:10014;
3 server_name cv.cleberg.net; 3 server_name cv.cleberg.net;
4 add_header Onion-Location "http://xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion$request_uri" always; 4 add_header Onion-Location "http://xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion$request_uri" always;
5 include custom.d/basic.conf; 5 include custom.d/basic.conf;
@@ -9,7 +9,7 @@ server {
9} 9}
10 10
11server { 11server {
12 listen 10015; 12 listen 127.0.0.1:10015;
13 server_name xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion; 13 server_name xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion;
14 include custom.d/basic.conf; 14 include custom.d/basic.conf;
15 root /var/www/cv/; 15 root /var/www/cv/;
linux/nginx/etc/nginx/conf.d/files.conf +7 −3
@@ -1,6 +1,10 @@
1server { 1server {
2 listen 10017; 2 listen 127.0.0.1:10017;
3 server_name files.cleberg.net; 3 # files.cleberg.net was retired 2026-08-03: it and files.krz.sh both routed
4 # here, so one origin served byte-identical content under both identities.
5 # The real-name hostname was removed; this vhost is krz-only now. Named
6 # explicitly rather than left to default-server fallback.
7 server_name files.krz.sh;
4 add_header Onion-Location "http://yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion$request_uri" always; 8 add_header Onion-Location "http://yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion$request_uri" always;
5 include custom.d/basic.conf; 9 include custom.d/basic.conf;
6 root /var/www/files/; 10 root /var/www/files/;
@@ -9,7 +13,7 @@ server {
9} 13}
10 14
11server { 15server {
12 listen 10018; 16 listen 127.0.0.1:10018;
13 server_name yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion; 17 server_name yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion;
14 include custom.d/basic.conf; 18 include custom.d/basic.conf;
15 root /var/www/files/; 19 root /var/www/files/;
linux/nginx/etc/nginx/conf.d/git.conf +12 −5
@@ -3,13 +3,14 @@
3# Repos are scanned from /git (scan-path in /etc/cgitrc). 3# Repos are scanned from /git (scan-path in /etc/cgitrc).
4 4
5server { 5server {
6 listen 10046; 6 listen 127.0.0.1:10046;
7 server_name git.krz.sh; 7 server_name git.krz.sh;
8 error_log /var/log/nginx/git.krz.sh.error.log;
9 8
9 # No per-vhost error_log: it overrode the global "off" and wrote visitor
10 # IPs to disk for the pseudonymous vhost.
11
12 # basic.conf now carries HSTS + Permissions-Policy.
10 include custom.d/basic.conf; 13 include custom.d/basic.conf;
11 include custom.d/security/strict-transport-security.conf;
12 include custom.d/security/permissions-policy.conf;
13 14
14 # The shared CSP (default-src 'self', no style-src) breaks cgit: the 15 # The shared CSP (default-src 'self', no style-src) breaks cgit: the
15 # pygments source-filter writes an inline <style> block into every blob 16 # pygments source-filter writes an inline <style> block into every blob
@@ -51,8 +52,14 @@ server {
51 fastcgi_pass unix:/run/fcgiwrap.socket; 52 fastcgi_pass unix:/run/fcgiwrap.socket;
52 fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend; 53 fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend;
53 fastcgi_param GIT_PROJECT_ROOT /git; 54 fastcgi_param GIT_PROJECT_ROOT /git;
54 fastcgi_param GIT_HTTP_EXPORT_ALL 1;
55 fastcgi_param PATH_INFO $uri; 55 fastcgi_param PATH_INFO $uri;
56
57 # GIT_HTTP_EXPORT_ALL is deliberately absent. git-http-backend tests
58 # it with getenv(), so ANY value -- including "0" -- exports every
59 # repo under GIT_PROJECT_ROOT. The variable must simply not be set.
60 # Export is now opt-in per repo via a git-daemon-export-ok marker,
61 # so a repo dropped into /git is not published by accident.
