Skip to content

Commit 5a35dc3

Browse files
Add ssl_ecdh_curve and ssl_buffer_size directives (#252)
1 parent 3db5164 commit 5a35dc3

File tree

2 files changed

+8
-0
lines changed

2 files changed

+8
-0
lines changed

defaults/main/template.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,8 @@ nginx_http_template:
114114
trusted_cert: /etc/ssl/certs/root_CA_cert_plus_intermediates.crt
115115
stapling: true
116116
stapling_verify: true
117+
buffer_size: 16k
118+
ecdh_curve: auto
117119
sub_filter:
118120
# sub_filters: []
119121
last_modified: "off"

templates/http/default.conf.j2

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -116,6 +116,12 @@ server {
116116
{% if item.value.servers[server].ssl.stapling_verify is defined and item.value.servers[server].ssl.stapling_verify %}
117117
ssl_stapling_verify on;
118118
{% endif %}
119+
{% if item.value.servers[server].ssl.ecdh_curve is defined and item.value.servers[server].ssl.ecdh_curve %}
120+
ssl_ecdh_curve {{ item.value.servers[server].ssl.ecdh_curve }};
121+
{% endif %}
122+
{% if item.value.servers[server].ssl.buffer_size is defined and item.value.servers[server].ssl.buffer_size %}
123+
ssl_buffer_size {{ item.value.servers[server].ssl.buffer_size }};
124+
{% endif %}
119125
{% endif %}
120126
{% if item.value.servers[server].include_files is defined and item.value.servers[server].include_files | length %}
121127
{% for file in item.value.servers[server].include_files %}

0 commit comments

Comments
 (0)