change nginx defaults to tls1.2 and above

This commit is contained in:
itiligent 2023-07-23 13:03:42 +10:00
parent c774b3cc95
commit 7a6d92ce89

View file

@ -51,6 +51,12 @@ else
echo echo
fi fi
# Force nginx to require tls1.2 and above
sudo sed -i -e '/ssl_protocols/s/^/#/' /etc/nginx/nginx.conf
sudo sed -i "/SSL Settings/a \ ssl_protocols TLSv1.2 TLSv1.3; # Dropping SSLv3, ref: POODLE" /etc/nginx/nginx.conf
# Symlink from sites-available to sites-enabled # Symlink from sites-available to sites-enabled
ln -s /etc/nginx/sites-available/$PROXY_SITE /etc/nginx/sites-enabled/ ln -s /etc/nginx/sites-available/$PROXY_SITE /etc/nginx/sites-enabled/