62
56 fastcgi_param QUERY_STRING $args; 63 fastcgi_param QUERY_STRING $args;
57 64
58 # /git is owned by uid 1001, which maps to no account on this host, 65 # /git is owned by uid 1001, which maps to no account on this host,
linux/nginx/etc/nginx/conf.d/hn.conf +3 −6
@@ -1,11 +1,8 @@
1server { 1server {
2 listen 10023; 2 listen 127.0.0.1:10023;
3 listen 10024; 3 listen 127.0.0.1:10024;
4 server_name hn.zerolabs.sh r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion hn.cleberg.net; 4 server_name hn.zerolabs.sh r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion;
5 5
6 if ($host = hn.cleberg.net) {
7 return 301 https://hn.zerolabs.sh$request_uri;
8 }
9 root /var/www/hn/output/; 6 root /var/www/hn/output/;
10 autoindex on; 7 autoindex on;
11 add_header Onion-Location "http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion$request_uri" always; 8 add_header Onion-Location "http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion$request_uri" always;
linux/nginx/etc/nginx/conf.d/img.conf +2 −2
@@ -1,5 +1,5 @@
1server { 1server {
2 listen 10025; 2 listen 127.0.0.1:10025;
3 server_name img.cleberg.net; 3 server_name img.cleberg.net;
4 add_header Onion-Location "http://ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion$request_uri" always; 4 add_header Onion-Location "http://ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion$request_uri" always;
5 include custom.d/basic.conf; 5 include custom.d/basic.conf;
@@ -9,7 +9,7 @@ server {
9} 9}
10 10
11server { 11server {
12 listen 10026; 12 listen 127.0.0.1:10026;
13 server_name ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion; 13 server_name ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion;
14 include custom.d/basic.conf; 14 include custom.d/basic.conf;
15 root /var/www/img/; 15 root /var/www/img/;
linux/nginx/etc/nginx/conf.d/krz.sh.conf +1 −1
@@ -1,5 +1,5 @@
1server { 1server {
2 listen 10047; 2 listen 127.0.0.1:10047;
3 server_name krz.sh; 3 server_name krz.sh;
4 root /var/www/krz.sh/; 4 root /var/www/krz.sh/;
5 absolute_redirect off; 5 absolute_redirect off;
linux/nginx/etc/nginx/conf.d/office.conf +3 −6
@@ -1,17 +1,14 @@
1server { 1server {
2 listen 10031; 2 listen 127.0.0.1:10031;
3 server_name office.zerolabs.sh office.cleberg.net; 3 server_name office.zerolabs.sh;
4 4
5 if ($host = office.cleberg.net) {
6 return 301 https://office.zerolabs.sh$request_uri;
7 }
8 add_header Onion-Location "http://uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion$request_uri" always; 5 add_header Onion-Location "http://uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion$request_uri" always;
9 root /var/www/office/; 6 root /var/www/office/;
10 include custom.d/basic.conf; 7 include custom.d/basic.conf;
11 location / { try_files $uri $uri/ /index.html; } 8 location / { try_files $uri $uri/ /index.html; }
12} 9}
13server { 10server {
14 listen 10032; 11 listen 127.0.0.1:10032;
15 server_name uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion; 12 server_name uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion;
16 include custom.d/basic.conf; 13 include custom.d/basic.conf;
17 root /var/www/office/; 14 root /var/www/office/;
linux/nginx/etc/nginx/conf.d/org.conf +3 −6
@@ -1,17 +1,14 @@
1server { 1server {
2 listen 10033; 2 listen 127.0.0.1:10033;
3 server_name org.zerolabs.sh org.cleberg.net; 3 server_name org.zerolabs.sh;
4 4
5 if ($host = org.cleberg.net) {
6 return 301 https://org.zerolabs.sh$request_uri;
7 }
8 add_header Onion-Location "http://7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion$request_uri" always; 5 add_header Onion-Location "http://7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion$request_uri" always;
9 root /var/www/org/; 6 root /var/www/org/;
10 include custom.d/basic.conf; 7 include custom.d/basic.conf;
11 location / { try_files $uri $uri/ /index.html; } 8 location / { try_files $uri $uri/ /index.html; }
12} 9}
13server { 10server {
14 listen 10034; 11 listen 127.0.0.1:10034;
15 server_name 7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion; 12 server_name 7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion;
