{"id":5647,"date":"2015-12-30T05:44:11","date_gmt":"2015-12-29T20:44:11","guid":{"rendered":"https:\/\/www.vincentina.net\/?p=5647"},"modified":"2020-02-23T18:47:43","modified_gmt":"2020-02-23T09:47:43","slug":"i-had-to-consider-about-a-ssl-conf","status":"publish","type":"post","link":"https:\/\/www.vincentina.net\/?p=5647","title":{"rendered":"I had to consider about a ssl.conf."},"content":{"rendered":"<p>The last time, My web site became HTTPS. However, according to SSL SERVER, it was scored B+. Disappointed. So that, I&#8217;ll consider at a ssl.conf, I think I want to enhance security connections. The result, I was able to increase to A+. And I introduce some of the examples.<\/p>\n<p><a href=\"https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslreport.png\" rel=\"attachment wp-att-5650\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslreport.png\" alt=\"sslreport\" width=\"933\" height=\"509\" class=\"alignnone size-full wp-image-5650\" srcset=\"https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslreport.png 933w, https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslreport-300x164.png 300w, https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslreport-768x419.png 768w, https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslreport-624x340.png 624w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><\/p>\n<p>First, I was enabled SPDY. But this is NOT related to security.<\/p>\n<pre>listen 443 ssl;\nlisten 443 ssl spdy;<\/pre>\n<p>Now, Spdy is enabled.<\/p>\n<p>Now then, although I am saying reviewed ssl.conf I need reference materials.<br \/>\nI found &#8220;<a href=\"https:\/\/mozilla.github.io\/server-side-tls\/ssl-config-generator\/\" target=\"_blank\" rel=\"noopener noreferrer\">Mozilla SSL Configuration Generator<\/a>&#8220;.<br \/>\nThis is outputted a ssl.conf to fit each environment. For example, Nginx, set of modern and SSL 1.01e version. etc..<\/p>\n<p>Second, about a ssl_ciphers.<br \/>\nApparently ECDHE-RSA-AES128-GCM-SHA256 is newer.<br \/>\nBecause<\/p>\n<pre>ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!3DES:!MD5:!PSK;<\/pre>\n<p>Priority is high that it is written to the left.<br \/>\nIf you use a generator, it would include &#8220;DHE-RSA-AES128-GCM-SHA256&#8221;, but I have removed it. so that, so that, also, I didn&#8217;t create a dhparam.<\/p>\n<p>Third, about an OCSP Stapling.<br \/>\nThis is needed root CA certificate.<br \/>\nlike this.<\/p>\n<pre>\n-----BEGIN CERTIFICATE-----\nRoot CA Certificate\n-----END CERTIFICATE-----\n-----BEGIN CERTIFICATE-----\nIntermediate Certificate\n-----END CERTIFICATE-----\n<\/pre>\n<pre>\nssl.conf\n    # OCSP Stapling ---\n    # fetch OCSP records from URL in ssl_certificate and cache them\n    ssl_stapling on;\n    ssl_stapling_verify on;\n    ssl_trusted_certificate ca-certs.pem;\n<\/pre>\n<p>That&#8217;s it.<\/p>\n<p><a href=\"https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslshot.png\" rel=\"attachment wp-att-5648\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslshot.png\" alt=\"sslshot\" width=\"787\" height=\"493\" class=\"alignnone size-full wp-image-5648\" srcset=\"https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslshot.png 787w, https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslshot-300x188.png 300w, https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslshot-768x481.png 768w, https:\/\/www.vincentina.net\/wp-content\/uploads\/2015\/12\/sslshot-624x391.png 624w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/p>\n<p>How was it.<br \/>\nHave a good day!<\/p>\n<p>These are references.<\/p>\n<p>My Library<br \/>\nhttp:\/\/blog.mylibs.jp\/archives\/181<\/p>\n<div class='wp_social_bookmarking_light'>        <div class=\"wsbl_twitter\"><a href=\"https:\/\/twitter.com\/share\" class=\"twitter-share-button\" data-url=\"https:\/\/www.vincentina.net\/?p=5647\" data-text=\"I had to consider about a ssl.conf.\" data-via=\"TakekenTw\" data-lang=\"ja\">Tweet<\/a><\/div><\/div>\n<br class='wp_social_bookmarking_light_clear' \/>\n","protected":false},"excerpt":{"rendered":"<p>The last time, My web site became HTTPS. However, according to SSL SERVER, it was scored B+. Disappointed. So  &hellip; <a href=\"https:\/\/www.vincentina.net\/?p=5647\" class=\"more-link\"><span class=\"screen-reader-text\">&#8220;I had to consider about a ssl.conf.&#8221; \u306e<\/span>\u7d9a\u304d\u3092\u8aad\u3080<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[117],"tags":[],"class_list":["post-5647","post","type-post","status-publish","format-standard","hentry","category-english"],"_links":{"self":[{"href":"https:\/\/www.vincentina.net\/index.php?rest_route=\/wp\/v2\/posts\/5647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.vincentina.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.vincentina.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.vincentina.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.vincentina.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5647"}],"version-history":[{"count":0,"href":"https:\/\/www.vincentina.net\/index.php?rest_route=\/wp\/v2\/posts\/5647\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.vincentina.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.vincentina.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5647"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.vincentina.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}