Skip to content

Commit 1f9fdcc

Browse files
authored
feat: Update the value of ssl_protocols. (#672)
1 parent d7f3517 commit 1f9fdcc

File tree

9 files changed

+90
-92
lines changed

9 files changed

+90
-92
lines changed

content/nginx/admin-guide/load-balancer/http-load-balancer.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -427,7 +427,7 @@ http {
427427
listen 443 ssl;
428428
ssl_certificate /etc/nginx/ssl/company.com.crt;
429429
ssl_certificate_key /etc/nginx/ssl/company.com.key;
430-
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
430+
ssl_protocols TLSv1.2 TLSv1.3;
431431
432432
location / {
433433
proxy_pass https://exchange;

content/nginx/admin-guide/mail-proxy/mail-proxy.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -166,7 +166,7 @@ To enable SSL/TLS for the mail proxy:
166166
```nginx
167167
mail {
168168
#...
169-
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
169+
ssl_protocols TLSv1.2 TLSv1.3;
170170
ssl_ciphers HIGH:!aNULL:!MD5;
171171
}
172172
```
@@ -223,7 +223,7 @@ mail {
223223
ssl on;
224224
ssl_certificate /etc/ssl/certs/server.crt;
225225
ssl_certificate_key /etc/ssl/certs/server.key;
226-
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
226+
ssl_protocols TLSv1.2 TLSv1.3;
227227
ssl_ciphers HIGH:!aNULL:!MD5;
228228
ssl_session_cache shared:SSL:10m;
229229
ssl_session_timeout 10m;

content/nginx/admin-guide/security-controls/securing-http-traffic-upstream.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -77,7 +77,7 @@ Optionally, you can specify which SSL protocols and ciphers are used:
7777
```nginx
7878
location /upstream {
7979
#...
80-
proxy_ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
80+
proxy_ssl_protocols TLSv1.2 TLSv1.3;
8181
proxy_ssl_ciphers HIGH:!aNULL:!MD5;
8282
}
8383
```
@@ -133,7 +133,7 @@ http {
133133
proxy_pass https://backend.example.com;
134134
proxy_ssl_certificate /etc/nginx/client.pem;
135135
proxy_ssl_certificate_key /etc/nginx/client.key;
136-
proxy_ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
136+
proxy_ssl_protocols TLSv1.2 TLSv1.3;
137137
proxy_ssl_ciphers HIGH:!aNULL:!MD5;
138138
proxy_ssl_trusted_certificate /etc/nginx/trusted_ca_cert.crt;
139139

content/nginx/admin-guide/security-controls/securing-tcp-traffic-upstream.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ Optionally, specify which SSL protocols and ciphers to use:
5858
```nginx
5959
server {
6060
...
61-
proxy_ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
61+
proxy_ssl_protocols TLSv1.2 TLSv1.3;
6262
proxy_ssl_ciphers HIGH:!aNULL:!MD5;
6363
}
6464
```
@@ -98,7 +98,7 @@ stream {
9898
9999
proxy_ssl_certificate /etc/ssl/certs/backend.crt;
100100
proxy_ssl_certificate_key /etc/ssl/certs/backend.key;
101-
proxy_ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
101+
proxy_ssl_protocols TLSv1.2 TLSv1.3;
102102
proxy_ssl_ciphers HIGH:!aNULL:!MD5;
103103
proxy_ssl_trusted_certificate /etc/ssl/certs/trusted_ca_cert.crt;
104104

content/nginx/admin-guide/security-controls/terminating-ssl-http.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ server {
2222
server_name www.example.com;
2323
ssl_certificate www.example.com.crt;
2424
ssl_certificate_key www.example.com.key;
25-
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
25+
ssl_protocols TLSv1.2 TLSv1.3;
2626
ssl_ciphers HIGH:!aNULL:!MD5;
2727
#...
2828
}
@@ -39,10 +39,10 @@ In this case it is important to restrict access to the file. Note that although
3939

4040
The [ssl_protocols](https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_protocols) and [ssl_ciphers](https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_ciphers ) directives can be used to require that clients use only the strong versions and ciphers of SSL/TLS when establishing connections.
4141

42-
Since version 1.9.1, NGINX uses these defaults:
42+
Since version 1.23.4, NGINX uses these defaults:
4343

4444
```nginx
45-
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
45+
ssl_protocols TLSv1.2 TLSv1.3;
4646
ssl_ciphers HIGH:!aNULL:!MD5;
4747
```
4848

@@ -118,7 +118,7 @@ http {
118118
119119
ssl_certificate www.example.com.crt;
120120
ssl_certificate_key www.example.com.key;
121-
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
121+
ssl_protocols TLSv1.2 TLSv1.3;
122122
ssl_ciphers HIGH:!aNULL:!MD5;
123123
#...
124124
}

content/nginx/admin-guide/security-controls/terminating-ssl-tcp.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ Additionally, the [ssl_protocols](https://nginx.org/en/docs/stream/ngx_stream_ss
6262
```nginx
6363
server {
6464
#...
65-
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
65+
ssl_protocols TLSv1.2 TLSv1.3;
6666
ssl_ciphers HIGH:!aNULL:!MD5;
6767
}
6868
```
@@ -152,7 +152,7 @@ stream {
152152
153153
ssl_certificate /etc/ssl/certs/server.crt;
154154
ssl_certificate_key /etc/ssl/certs/server.key;
155-
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;
155+
ssl_protocols TLSv1.2 TLSv1.3;
156156
ssl_ciphers HIGH:!aNULL:!MD5;
157157
ssl_session_cache shared:SSL:20m;
158158
ssl_session_timeout 4h;

0 commit comments

Comments
 (0)