5 ms·
A+ without any changes, whoop :) https://www.ssllabs.com/ssltest/analyze.html?d=theticketfairy.com https://www.ssllabs.com/ssltest/analyze.html?d=theticketfair
by riteshpatel 13y ago
A+ without any changes, whoop :)
https://www.ssllabs.com/ssltest/analyze.html?d=theticketfairy.com https://www.ssllabs.com/ssltest/analyze.html?d=theticketfair...
- gog 13y agoCan you share the nginx config?
- knite 13y agoYes, please!
- RKearney 13y agoNot OP, but here's the relevant portion of my Nginx config that scores an A+ https://gist.github.com/ryankearney/8552425 https://gist.github.com/ryankearney/8552425
- ivanr 13y agoSome comments: - You don't need the builtin session cache. According to the Nginx documentation, it's more efficient to rely only on shared memory alone. - You should use a longer session duration. Five minutes is too short. Use at least one hour there. - For performance reasons, you might want to enable OCSP stapling. - SSL Labs does not currently penalize Diffie-Hellman parameters of 1024 bits (the Nginx default), but it's something you should generally look to improve. It's easy with the ssl_dhparam directive. (Some libraries, for example Java 6 and 7, does not support DH params over 1024 bits, though. So take that into consideration.)
- RKearney 13y agoThanks for all these suggestions. I was able to implement all of them except for oscp stapling due to our version of nginx not supporting it. Once that gets upgraded that can be implemented too.
- aroch 13y agoAlso not the OP, but this is my conf and it got an A+ with no modifications. Redirects http://www http://www and http:// http:// to https://example.com https://example.com (also strips www from https://www. https://www.), supports sdpy where appropriate, and does OCSP stapling. http://idzr.org/r0v7 http://idzr.org/r0v7 Also, my nginx.conf includes add_header Strict-Transport-Security "max-age=31536000; includeSubDomains";