Commit 565e8c2db8
565e8c2db8e79197ffb49554a70e209fa1ead16e
parent: 6783d54468
Verified · cmc
cmc <hello@cleberg.net> · 2026-08-03 05:31 UTC
chore: cleanup
Layout: unified · split
linux/nginx/etc/nginx/conf.d/cleberg.dev.conf
+1 −1
| @@ -1,7 +1,7 @@ |
| 1 | 1 | |
| 2 | 2 | |
| 3 | 3 | server { |
| 4 | | listen 10010; |
| 4 | listen 127.0.0.1:10010; |
| 5 | 5 | server_name cleberg.dev; |
| 6 | 6 | root /var/www/cleberg.dev/; |
| 7 | 7 | include custom.d/basic.conf; |
linux/nginx/etc/nginx/conf.d/cleberg.io.conf
deleted
−1
linux/nginx/etc/nginx/conf.d/cleberg.net.conf
+7 −15
| @@ -1,11 +1,14 @@ |
| 1 | 1 | server { |
| 2 | | listen 10011; |
| 2 | listen 127.0.0.1:10011; |
| 3 | 3 | server_name cleberg.net paske4urhs6nttrtlkuwa5cowum3fjkc6yv6kl4ncx3mjxcd77764nqd.onion; |
| 4 | | error_log /var/log/nginx/cleberg.net.error.log; |
| 4 | |
| 5 | # No per-vhost error_log: it overrode the global "off" and wrote visitor |
| 6 | # IPs to disk. |
| 7 | |
| 8 | # basic.conf now carries HSTS + Permissions-Policy. CSP stays explicit -- |
| 9 | # the shared policy is written for this vhost (it allows img.cleberg.net). |
| 5 | 10 | include custom.d/basic.conf; |
| 6 | | include custom.d/security/strict-transport-security.conf; |
| 7 | 11 | include custom.d/security/content-security-policy.conf; |
| 8 | | include custom.d/security/permissions-policy.conf; |
| 9 | 12 | root /var/www/cleberg.net/; |
| 10 | 13 | include custom.d/redirects/blog.conf; |
| 11 | 14 | port_in_redirect off; |
| @@ -48,14 +51,3 @@ server { |
| 48 | 51 | try_files $uri =404; |
| 49 | 52 | } |
| 50 | 53 | } |
| 51 | | |
| 52 | | server { |
| 53 | | listen 10012; |
| 54 | | server_name hutch.cleberg.net; |
| 55 | | include custom.d/basic.conf; |
| 56 | | include custom.d/security/strict-transport-security.conf; |
| 57 | | include custom.d/security/content-security-policy.conf; |
| 58 | | include custom.d/security/permissions-policy.conf; |
| 59 | | location = /privacy.html { return 301 https://zerolabs.sh/hutch/privacy-policy/; } |
| 60 | | location = / { return 301 https://zerolabs.sh/hutch/; } |
| 61 | | } |
linux/nginx/etc/nginx/conf.d/cleberg.net_wildcard.conf
deleted
−1
linux/nginx/etc/nginx/conf.d/cv.conf
+2 −2
| @@ -1,5 +1,5 @@ |
| 1 | 1 | server { |
| 2 | | listen 10014; |
| 2 | listen 127.0.0.1:10014; |
| 3 | 3 | server_name cv.cleberg.net; |
| 4 | 4 | add_header Onion-Location "http://xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion$request_uri" always; |
| 5 | 5 | include custom.d/basic.conf; |
| @@ -9,7 +9,7 @@ server { |
| 9 | 9 | } |
| 10 | 10 | |
| 11 | 11 | server { |
| 12 | | listen 10015; |
| 12 | listen 127.0.0.1:10015; |
| 13 | 13 | server_name xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion; |
| 14 | 14 | include custom.d/basic.conf; |
| 15 | 15 | root /var/www/cv/; |
linux/nginx/etc/nginx/conf.d/files.conf
+7 −3
| @@ -1,6 +1,10 @@ |
| 1 | 1 | server { |
| 2 | | listen 10017; |
| 3 | | server_name files.cleberg.net; |
| 2 | listen 127.0.0.1:10017; |
| 3 | # files.cleberg.net was retired 2026-08-03: it and files.krz.sh both routed |
| 4 | # here, so one origin served byte-identical content under both identities. |