16 include custom.d/basic.conf; 13 include custom.d/basic.conf;
17 root /var/www/org/; 14 root /var/www/org/;
linux/nginx/etc/nginx/conf.d/projects.conf +3 −6
@@ -1,10 +1,7 @@
1server { 1server {
2 listen 10040; 2 listen 127.0.0.1:10040;
3 server_name projects.zerolabs.sh projects.cleberg.net; 3 server_name projects.zerolabs.sh;
4 4
5 if ($host = projects.cleberg.net) {
6 return 301 https://projects.zerolabs.sh$request_uri;
7 }
8 add_header Onion-Location "http://krednuajd2wpt67ozmkollddpbdphpeyh74hbenagzoxqjncrtrgxkid.onion$request_uri" always; 5 add_header Onion-Location "http://krednuajd2wpt67ozmkollddpbdphpeyh74hbenagzoxqjncrtrgxkid.onion$request_uri" always;
9 root /var/www/projects/; 6 root /var/www/projects/;
10 autoindex on; 7 autoindex on;
@@ -13,7 +10,7 @@ server {
13} 10}
14 11
15server { 12server {
16 listen 10041; 13 listen 127.0.0.1:10041;
17 server_name krednuajd2wpt67ozmkollddpbdphpeyh74hbenagzoxqjncrtrgxkid.onion; 14 server_name krednuajd2wpt67ozmkollddpbdphpeyh74hbenagzoxqjncrtrgxkid.onion;
18 include custom.d/basic.conf; 15 include custom.d/basic.conf;
19 root /var/www/projects/; 16 root /var/www/projects/;
linux/nginx/etc/nginx/conf.d/reminiscecleberg.com.conf +1 −1
@@ -1,7 +1,7 @@
1 1
2 2
3server { 3server {
4 listen 10043; 4 listen 127.0.0.1:10043;
5 server_name reminiscecleberg.com; 5 server_name reminiscecleberg.com;
6 root /var/www/reminiscecleberg.com/; 6 root /var/www/reminiscecleberg.com/;
7 include custom.d/basic.conf; 7 include custom.d/basic.conf;
linux/nginx/etc/nginx/conf.d/rogue.conf +1 −1
@@ -1,5 +1,5 @@
1server { 1server {
2 listen 10001; 2 listen 127.0.0.1:10001;
3 server_name rogue.krz.sh; 3 server_name rogue.krz.sh;
4 4
5 root /var/www/rogue; 5 root /var/www/rogue;
linux/nginx/etc/nginx/conf.d/rss.conf +2 −5
@@ -1,11 +1,8 @@
1upstream freshrss { server 127.0.0.1:8099; keepalive 64; } 1upstream freshrss { server 127.0.0.1:8099; keepalive 64; }
2server { 2server {
3 listen 10045; 3 listen 127.0.0.1:10045;
4 server_name rss.zerolabs.sh rss.cleberg.net; 4 server_name rss.zerolabs.sh;
5 5
6 if ($host = rss.cleberg.net) {
7 return 301 https://rss.zerolabs.sh$request_uri;
8 }
9 include custom.d/basic.conf; 6 include custom.d/basic.conf;
10 location / { 7 location / {
11 proxy_pass http://freshrss/; 8 proxy_pass http://freshrss/;
linux/nginx/etc/nginx/conf.d/zerolabs.sh.conf +6 −1
@@ -5,8 +5,13 @@ map $host $krz_target {
5} 5}
6 6
7server { 7server {
8 listen 10000; 8 listen 127.0.0.1:10000;
9 server_name zerolabs.sh *.zerolabs.sh; 9 server_name zerolabs.sh *.zerolabs.sh;
10 10
11 # This vhost is a bare redirect and does not include basic.conf, so HSTS
12 # is set explicitly -- otherwise the redirect hop is the one response on
13 # this domain without it.
14 include custom.d/security/strict-transport-security.conf;
15
11 return 301 https://$krz_target$request_uri; 16 return 301 https://$krz_target$request_uri;
12} 17}
linux/nginx/etc/nginx/custom.d/basic.conf +8
@@ -4,5 +4,13 @@
4include custom.d/security/referrer-policy.conf; 4include custom.d/security/referrer-policy.conf;
5include custom.d/security/x-content-type-options.conf; 5include custom.d/security/x-content-type-options.conf;
6include custom.d/security/x-frame-options.conf; 6include custom.d/security/x-frame-options.conf;
7include custom.d/security/strict-transport-security.conf;
8include custom.d/security/permissions-policy.conf;
7include custom.d/location/security_file_access.conf; 9include custom.d/location/security_file_access.conf;
8#include custom.d/cross-origin/requests.conf; 10#include custom.d/cross-origin/requests.conf;
11
12# HSTS and Permissions-Policy live here, not per-vhost: every vhost is HTTPS
13# via the tunnel, so the commitment is universal. CSP is deliberately NOT
14# here -- it is content-type-mapped and a blanket policy breaks app UIs, so
15# it stays per-vhost until the per-app pass. Note that rogue.conf does not
16# include this file (intentional: it strips headers as a byte-size test).
linux/nginx/etc/nginx/custom.d/tls/certificate_files.conf deleted −2
@@ -1,2 +0,0 @@
1# Legacy include name: cleberg.net certificate (most zerolabs/cleberg.net vhosts).
