challenger-tls.conf.inc (484B)
1 2 ssl_certificate /etc/letsencrypt/live/challenger/fullchain.pem; 3 ssl_certificate_key /etc/letsencrypt/live/challenger/privkey.pem; 4 ssl_trusted_certificate /etc/letsencrypt/live/challenger/chain.pem; 5 ssl_prefer_server_ciphers on; 6 ssl_session_cache shared:SSL:10m; 7 ssl_dhparam /etc/ssl/private/dhparam.pem; 8 ssl_protocols TLSv1.3 TLSv1.2; 9 ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'; 10 11 add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";