From 943dc81718d7b1fc9d83a378fb3221df345c5b03 Mon Sep 17 00:00:00 2001 From: Asif Bacchus Date: Fri, 4 Jan 2019 04:50:10 -0700 Subject: [PATCH] turned on ssl_early_data --- etc/nginx/conf.d/mozModern_ssl.conf | 1 + 1 file changed, 1 insertion(+) diff --git a/etc/nginx/conf.d/mozModern_ssl.conf b/etc/nginx/conf.d/mozModern_ssl.conf index d89b0a1..e5649c2 100644 --- a/etc/nginx/conf.d/mozModern_ssl.conf +++ b/etc/nginx/conf.d/mozModern_ssl.conf @@ -17,6 +17,7 @@ ssl_session_tickets off; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers 'TLS-CHACHA20-POLY1305-SHA256:TLS-AES-256-GCM-SHA384:TLS-AES-128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256' ssl_prefer_server_ciphers on; +ssl_early_data on; # Diffie-Hellman parameter for DHE cipher suites, using 4096 bits ssl_dhparam /path/to/your_dhparam.pem;