2include certificate_files_cleberg_net.conf;
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_dev.conf deleted −3
@@ -1,3 +0,0 @@
1ssl_certificate /etc/letsencrypt/live/cleberg.dev/fullchain.pem;
2ssl_certificate_key /etc/letsencrypt/live/cleberg.dev/privkey.pem;
3ssl_trusted_certificate /etc/letsencrypt/live/cleberg.dev/chain.pem;
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_io.conf deleted −3
@@ -1,3 +0,0 @@
1ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem;
2ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem;
3ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem;
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_net.conf deleted −16
@@ -1,16 +0,0 @@
1# ----------------------------------------------------------------------
2# | Certificate files — cleberg.net |
3# ----------------------------------------------------------------------
4
5# This default SSL certificate will be served whenever the client lacks support
6# for SNI (Server Name Indication).
7#
8# (1) Certificate and key files location
9# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate
10#
11# (2) Intermediate certificate for OCSP stapling
12# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_trusted_certificate
13
14ssl_certificate /etc/letsencrypt/live/cleberg.net/fullchain.pem;
15ssl_certificate_key /etc/letsencrypt/live/cleberg.net/privkey.pem;
16ssl_trusted_certificate /etc/letsencrypt/live/cleberg.net/chain.pem;
linux/nginx/etc/nginx/custom.d/tls/certificate_files_reminiscecleberg_com.conf deleted −3
@@ -1,3 +0,0 @@
1ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem;
2ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem;
3ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem;
linux/nginx/etc/nginx/custom.d/tls/certificate_files_zerolabs_sh.conf deleted −3
@@ -1,3 +0,0 @@
1ssl_certificate /etc/letsencrypt/live/zerolabs.sh/fullchain.pem;
2ssl_certificate_key /etc/letsencrypt/live/zerolabs.sh/privkey.pem;
3ssl_trusted_certificate /etc/letsencrypt/live/zerolabs.sh/chain.pem;
linux/nginx/etc/nginx/custom.d/tls/ocsp_stapling.conf deleted −34
@@ -1,34 +0,0 @@
1# ----------------------------------------------------------------------
2# | Online Certificate Status Protocol stapling |
3# ----------------------------------------------------------------------
4
5# OCSP is a lightweight, only one record to help clients verify the validity of
6# the server certificate.
7# OCSP stapling allows the server to send its cached OCSP record during the TLS
8# handshake, without the need of 3rd party OCSP responder.
9#
10# https://wiki.mozilla.org/Security/Server_Side_TLS#OCSP_Stapling
11# https://tools.ietf.org/html/rfc6066#section-8
12# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling
13#
14# (1) Use Cloudflare 1.1.1.1 DNS resolver
15# https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1/
16#
17# (2) Use Google 8.8.8.8 DNS resolver
18# https://developers.google.com/speed/public-dns/docs/using
19#
20# (3) Use OpenDNS resolver
21# https://use.opendns.com
22
23ssl_stapling on;
24ssl_stapling_verify on;
25
26resolver
27 # (1)
28 1.1.1.1 1.0.0.1 [2606:4700:4700::1111] [2606:4700:4700::1001]
29 # (2)
30 8.8.8.8 8.8.4.4 [2001:4860:4860::8888] [2001:4860:4860::8844]
31 # (3)
32 # 208.67.222.222 208.67.220.220 [2620:119:35::35] [2620:119:53::53]
33 valid=60s;
34resolver_timeout 2s;
linux/nginx/etc/nginx/custom.d/tls/policy_balanced.conf deleted −20
@@ -1,20 +0,0 @@
1# ----------------------------------------------------------------------
2# | SSL policy - Balanced |
3# ----------------------------------------------------------------------
4
5# For services that need to support a wide range of clients, this configuration
6# is reasonably balanced.
7#
8# (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak
9# and potentially vulnerable but are required to support Microsoft Edge
10# and Safari.