| 5 | # The real-name hostname was removed; this vhost is krz-only now. Named |
| 6 | # explicitly rather than left to default-server fallback. |
| 7 | server_name files.krz.sh; |
| 4 | 8 | add_header Onion-Location "http://yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion$request_uri" always; |
| 5 | 9 | include custom.d/basic.conf; |
| 6 | 10 | root /var/www/files/; |
| @@ -9,7 +13,7 @@ server { |
| 9 | 13 | } |
| 10 | 14 | |
| 11 | 15 | server { |
| 12 | | listen 10018; |
| 16 | listen 127.0.0.1:10018; |
| 13 | 17 | server_name yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion; |
| 14 | 18 | include custom.d/basic.conf; |
| 15 | 19 | root /var/www/files/; |
linux/nginx/etc/nginx/conf.d/git.conf
+12 −5
| @@ -3,13 +3,14 @@ |
| 3 | 3 | # Repos are scanned from /git (scan-path in /etc/cgitrc). |
| 4 | 4 | |
| 5 | 5 | server { |
| 6 | | listen 10046; |
| 6 | listen 127.0.0.1:10046; |
| 7 | 7 | server_name git.krz.sh; |
| 8 | | error_log /var/log/nginx/git.krz.sh.error.log; |
| 9 | 8 | |
| 9 | # No per-vhost error_log: it overrode the global "off" and wrote visitor |
| 10 | # IPs to disk for the pseudonymous vhost. |
| 11 | |
| 12 | # basic.conf now carries HSTS + Permissions-Policy. |
| 10 | 13 | include custom.d/basic.conf; |
| 11 | | include custom.d/security/strict-transport-security.conf; |
| 12 | | include custom.d/security/permissions-policy.conf; |
| 13 | 14 | |
| 14 | 15 | # The shared CSP (default-src 'self', no style-src) breaks cgit: the |
| 15 | 16 | # pygments source-filter writes an inline <style> block into every blob |
| @@ -51,8 +52,14 @@ server { |
| 51 | 52 | fastcgi_pass unix:/run/fcgiwrap.socket; |
| 52 | 53 | fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend; |
| 53 | 54 | fastcgi_param GIT_PROJECT_ROOT /git; |
| 54 | | fastcgi_param GIT_HTTP_EXPORT_ALL 1; |
| 55 | 55 | fastcgi_param PATH_INFO $uri; |
| 56 | |
| 57 | # GIT_HTTP_EXPORT_ALL is deliberately absent. git-http-backend tests |
| 58 | # it with getenv(), so ANY value -- including "0" -- exports every |
| 59 | # repo under GIT_PROJECT_ROOT. The variable must simply not be set. |
| 60 | # Export is now opt-in per repo via a git-daemon-export-ok marker, |
| 61 | # so a repo dropped into /git is not published by accident. |
| 62 | |
| 56 | 63 | fastcgi_param QUERY_STRING $args; |
| 57 | 64 | |
| 58 | 65 | # /git is owned by uid 1001, which maps to no account on this host, |
linux/nginx/etc/nginx/conf.d/hn.conf
+3 −6
| @@ -1,11 +1,8 @@ |
| 1 | 1 | server { |
| 2 | | listen 10023; |
| 3 | | listen 10024; |
| 4 | | server_name hn.zerolabs.sh r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion hn.cleberg.net; |
| 2 | listen 127.0.0.1:10023; |
| 3 | listen 127.0.0.1:10024; |
| 4 | server_name hn.zerolabs.sh r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion; |
| 5 | 5 | |
| 6 | | if ($host = hn.cleberg.net) { |
| 7 | | return 301 https://hn.zerolabs.sh$request_uri; |
| 8 | | } |
| 9 | 6 | root /var/www/hn/output/; |
| 10 | 7 | autoindex on; |
| 11 | 8 | add_header Onion-Location "http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion$request_uri" always; |
linux/nginx/etc/nginx/conf.d/img.conf
+2 −2
| @@ -1,5 +1,5 @@ |
