Skip to content

Commit 9b32329

Browse files
committed
Apply fixes from v2
1 parent 001583b commit 9b32329

File tree

3 files changed

+5
-6
lines changed

3 files changed

+5
-6
lines changed

docker/rootfs/etc/nginx/conf.d/default.conf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,7 @@ server {
1616
server {
1717
listen 443 ssl default;
1818
server_name localhost;
19+
include conf.d/include/ssl-ciphers.conf;
1920
include conf.d/include/block-exploits.conf;
2021
access_log /data/logs/default.log proxy;
2122
ssl_reject_handshake on;

docker/rootfs/etc/nginx/conf.d/include/ssl-ciphers.conf

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,5 @@ ssl_session_cache shared:SSL:50m;
33

44
# intermediate configuration. tweak to your needs.
55
ssl_protocols TLSv1.2 TLSv1.3;
6-
ssl_ciphers 'EECDH+AESGCM:AES256+EECDH:AES256+EDH:EDH+AESGCM:ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-
7-
ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AE
8-
S128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES';
9-
ssl_prefer_server_ciphers on;
6+
ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384';
7+
ssl_prefer_server_ciphers off;

docker/rootfs/etc/s6-overlay/s6-rc.d/prepare/50-ipv46.sh

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ process_folder () {
3232
for FILE in $FILES
3333
do
3434
echo " - ${FILE}"
35-
sed -E -i "$SED_REGEX" "$FILE" || true
35+
echo "$(sed -E "$SED_REGEX" "$FILE")" > $FILE
3636
done
3737

3838
# IPV6 ...
@@ -47,7 +47,7 @@ process_folder () {
4747
for FILE in $FILES
4848
do
4949
echo " - ${FILE}"
50-
sed -E -i "$SED_REGEX" "$FILE" || true
50+
echo "$(sed -E "$SED_REGEX" "$FILE")" > $FILE
5151
done
5252

5353
# ensure the files are still owned by the npm user

0 commit comments

Comments
 (0)