# {{ ansible_managed }} # Listen for IPv4 and IPv6 with HTTP2 listen [::]:443 ssl http2; listen 443 ssl http2; # Hide NGINX version server_tokens off; # Reverse Proxy Adm set_real_ip_from 10.128.0.0/16; real_ip_header P-Real-Ip; # SSL ssl on; ssl_session_timeout 5m; ssl_ciphers "ECDHE-ECDSA-CHACHA20-POLY1305:ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:!AES256-GCM-SHA256:!AES256-GCM-SHA128:!aNULL:!MD5"; ssl_prefer_server_ciphers on; ssl_session_cache shared:SSL:10m; # Use more secure ECDH curve ssl_ecdh_curve secp521r1:secp384r1; # In buster we will be able to use TLSv1.3 ssl_protocols TLSv1.2; # Executer "cd /etc/ssl/certs; openssl dhparam -out dhparam.pem 4096" avant d'activer ssl_dhparam /etc/ssl/certs/dhparam.pem; # Enable OCSP Stapling, point to certificate chain ssl_stapling on; ssl_stapling_verify on;