| 1 | 1 | server { |
| 2 | | listen 10025; |
| 2 | listen 127.0.0.1:10025; |
| 3 | 3 | server_name img.cleberg.net; |
| 4 | 4 | add_header Onion-Location "http://ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion$request_uri" always; |
| 5 | 5 | include custom.d/basic.conf; |
| @@ -9,7 +9,7 @@ server { |
| 9 | 9 | } |
| 10 | 10 | |
| 11 | 11 | server { |
| 12 | | listen 10026; |
| 12 | listen 127.0.0.1:10026; |
| 13 | 13 | server_name ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion; |
| 14 | 14 | include custom.d/basic.conf; |
| 15 | 15 | root /var/www/img/; |
linux/nginx/etc/nginx/conf.d/krz.sh.conf
+1 −1
| @@ -1,5 +1,5 @@ |
| 1 | 1 | server { |
| 2 | | listen 10047; |
| 2 | listen 127.0.0.1:10047; |
| 3 | 3 | server_name krz.sh; |
| 4 | 4 | root /var/www/krz.sh/; |
| 5 | 5 | absolute_redirect off; |
linux/nginx/etc/nginx/conf.d/office.conf
+3 −6
| @@ -1,17 +1,14 @@ |
| 1 | 1 | server { |
| 2 | | listen 10031; |
| 3 | | server_name office.zerolabs.sh office.cleberg.net; |
| 2 | listen 127.0.0.1:10031; |
| 3 | server_name office.zerolabs.sh; |
| 4 | 4 | |
| 5 | | if ($host = office.cleberg.net) { |
| 6 | | return 301 https://office.zerolabs.sh$request_uri; |
| 7 | | } |
| 8 | 5 | add_header Onion-Location "http://uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion$request_uri" always; |
| 9 | 6 | root /var/www/office/; |
| 10 | 7 | include custom.d/basic.conf; |
| 11 | 8 | location / { try_files $uri $uri/ /index.html; } |
| 12 | 9 | } |
| 13 | 10 | server { |
| 14 | | listen 10032; |
| 11 | listen 127.0.0.1:10032; |
| 15 | 12 | server_name uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion; |
| 16 | 13 | include custom.d/basic.conf; |
| 17 | 14 | root /var/www/office/; |
linux/nginx/etc/nginx/conf.d/org.conf
+3 −6
| @@ -1,17 +1,14 @@ |
| 1 | 1 | server { |
| 2 | | listen 10033; |
| 3 | | server_name org.zerolabs.sh org.cleberg.net; |
| 2 | listen 127.0.0.1:10033; |
| 3 | server_name org.zerolabs.sh; |
| 4 | 4 | |
| 5 | | if ($host = org.cleberg.net) { |
| 6 | | return 301 https://org.zerolabs.sh$request_uri; |
| 7 | | } |
| 8 | 5 | add_header Onion-Location "http://7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion$request_uri" always; |
| 9 | 6 | root /var/www/org/; |
| 10 | 7 | include custom.d/basic.conf; |
| 11 | 8 | location / { try_files $uri $uri/ /index.html; } |
| 12 | 9 | } |
| 13 | 10 | server { |
| 14 | | listen 10034; |
| 11 | listen 127.0.0.1:10034; |
| 15 | 12 | server_name 7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion; |
| 16 | 13 | include custom.d/basic.conf; |
| 17 | 14 | root /var/www/org/; |
linux/nginx/etc/nginx/conf.d/projects.conf
+3 −6
| @@ -1,10 +1,7 @@ |
| 1 | 1 | server { |
| 2 | | listen 10040; |
| 3 | | server_name projects.zerolabs.sh projects.cleberg.net; |
| 2 | listen 127.0.0.1:10040; |
| 3 | server_name projects.zerolabs.sh; |
| 4 | 4 | |
| 5 | | if ($host = projects.cleberg.net) { |
| 6 | | return 301 https://projects.zerolabs.sh$request_uri; |
| 7 | | } |
| 8 | 5 | add_header Onion-Location "http://krednuajd2wpt67ozmkollddpbdphpeyh74hbenagzoxqjncrtrgxkid.onion$request_uri" always; |
| 9 | 6 | root /var/www/projects/; |
