From dc46215600a047798fdc1b8c0c83664efbf37cd4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Hanno=20B=C3=B6ck?= Date: Tue, 14 Apr 2020 16:59:19 +0200 Subject: [PATCH] web: remove DHE suites support Ref: https://github.com/jitsi/docker-jitsi-meet/issues/433 --- web/rootfs/defaults/ssl.conf | 5 +---- web/rootfs/etc/cont-init.d/10-config | 3 --- 2 files changed, 1 insertion(+), 7 deletions(-) diff --git a/web/rootfs/defaults/ssl.conf b/web/rootfs/defaults/ssl.conf index 60e3c6c..cb79fb7 100644 --- a/web/rootfs/defaults/ssl.conf +++ b/web/rootfs/defaults/ssl.conf @@ -3,9 +3,6 @@ ssl_session_timeout 1d; ssl_session_cache shared:SSL:50m; ssl_session_tickets off; -# Diffie-Hellman parameter for DHE cipher suites -ssl_dhparam /config/nginx/dhparams.pem; - # ssl certs {{ if .Env.ENABLE_LETSENCRYPT | default "0" | toBool }} ssl_certificate /etc/letsencrypt/live/{{ .Env.LETSENCRYPT_DOMAIN }}/fullchain.pem; @@ -19,7 +16,7 @@ ssl_certificate_key /config/keys/cert.key; ssl_protocols TLSv1.2; ssl_prefer_server_ciphers on; ssl_ecdh_curve secp384r1; -ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDH+CHACHA20:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!3DES:!MD5:!PSK; +ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:ECDH+CHACHA20:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!3DES:!MD5:!PSK; # headers add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"; diff --git a/web/rootfs/etc/cont-init.d/10-config b/web/rootfs/etc/cont-init.d/10-config index 1738cc4..b0cd722 100644 --- a/web/rootfs/etc/cont-init.d/10-config +++ b/web/rootfs/etc/cont-init.d/10-config @@ -47,9 +47,6 @@ if [[ $DISABLE_HTTPS -ne 1 ]]; then openssl req -new -x509 -days 3650 -nodes -out /config/keys/cert.crt -keyout /config/keys/cert.key -subj "$SUBJECT" fi fi - if [[ ! -f /config/nginx/dhparams.pem ]]; then - openssl dhparam -out /config/nginx/dhparams.pem 2048 - fi fi # copy config files