Skip to content

Commit 79f5e1d

Browse files
committed
Disabled SSLv3 to fix POODLE vulnerability.
https://www.digicert.com/ssl-support/nginx-disabling-ssl-v3.htm
1 parent d59b0e5 commit 79f5e1d

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

sites-available/example.com.conf

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -168,6 +168,9 @@ server {
168168
ssl_certificate /etc/ssl/certs/example-cert.pem;
169169
ssl_certificate_key /etc/ssl/private/example.key;
170170

171+
# Disable SSL v3 protocol to fix POODLE bug.
172+
ssl_protocols TLSv1.2 TLSv1.1 TLSv1;
173+
171174
## Strict Transport Security header for enhanced security. See
172175
## http://www.chromium.org/sts. I've set it to 2 hours; set it to
173176
## whichever age you want.

0 commit comments

Comments
 (0)