| 10 | 7 | autoindex on; |
| @@ -13,7 +10,7 @@ server { |
| 13 | 10 | } |
| 14 | 11 | |
| 15 | 12 | server { |
| 16 | | listen 10041; |
| 13 | listen 127.0.0.1:10041; |
| 17 | 14 | server_name krednuajd2wpt67ozmkollddpbdphpeyh74hbenagzoxqjncrtrgxkid.onion; |
| 18 | 15 | include custom.d/basic.conf; |
| 19 | 16 | root /var/www/projects/; |
linux/nginx/etc/nginx/conf.d/reminiscecleberg.com.conf
+1 −1
| @@ -1,7 +1,7 @@ |
| 1 | 1 | |
| 2 | 2 | |
| 3 | 3 | server { |
| 4 | | listen 10043; |
| 4 | listen 127.0.0.1:10043; |
| 5 | 5 | server_name reminiscecleberg.com; |
| 6 | 6 | root /var/www/reminiscecleberg.com/; |
| 7 | 7 | include custom.d/basic.conf; |
linux/nginx/etc/nginx/conf.d/rogue.conf
+1 −1
| @@ -1,5 +1,5 @@ |
| 1 | 1 | server { |
| 2 | | listen 10001; |
| 2 | listen 127.0.0.1:10001; |
| 3 | 3 | server_name rogue.krz.sh; |
| 4 | 4 | |
| 5 | 5 | root /var/www/rogue; |
linux/nginx/etc/nginx/conf.d/rss.conf
+2 −5
| @@ -1,11 +1,8 @@ |
| 1 | 1 | upstream freshrss { server 127.0.0.1:8099; keepalive 64; } |
| 2 | 2 | server { |
| 3 | | listen 10045; |
| 4 | | server_name rss.zerolabs.sh rss.cleberg.net; |
| 3 | listen 127.0.0.1:10045; |
| 4 | server_name rss.zerolabs.sh; |
| 5 | 5 | |
| 6 | | if ($host = rss.cleberg.net) { |
| 7 | | return 301 https://rss.zerolabs.sh$request_uri; |
| 8 | | } |
| 9 | 6 | include custom.d/basic.conf; |
| 10 | 7 | location / { |
| 11 | 8 | proxy_pass http://freshrss/; |
linux/nginx/etc/nginx/conf.d/zerolabs.sh.conf
+6 −1
| @@ -5,8 +5,13 @@ map $host $krz_target { |
| 5 | 5 | } |
| 6 | 6 | |
| 7 | 7 | server { |
| 8 | | listen 10000; |
| 8 | listen 127.0.0.1:10000; |
| 9 | 9 | server_name zerolabs.sh *.zerolabs.sh; |
| 10 | 10 | |
| 11 | # This vhost is a bare redirect and does not include basic.conf, so HSTS |
| 12 | # is set explicitly -- otherwise the redirect hop is the one response on |
| 13 | # this domain without it. |
| 14 | include custom.d/security/strict-transport-security.conf; |
| 15 | |
| 11 | 16 | return 301 https://$krz_target$request_uri; |
| 12 | 17 | } |
linux/nginx/etc/nginx/custom.d/basic.conf
+8
| @@ -4,5 +4,13 @@ |
| 4 | 4 | include custom.d/security/referrer-policy.conf; |
| 5 | 5 | include custom.d/security/x-content-type-options.conf; |
| 6 | 6 | include custom.d/security/x-frame-options.conf; |
| 7 | include custom.d/security/strict-transport-security.conf; |
| 8 | include custom.d/security/permissions-policy.conf; |
| 7 | 9 | include custom.d/location/security_file_access.conf; |
| 8 | 10 | #include custom.d/cross-origin/requests.conf; |
| 11 | |
| 12 | # HSTS and Permissions-Policy live here, not per-vhost: every vhost is HTTPS |
| 13 | # via the tunnel, so the commitment is universal. CSP is deliberately NOT |
| 14 | # here -- it is content-type-mapped and a blanket policy breaks app UIs, so |
| 15 | # it stays per-vhost until the per-app pass. Note that rogue.conf does not |
| 16 | # include this file (intentional: it strips headers as a byte-size test). |
linux/nginx/etc/nginx/custom.d/tls/certificate_files.conf
deleted
−2
| @@ -1,2 +0,0 @@ |
| 1 | | # Legacy include name: cleberg.net certificate (most zerolabs/cleberg.net vhosts). |
