Add ability to configure SSL timeout per host

This commit is contained in:
Shaun McPeck 2019-03-27 06:43:00 -05:00 committed by GitHub
parent 8c590fc68f
commit f982222807
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -244,8 +244,9 @@ server {
ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:AES128-GCM-SHA256:AES128-SHA256:AES128-SHA:AES256-GCM-SHA384:AES256-SHA256:AES256-SHA:DHE-DSS-AES128-SHA';
{{ end }}
{{ $ssl_session_timeout := eq (or ($.Env.SSL_TIMEOUT) "") "5m" }}
ssl_prefer_server_ciphers on;
ssl_session_timeout 5m;
ssl_session_timeout {{ (printf "%s" $ssl_session_timeout) }};
ssl_session_cache shared:SSL:50m;
ssl_session_tickets off;