Skip to content
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 1 addition & 2 deletions nginx-custom-ssl/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,10 +1,9 @@
FROM nginx:1.23.3
FROM nginx:1.30.0

COPY conf/nginx.conf /etc/nginx/nginx.conf
COPY conf/ssl-params.conf /etc/nginx/ssl-params.conf

COPY certs/nginx.crt /etc/ssl/certs/nginx.crt
COPY certs/nginx.key /etc/ssl/private/nginx.key
COPY certs/dhparam.pem /etc/ssl/certs/dhparam.pem

CMD nginx -g "daemon off;"
1 change: 0 additions & 1 deletion nginx-custom-ssl/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,6 @@ SSL support with custom cert.
To enable SSL with your custom certificate, follow the steps below:

1. Copy your certificate and key to certs/nginx.crt and certs/nginx.key
2. Copy your dhparam file to certs/dhparam.pem

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The rest of these need to be renumbered (it's "1, 3, 4, 5, ..." currently).

3. Edit conf/nginx.conf to update `__server_names__` to your domain or IP address
4. Perform any other configuration edits that you might need
5. Run `docker build -t sublime_nginx_custom_ssl .`
Expand Down
4 changes: 2 additions & 2 deletions nginx-custom-ssl/conf/nginx.conf
Original file line number Diff line number Diff line change
Expand Up @@ -18,12 +18,12 @@ http {

server {
listen 443 ssl http2 default_server;
listen [::]:443 ssl http2 default_server;
listen [::]:443 ssl http2 default_server;

ssl_certificate /etc/ssl/certs/nginx.crt;
ssl_certificate_key /etc/ssl/private/nginx.key;

include ssl-params.conf;
include ssl-params.conf;

location /v1 {
proxy_pass http://sublime_mantis:8000;
Expand Down
26 changes: 14 additions & 12 deletions nginx-custom-ssl/conf/ssl-params.conf
Original file line number Diff line number Diff line change
@@ -1,21 +1,23 @@
# from https://cipherli.st/
# and https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html
# adapted from:
# generated 2026-05-04, Mozilla Guideline v6.0, nginx 1.30, OpenSSL 3.5.5, intermediate config, HSTS
# https://ssl-config.mozilla.org/#server=nginx&version=1.30&config=intermediate&openssl=3.5.5&hsts&guideline=6.0

# intermediate configuration
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ecdh_curve X25519MLKEM768:X25519:prime256v1:secp384r1;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305;
ssl_prefer_server_ciphers off;

# see also ssl_session_ticket_key alternative to stateful session cache
ssl_session_timeout 1d;
ssl_session_cache shared:MozSSL:10m; # about 40000 sessions

ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_prefer_server_ciphers on;
ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";
ssl_ecdh_curve secp384r1;
ssl_session_cache shared:SSL:10m;
ssl_session_tickets off;
ssl_stapling on;
ssl_stapling_verify on;
resolver 8.8.8.8 8.8.4.4 valid=300s;
Comment thread
madirey marked this conversation as resolved.
Outdated
resolver_timeout 5s;

# Disable preloading HSTS for now. You can use the commented out header line that includes
# the "preload" directive if you understand the implications.
#add_header Strict-Transport-Security "max-age=63072000; includeSubdomains; preload";
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains";
add_header X-Frame-Options DENY;
add_header X-Content-Type-Options nosniff;

ssl_dhparam /etc/ssl/certs/dhparam.pem;
2 changes: 1 addition & 1 deletion nginx-letsencrypt/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM nginx:1.23.3
FROM nginx:1.30.0

RUN apt-get update && apt-get install -y \
wget \
Expand Down
Loading