| 2 | | include certificate_files_cleberg_net.conf; |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_dev.conf
deleted
−3
| @@ -1,3 +0,0 @@ |
| 1 | | ssl_certificate /etc/letsencrypt/live/cleberg.dev/fullchain.pem; |
| 2 | | ssl_certificate_key /etc/letsencrypt/live/cleberg.dev/privkey.pem; |
| 3 | | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.dev/chain.pem; |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_io.conf
deleted
−3
| @@ -1,3 +0,0 @@ |
| 1 | | ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem; |
| 2 | | ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem; |
| 3 | | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem; |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_net.conf
deleted
−16
| @@ -1,16 +0,0 @@ |
| 1 | | # ---------------------------------------------------------------------- |
| 2 | | # | Certificate files — cleberg.net | |
| 3 | | # ---------------------------------------------------------------------- |
| 4 | | |
| 5 | | # This default SSL certificate will be served whenever the client lacks support |
| 6 | | # for SNI (Server Name Indication). |
| 7 | | # |
| 8 | | # (1) Certificate and key files location |
| 9 | | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate |
| 10 | | # |
| 11 | | # (2) Intermediate certificate for OCSP stapling |
| 12 | | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_trusted_certificate |
| 13 | | |
| 14 | | ssl_certificate /etc/letsencrypt/live/cleberg.net/fullchain.pem; |
| 15 | | ssl_certificate_key /etc/letsencrypt/live/cleberg.net/privkey.pem; |
| 16 | | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.net/chain.pem; |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_reminiscecleberg_com.conf
deleted
−3
| @@ -1,3 +0,0 @@ |
| 1 | | ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem; |
| 2 | | ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem; |
| 3 | | ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem; |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_zerolabs_sh.conf
deleted
−3
| @@ -1,3 +0,0 @@ |
| 1 | | ssl_certificate /etc/letsencrypt/live/zerolabs.sh/fullchain.pem; |
| 2 | | ssl_certificate_key /etc/letsencrypt/live/zerolabs.sh/privkey.pem; |
| 3 | | ssl_trusted_certificate /etc/letsencrypt/live/zerolabs.sh/chain.pem; |
linux/nginx/etc/nginx/custom.d/tls/ocsp_stapling.conf
deleted
−34
| @@ -1,34 +0,0 @@ |
| 1 | | # ---------------------------------------------------------------------- |
| 2 | | # | Online Certificate Status Protocol stapling | |
| 3 | | # ---------------------------------------------------------------------- |
| 4 | | |
| 5 | | # OCSP is a lightweight, only one record to help clients verify the validity of |
| 6 | | # the server certificate. |
| 7 | | # OCSP stapling allows the server to send its cached OCSP record during the TLS |
| 8 | | # handshake, without the need of 3rd party OCSP responder. |
| 9 | | # |
| 10 | | # https://wiki.mozilla.org/Security/Server_Side_TLS#OCSP_Stapling |
| 11 | | # https://tools.ietf.org/html/rfc6066#section-8 |
| 12 | | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling |
| 13 | | # |
| 14 | | # (1) Use Cloudflare 1.1.1.1 DNS resolver |
