Skip to content

Commit e658031

Browse files
senorsmilegdzien
authored andcommitted
Add ssl_dhparam option (#114)
* add dhparam to README * add dhparam to defaults/main.yml
1 parent 4c96e19 commit e658031

File tree

3 files changed

+5
-0
lines changed

3 files changed

+5
-0
lines changed

README.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -376,6 +376,7 @@ nginx_http_template:
376376
cert: /etc/ssl/certs/proxy_default.crt
377377
key: /etc/ssl/private/proxy_default.key
378378
trusted_cert: /etc/ssl/certs/proxy_ca.crt
379+
dhparam: /etc/ssl/private/dh_param.pem
379380
server_name: false
380381
name: server_name
381382
protocols: TLSv1 TLSv1.1 TLSv1.2

defaults/main.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -175,6 +175,7 @@ nginx_http_template:
175175
ssl:
176176
cert: /etc/ssl/certs/default.crt
177177
key: /etc/ssl/private/default.key
178+
dhparam: /etc/ssl/private/dh_param.pem
178179
protocols: TLSv1 TLSv1.1 TLSv1.2
179180
ciphers: HIGH:!aNULL:!MD5
180181
session_cache: none

templates/http/default.conf.j2

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -52,6 +52,9 @@ server {
5252
listen {{ item.value.port }} ssl;
5353
ssl_certificate {{ item.value.ssl.cert }};
5454
ssl_certificate_key {{ item.value.ssl.key }};
55+
{% if item.value.ssl.dhparam is defined %}
56+
ssl_dhparam {{ item.value.ssl.dhparam }};
57+
{% endif %}
5558
{% if item.value.ssl.protocols is defined %}
5659
ssl_protocols {{ item.value.ssl.protocols }};
5760
{% endif %}

0 commit comments

Comments
 (0)