nixos/nginx: drop DHE usage (#515057)
This commit is contained in:
@@ -206,11 +206,6 @@ let
|
||||
if lib.isList cfg.sslCiphers then (lib.concatStringsSep ":" cfg.sslCiphers) else cfg.sslCiphers
|
||||
};"
|
||||
}
|
||||
${optionalString (cfg.sslDhparam != false)
|
||||
"ssl_dhparam ${
|
||||
if cfg.sslDhparam == true then config.security.dhparams.params.nginx.path else cfg.sslDhparam
|
||||
};"
|
||||
}
|
||||
|
||||
${optionalString cfg.recommendedTlsSettings ''
|
||||
# Consider https://ssl-config.mozilla.org/#server=nginx&config=intermediate as the lower bound
|
||||
@@ -981,9 +976,6 @@ in
|
||||
"ECDHE-RSA-AES256-GCM-SHA384"
|
||||
"ECDHE-ECDSA-CHACHA20-POLY1305"
|
||||
"ECDHE-RSA-CHACHA20-POLY1305"
|
||||
"DHE-RSA-AES128-GCM-SHA256"
|
||||
"DHE-RSA-AES256-GCM-SHA384"
|
||||
"DHE-RSA-CHACHA20-POLY1305"
|
||||
];
|
||||
description = ''
|
||||
List of available cipher suites to choose from when negotiating TLS sessions.
|
||||
@@ -1002,13 +994,6 @@ in
|
||||
description = "Allowed TLS protocol versions.";
|
||||
};
|
||||
|
||||
sslDhparam = mkOption {
|
||||
type = types.either types.path types.bool;
|
||||
default = false;
|
||||
example = "/path/to/dhparams.pem";
|
||||
description = "Path to DH parameters file, or `true` to generate with `security.dhparms.params.nginx`.";
|
||||
};
|
||||
|
||||
proxyResolveWhileRunning = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
@@ -1308,6 +1293,13 @@ in
|
||||
};
|
||||
|
||||
imports = [
|
||||
(mkRemovedOptionModule [ "services" "nginx" "sslDhparam" ] ''
|
||||
DHE cipher suites have been removed from the default nginx cipher list.
|
||||
|
||||
No additional configuration is required as ECDHE is used by default already.
|
||||
|
||||
If you wish to use Hybrid PQ key exchange, you can set services.nginx.recommendedTlsSettings = true.
|
||||
'')
|
||||
(mkRemovedOptionModule [ "services" "nginx" "stateDir" ] ''
|
||||
The Nginx log directory has been moved to /var/log/nginx, the cache directory
|
||||
to /var/cache/nginx. The option services.nginx.stateDir has been removed.
|
||||
@@ -1678,8 +1670,6 @@ in
|
||||
in
|
||||
listToAttrs acmePairs;
|
||||
|
||||
security.dhparams.params.nginx = lib.mkIf (cfg.sslDhparam == true) { };
|
||||
|
||||
users.users = optionalAttrs (cfg.user == "nginx") {
|
||||
nginx = {
|
||||
group = cfg.group;
|
||||
|
||||
Reference in New Issue
Block a user