3 ms·
Yeah no, that's where I'd draw the line. I have one nginx instance serving my blog and various resources via proxypass (nextcloud, grafana, icinga, kibana etc.)
by lazyweb 6y ago
Yeah no, that's where I'd draw the line. I have one nginx instance serving my blog and various resources via proxypass (nextcloud, grafana, icinga, kibana etc.).
For the sake of keeping things maintainable, there's one wildcard cert for my domain and one global SSL configuration. I'd rather shut out people with Windows XP than enabling < TLS 1.2 globally.
- gnyman 6y agoEveryone has different priorities of course. But note that as long as you use a modern client TLS_FALLBACK_SCSV will ensure you won't be at risk of downgrade attacks or similar. Without that I also don't think I would run it.