summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJulien Vehent [:ulfr] <jvehent@users.noreply.github.com>2016-03-03 06:43:33 -0500
committerJulien Vehent [:ulfr] <jvehent@users.noreply.github.com>2016-03-03 06:43:33 -0500
commit0c52c96ebfa246c80d56a122875594cab0912745 (patch)
treef606ef2145f9840383f59394e3ef12946f91b305
parent1a41a79ca2d93bb5b86cb834cd1cc05a169221ed (diff)
parent332cb015935b08cf386002dbeadfda4133c99836 (diff)
downloadserver-side-tls-0c52c96ebfa246c80d56a122875594cab0912745.zip
server-side-tls-0c52c96ebfa246c80d56a122875594cab0912745.tar.gz
server-side-tls-0c52c96ebfa246c80d56a122875594cab0912745.tar.bz2
Merge pull request #126 from Yajo/patch-1
Better defaults for HAProxy
-rw-r--r--ssl-config-generator/index.html8
1 files changed, 6 insertions, 2 deletions
diff --git a/ssl-config-generator/index.html b/ssl-config-generator/index.html
index 0385cd1..2df5628 100644
--- a/ssl-config-generator/index.html
+++ b/ssl-config-generator/index.html
@@ -116,11 +116,15 @@ global
# set default parameters to the {{securityProfile}} configuration
tune.ssl.default-dh-param {{maxDHKeySize}}
ssl-default-bind-ciphers {{cipherSuites}}
- ssl-default-bind-options no-tls-tickets
+ ssl-default-bind-options {{sslProtocols}} no-tls-tickets
+ ssl-default-server-ciphers {{cipherSuites}}
+ ssl-default-server-options {{sslProtocols}} no-tls-tickets
frontend ft_test
mode http
- bind 0.0.0.0:443 {{sslProtocols}} crt /path/to/&lt;cert+privkey+intermediate+dhparam&gt;
+ bind :443 crt /path/to/&lt;cert+privkey+intermediate+dhparam&gt;
+ bind :80
+ redirect scheme https code 301 if !{ ssl_fc }
{{hsts}}
</pre>
</script>