nginx – ssllabs一直说sslv3没有启用

前端之家收集整理的这篇文章主要介绍了nginx – ssllabs一直说sslv3没有启用前端之家小编觉得挺不错的,现在分享给大家,也给大家做个参考。

https://www.ssllabs.com/ssltest/analyze.html?d=cablework.co

我无法弄清楚为什么一直说“C”.我已禁用SSLv3.

这是我的配置文件

  1. server {
  2. listen 80;
  3. listen 443 ssl spdy;
  4. server_name cablework.co;
  5. ssl_certificate /etc/Nginx/ssl/cablework.co.pem;
  6. ssl_certificate_key /etc/Nginx/ssl/server.key;
  7. return 301 https://www.cablework.co$request_uri;
  8. }
  9. server {
  10. listen 443 ssl spdy;
  11. ssl_certificate /etc/Nginx/ssl/cablework.co.pem;
  12. ssl_certificate_key /etc/Nginx/ssl/server.key;
  13. ssl_ciphers 'AES256+EECDH:AES256+EDH';
  14. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  15. ssl_session_cache shared:SSL:10m;
  16. ssl_stapling on;
  17. ssl_stapling_verify on;
  18. resolver 8.8.4.4 8.8.4.4 valid=300s;
  19. resolver_timeout 10s;
  20. ssl_prefer_server_ciphers on;
  21. ssl_dhparam /etc/Nginx/ssl/dhparam.pem;
  22. charset utf-8;
  23. location / {
  24. try_files $uri $uri/ /index.PHP?$query_string;
  25. }
  26. location = /favicon.ico { access_log off; log_not_found off; }
  27. location = /robots.txt { access_log off; log_not_found off; }
  28. access_log off;
  29. error_log /var/log/Nginx/www.cablework.co-error.log error;
  30. error_page 404 /index.PHP;
  31. location ~ \.PHP${
  32. fastcgi_split_path_info ^(.+\.PHP)(/.+)$;
  33. fastcgi_pass unix:/var/run/PHP5-fpm.sock;
  34. fastcgi_index index.PHP;
  35. include fastcgi_params;
  36. }
  37. location ~ /\.ht {
  38. deny all;
  39. }
  40. add_header Strict-Transport-Security max-age=63072000;
  41. add_header X-Frame-Options DENY;
  42. add_header X-Content-Type-Options nosniff;
  43. root /home/kryptonit3/cablework/public;
  44. index index.html index.htm index.PHP;
  45. server_name www.cablework.co;
  46. }
最佳答案
您忘了为名为cablework.co的服务器指定ssl_protocols和ssl_ciphers.因此默认值 – 无论它们是什么 – 都会被使用.

猜你在找的Nginx相关文章