| 15 | | # https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1/ |
| 16 | | # |
| 17 | | # (2) Use Google 8.8.8.8 DNS resolver |
| 18 | | # https://developers.google.com/speed/public-dns/docs/using |
| 19 | | # |
| 20 | | # (3) Use OpenDNS resolver |
| 21 | | # https://use.opendns.com |
| 22 | | |
| 23 | | ssl_stapling on; |
| 24 | | ssl_stapling_verify on; |
| 25 | | |
| 26 | | resolver |
| 27 | | # (1) |
| 28 | | 1.1.1.1 1.0.0.1 [2606:4700:4700::1111] [2606:4700:4700::1001] |
| 29 | | # (2) |
| 30 | | 8.8.8.8 8.8.4.4 [2001:4860:4860::8888] [2001:4860:4860::8844] |
| 31 | | # (3) |
| 32 | | # 208.67.222.222 208.67.220.220 [2620:119:35::35] [2620:119:53::53] |
| 33 | | valid=60s; |
| 34 | | resolver_timeout 2s; |
linux/nginx/etc/nginx/custom.d/tls/policy_balanced.conf
deleted
−20
| @@ -1,20 +0,0 @@ |
| 1 | | # ---------------------------------------------------------------------- |
| 2 | | # | SSL policy - Balanced | |
| 3 | | # ---------------------------------------------------------------------- |
| 4 | | |
| 5 | | # For services that need to support a wide range of clients, this configuration |
| 6 | | # is reasonably balanced. |
| 7 | | # |
| 8 | | # (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak |
| 9 | | # and potentially vulnerable but are required to support Microsoft Edge |
| 10 | | # and Safari. |
| 11 | | # https://safecurves.cr.yp.to/ |
| 12 | | # |
| 13 | | # https://wiki.mozilla.org/Security/Server_Side_TLS#Recommended_configurations |
| 14 | | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html |
| 15 | | |
| 16 | | ssl_protocols TLSv1.2; |
| 17 | | ssl_ciphers EECDH+CHACHA20:EECDH+AES; |
| 18 | | |
| 19 | | # (1) |
| 20 | | ssl_ecdh_curve X25519:prime256v1:secp521r1:secp384r1; |
linux/nginx/etc/nginx/custom.d/tls/policy_strict.conf
deleted
−50
| @@ -1,50 +0,0 @@ |
| 1 | | # ---------------------------------------------------------------------- |
| 2 | | # | SSL policy - Strict | |
| 3 | | # ---------------------------------------------------------------------- |
| 4 | | |
| 5 | | # For services that don't need backward compatibility, the parameters below |
| 6 | | # provide the highest level of security and performance. |
| 7 | | # |
| 8 | | # (!) This policy enforces a strong TLS configuration, which may raise |
| 9 | | # errors with old clients. |
| 10 | | # If a more compatible profile is required, use the "balanced" policy. |
| 11 | | # |
| 12 | | # (!) TLSv1.3 and its 0-RTT feature require NGINX >=1.15.4 and OpenSSL >=1.1.1 |
| 13 | | # to be installed. |
| 14 | | # |
| 15 | | # (!) Don't enable `ssl_early_data` blindly! Requests sent within early data are |
| 16 | | # subject to replay attacks. |
| 17 | | # |
| 18 | | # (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak |
| 19 | | # and potentially vulnerable. |
| 20 | | # |
| 21 | | # Add them back to the parameter `ssl_ecdh_curve` below to support |
| 22 | | # Microsoft Edge and Safari. |
| 23 | | # |
| 24 | | # https://safecurves.cr.yp.to/ |
| 25 | | # |
| 26 | | # (2) Enables TLS 1.3 0-RTT, allows for faster resumption of TLS sessions. |
| 27 | | # |
| 28 | | # (!) Requests sent within early data are subject to replay attacks. |
