4 ms·
I'm mentioning tuning your SSL ciphers a number of times in this thread. It really is quite important. For Nginx you should compile it with the latest OpenSSL
by poutine 13y ago
I'm mentioning tuning your SSL ciphers a number of times in this thread. It really is quite important. For Nginx you should compile it with the latest OpenSSL (1.0.1e right now -- you can statically link it if you dont want to mess up your OS's packages) to get the latest ciphers.
Use a config line like the following in nginx:
ssl_ciphers ECDHE-RSA-AES128-SHA256:AES128-GCM-SHA256:RC4:HIGH:!MD5:!aNULL:!EDH;
RC4 is a problem right now but unfortunately there's not a good solution until we get more TLS 1.2 support out there.
If you don't do this sort of tuning you're exposed to some weak ciphers that can result in attacks.