bitnami-containers/bitnami/nginx/1.25/debian-11
samsepi0l 4a878fac9f
[bitnami/nginx] Specify ciphers suites and set strong ciphers (#53352)
* Specify ciphers suites for better control and security

It's better to specify cipher suites to avoid having too many ciphers authorized.

It allow better control of which cipher suites you use.

The cipher have been choosed based on https://english.ncsc.nl/publications/publications/2021/january/19/it-security-guidelines-for-transport-layer-security-2.1

Signed-off-by: samsepi0l <contact@simpleprivacy.fr>

* Remove useless ciphers

Signed-off-by: samsepi0l <contact@simpleprivacy.fr>

* Add "ssl_prefer_server_ciphers" and prioritize ChaCha20 suites with clients that don't have AES-NI

Signed-off-by: samsepi0l <contact@simpleprivacy.fr>

* Update bitnami/nginx/1.25/debian-11/rootfs/opt/bitnami/nginx/conf/nginx.conf

Co-authored-by: Juan José Martos <jotamartos@gmail.com>
Signed-off-by: samsepi0l <contact@samsepi0l.dev>

---------

Signed-off-by: samsepi0l <contact@simpleprivacy.fr>
Signed-off-by: samsepi0l <contact@samsepi0l.dev>
Co-authored-by: samsepi0l <contact@simpleprivacy.fr>
Co-authored-by: Juan José Martos <jotamartos@gmail.com>
2023-12-21 09:13:15 +01:00
..
prebuildfs [bitnami/nginx] Release 1.25.3-debian-11-r2 (#53673) 2023-12-09 02:41:50 +01:00
rootfs/opt/bitnami [bitnami/nginx] Specify ciphers suites and set strong ciphers (#53352) 2023-12-21 09:13:15 +01:00
Dockerfile [bitnami/nginx] Release 1.25.3-debian-11-r2 (#53673) 2023-12-09 02:41:50 +01:00
docker-compose.yml
tags-info.yaml