From 2c60281fec45f1a321461749d9027285ce1c30e2 Mon Sep 17 00:00:00 2001 From: nono <np@laquadrature.net> Date: Fri, 5 Mar 2021 15:03:14 +0100 Subject: [PATCH] Changed key lookup from 4096 to 2048 --- files/etc/nginx/hedgedocs-nginx.conf.j2 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/files/etc/nginx/hedgedocs-nginx.conf.j2 b/files/etc/nginx/hedgedocs-nginx.conf.j2 index 9bd6570..c45c1f4 100644 --- a/files/etc/nginx/hedgedocs-nginx.conf.j2 +++ b/files/etc/nginx/hedgedocs-nginx.conf.j2 @@ -39,7 +39,7 @@ server { ssl_ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384"; # RFC-7919 recommended: https://wiki.mozilla.org/Security/Server_Side_TLS#ffdhe4096 - ssl_dhparam /etc/ssl/ffdhe4096.pem; + ssl_dhparam /etc/ssl/ffdhe2048.pem; ssl_ecdh_curve secp521r1:secp384r1; # Aditional Security Headers -- GitLab