3 ms·
Some comments: - You don't need the builtin session cache. According to the Nginx documentation, it's more efficient to rely only on shared memory alone. - Yo
by ivanr 13y ago
Some comments:
- You don't need the builtin session cache. According to the Nginx documentation, it's more efficient to rely only on shared memory alone.
- You should use a longer session duration. Five minutes is too short. Use at least one hour there.
- For performance reasons, you might want to enable OCSP stapling.
- SSL Labs does not currently penalize Diffie-Hellman parameters of 1024 bits (the Nginx default), but it's something you should generally look to improve. It's easy with the ssl_dhparam directive. (Some libraries, for example Java 6 and 7, does not support DH params over 1024 bits, though. So take that into consideration.)
- RKearney 13y agoThanks for all these suggestions. I was able to implement all of them except for oscp stapling due to our version of nginx not supporting it. Once that gets upgraded that can be implemented too.