| 29 | | # To protect against such attacks at the application layer, the |
| 30 | | # `$ssl_early_data` variable should be used: |
| 31 | | # |
| 32 | | # proxy_set_header Early-Data $ssl_early_data; |
| 33 | | # |
| 34 | | # The application should return response code 425 "Too Early" for anything |
| 35 | | # that could contain user supplied data. |
| 36 | | # |
| 37 | | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/425 |
| 38 | | # |
| 39 | | # https://github.com/certbot/certbot/issues/6367 |
| 40 | | # https://github.com/mozilla/server-side-tls/issues/217 |
| 41 | | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html |
| 42 | | |
| 43 | | ssl_protocols TLSv1.2 TLSv1.3; |
| 44 | | ssl_ciphers EECDH+CHACHA20:EECDH+AES; |
| 45 | | |
| 46 | | # (1) |
| 47 | | ssl_ecdh_curve X25519; |
| 48 | | |
| 49 | | # (2) |
| 50 | | #ssl_early_data on; |
linux/nginx/etc/nginx/custom.d/tls/ssl_engine.conf
deleted
−47
| @@ -1,47 +0,0 @@ |
| 1 | | # ---------------------------------------------------------------------- |
| 2 | | # | SSL engine | |
| 3 | | # ---------------------------------------------------------------------- |
| 4 | | |
| 5 | | # (1) Optimize SSL by caching session parameters for 24 hours. |
| 6 | | # This cuts down on the number of expensive SSL handshakes. |
| 7 | | # By enabling a cache, we tell the client to re-use the already |
| 8 | | # negotiated state. |
| 9 | | # Here 10m (10 MB) in ssl_session_cache is size value (not time). |
| 10 | | # 1 MB cache can store about 4000 sessions, so we can store 40000 sessions. |
| 11 | | # |
| 12 | | # (2) Use a higher keepalive timeout to reduce the need for repeated handshakes |
| 13 | | # (!) Shouldn't be done unless you serve primarily HTTPS. |
| 14 | | # Default is 75s |
| 15 | | # |
| 16 | | # (3) SSL buffer size |
| 17 | | # Set 1400 bytes to fit in one MTU. |
| 18 | | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_buffer_size |
| 19 | | # |
| 20 | | # (4) Disable session tickets |
| 21 | | # Session tickets keys are not auto-rotated. Only a HUP / restart will do |
| 22 | | # so and when a restart is performed the previous key is lost, which resets |
| 23 | | # all previous sessions. |
| 24 | | # Only enable session tickets if you set up a manual rotation mechanism. |
| 25 | | # https://trac.nginx.org/nginx/changeset/1356a3b9692441e163b4e78be4e9f5a46c7479e9/nginx |
| 26 | | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_tickets |
| 27 | | # |
| 28 | | # (5) The TLS 1.2 and 1.3 ciphers in use in current policies are not considered |
| 29 | | # dangerous. This directive let the client choose the one that best fits their needs. |
| 30 | | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_prefer_server_ciphers |
| 31 | | # https://wiki.mozilla.org/Security/Server_Side_TLS |
| 32 | | |
| 33 | | # (1) |
| 34 | | ssl_session_timeout 24h; |
| 35 | | ssl_session_cache shared:SSL:10m; |
| 36 | | |
| 37 | | # (2) |
| 38 | | keepalive_timeout 300s; |
| 39 | | |
| 40 | | # (3) |
| 41 | | # ssl_buffer_size 1400; |
| 42 | | |
| 43 | | # (4) |
| 44 | | ssl_session_tickets off; |
| 45 | | |
| 46 | | # (5) |
| 47 | | ssl_prefer_server_ciphers off; |