turn on http3 support
Build Container Image / build_arm64 (push) Successful in 15s Details
Build Container Image / build_riscv64 (push) Successful in 21s Details
Build Container Image / publish_arm64 (push) Successful in 9s Details
Build Container Image / build_armhf (push) Successful in 29s Details
Build Container Image / publish_riscv64 (push) Successful in 9s Details
Build Container Image / build_amd64 (push) Successful in 35s Details
Build Container Image / build_manifest (push) Successful in 5s Details
Build Container Image / publish_armhf (push) Successful in 18s Details
Build Container Image / publish_amd64 (push) Successful in 31s Details
Build Container Image / publish_manifest (push) Successful in 27s Details

This commit is contained in:
Daniel Wolf 2023-06-18 22:03:55 -04:00
parent 389eb39960
commit 5060e4d293
Signed by: nephatrine
GPG Key ID: 59D70EC2E4AAB4D0
3 changed files with 19 additions and 5 deletions

View File

@ -1,11 +1,18 @@
#NOSSL:listen 80;
#NOSSL:listen [::]:80;
#SSL:listen 443 ssl http2;
#SSL:listen [::]:443 ssl http2;
#SSL:listen 443 quic reuseport;
#SSL:listen 443 ssl;
#SSL:listen [::]:443 quic reuseport;
#SSL:listen [::]:443 ssl;
#SSL:http2 on;
#SSL:http3 on;
#SSL:ssl_certificate /mnt/config/ssl/live/example.net/fullchain.pem;
#SSL:ssl_certificate_key /mnt/config/ssl/live/example.net/privkey.pem;
#SSL:ssl_trusted_certificate /mnt/config/ssl/live/example.net/chain.pem;
#SSL:add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
#SSL:add_header Alt-Svc 'h3=":$server_port"; ma=86400';
autoindex off;
add_header X-Content-Type-Options nosniff;

View File

@ -1,11 +1,18 @@
#NOSSL:listen 80;
#NOSSL:listen [::]:80;
#SSL:listen 443 ssl http2;
#SSL:listen [::]:443 ssl http2;
#SSL:listen 443 quic;
#SSL:listen 443 ssl;
#SSL:listen [::]:443 quic;
#SSL:listen [::]:443 ssl;
#SSL:http2 on;
#SSL:http3 on;
#SSL:ssl_certificate /mnt/config/ssl/live/example.net/fullchain.pem;
#SSL:ssl_certificate_key /mnt/config/ssl/live/example.net/privkey.pem;
#SSL:ssl_trusted_certificate /mnt/config/ssl/live/example.net/chain.pem;
#SSL:add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
#SSL:add_header Alt-Svc 'h3=":$server_port"; ma=86400';
add_header X-Cache-Status $cache_status;
proxy_set_header Host $host;

View File

@ -1,7 +1,7 @@
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;
ssl_dhparam /mnt/config/ssl/dhparam.pem;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305;
ssl_session_timeout 4h;
ssl_session_cache shared:SSL:10m;
ssl_session_tickets off;