11# https://safecurves.cr.yp.to/
12#
13# https://wiki.mozilla.org/Security/Server_Side_TLS#Recommended_configurations
14# https://nginx.org/en/docs/http/ngx_http_ssl_module.html
15
16ssl_protocols TLSv1.2;
17ssl_ciphers EECDH+CHACHA20:EECDH+AES;
18
19# (1)
20ssl_ecdh_curve X25519:prime256v1:secp521r1:secp384r1;
linux/nginx/etc/nginx/custom.d/tls/policy_strict.conf deleted −50
@@ -1,50 +0,0 @@
1# ----------------------------------------------------------------------
2# | SSL policy - Strict |
3# ----------------------------------------------------------------------
4
5# For services that don't need backward compatibility, the parameters below
6# provide the highest level of security and performance.
7#
8# (!) This policy enforces a strong TLS configuration, which may raise
9# errors with old clients.
10# If a more compatible profile is required, use the "balanced" policy.
11#
12# (!) TLSv1.3 and its 0-RTT feature require NGINX >=1.15.4 and OpenSSL >=1.1.1
13# to be installed.
14#
15# (!) Don't enable `ssl_early_data` blindly! Requests sent within early data are
16# subject to replay attacks.
17#
18# (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak
19# and potentially vulnerable.
20#
21# Add them back to the parameter `ssl_ecdh_curve` below to support
22# Microsoft Edge and Safari.
23#
24# https://safecurves.cr.yp.to/
25#
26# (2) Enables TLS 1.3 0-RTT, allows for faster resumption of TLS sessions.
27#
28# (!) Requests sent within early data are subject to replay attacks.
29# To protect against such attacks at the application layer, the
30# `$ssl_early_data` variable should be used:
31#
32# proxy_set_header Early-Data $ssl_early_data;
33#
34# The application should return response code 425 "Too Early" for anything
35# that could contain user supplied data.
36#
37# https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/425
38#
39# https://github.com/certbot/certbot/issues/6367
40# https://github.com/mozilla/server-side-tls/issues/217
41# https://nginx.org/en/docs/http/ngx_http_ssl_module.html
42
43ssl_protocols TLSv1.2 TLSv1.3;
44ssl_ciphers EECDH+CHACHA20:EECDH+AES;
45
46# (1)
47ssl_ecdh_curve X25519;
48
49# (2)
50#ssl_early_data on;
linux/nginx/etc/nginx/custom.d/tls/ssl_engine.conf deleted −47
@@ -1,47 +0,0 @@
1# ----------------------------------------------------------------------
2# | SSL engine |
3# ----------------------------------------------------------------------
4
5# (1) Optimize SSL by caching session parameters for 24 hours.
6# This cuts down on the number of expensive SSL handshakes.
7# By enabling a cache, we tell the client to re-use the already
8# negotiated state.
9# Here 10m (10 MB) in ssl_session_cache is size value (not time).
10# 1 MB cache can store about 4000 sessions, so we can store 40000 sessions.
11#
12# (2) Use a higher keepalive timeout to reduce the need for repeated handshakes
13# (!) Shouldn't be done unless you serve primarily HTTPS.
14# Default is 75s
15#
16# (3) SSL buffer size
17# Set 1400 bytes to fit in one MTU.
18# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_buffer_size
19#
20# (4) Disable session tickets
21# Session tickets keys are not auto-rotated. Only a HUP / restart will do
22# so and when a restart is performed the previous key is lost, which resets
23# all previous sessions.
24# Only enable session tickets if you set up a manual rotation mechanism.
25# https://trac.nginx.org/nginx/changeset/1356a3b9692441e163b4e78be4e9f5a46c7479e9/nginx
26# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_tickets
27#
28# (5) The TLS 1.2 and 1.3 ciphers in use in current policies are not considered
29# dangerous. This directive let the client choose the one that best fits their needs.
30# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_prefer_server_ciphers
31# https://wiki.mozilla.org/Security/Server_Side_TLS
32
33# (1)
34ssl_session_timeout 24h;
35ssl_session_cache shared:SSL:10m;
36
37# (2)
38keepalive_timeout 300s;
39
40# (3)
41# ssl_buffer_size 1400;
42
43# (4)
44ssl_session_tickets off;
45
46# (5)
47ssl_prefer_server_ciphers off;