blob: fdd95a580423659dd000903d746599e6c70308c9 [file] [log] [blame]
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +03001parameters:
2 _param:
3 nginx_proxy_ssl_enabled: false
4 nginx_proxy_ssl:
5 mode: 'strict'
6 enabled: ${_param:nginx_proxy_ssl_enabled}
7 engine: salt
8 dhparam:
9 enabled: True
10 numbits: 2048
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030011 prefer_server_ciphers: "on"
12 protocols:
13 TLSv1:
14 name: 'TLSv1'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030015 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030016 TLSv1.1:
17 name: 'TLSv1.1'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030018 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030019 TLSv1.2:
20 name: 'TLSv1.2'
21 enabled: True
22 stapling: "on"
23 stapling_verify: "on"
24 ciphers:
25 ECDHE-ECDSA-CHACHA20-POLY1305:
26 name: 'ECDHE-ECDSA-CHACHA20-POLY1305'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030027 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030028 ECDHE-RSA-CHACHA20-POLY1305:
29 name: 'ECDHE-RSA-CHACHA20-POLY1305'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030030 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030031 ECDHE-ECDSA-AES128-GCM-SHA256:
32 name: 'ECDHE-ECDSA-AES128-GCM-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030033 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030034 ECDHE-RSA-AES128-GCM-SHA256:
35 name: 'ECDHE-RSA-AES128-GCM-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030036 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030037 ECDHE-ECDSA-AES256-GCM-SHA384:
38 name: 'ECDHE-ECDSA-AES256-GCM-SHA384'
39 enabled: True
40 ECDHE-RSA-AES256-GCM-SHA384:
41 name: 'ECDHE-RSA-AES256-GCM-SHA384'
42 enabled: True
43 DHE-RSA-AES128-GCM-SHA256:
44 name: 'DHE-RSA-AES128-GCM-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030045 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030046 DHE-RSA-AES256-GCM-SHA384:
47 name: 'DHE-RSA-AES256-GCM-SHA384'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030048 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030049 ECDHE-ECDSA-AES128-SHA256:
50 name: 'ECDHE-ECDSA-AES128-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030051 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030052 ECDHE-RSA-AES128-SHA256:
53 name: 'ECDHE-RSA-AES128-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030054 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030055 ECDHE-ECDSA-AES128-SHA:
56 name: 'ECDHE-ECDSA-AES128-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030057 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030058 ECDHE-RSA-AES256-SHA384:
59 name: 'ECDHE-RSA-AES256-SHA384'
60 enabled: True
61 ECDHE-RSA-AES128-SHA:
62 name: 'ECDHE-RSA-AES128-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030063 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030064 ECDHE-ECDSA-AES256-SHA384:
65 name: 'ECDHE-ECDSA-AES256-SHA384'
66 enabled: True
67 ECDHE-ECDSA-AES256-SHA:
68 name: 'ECDHE-ECDSA-AES256-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030069 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030070 ECDHE-RSA-AES256-SHA:
71 name: 'ECDHE-RSA-AES256-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030072 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030073 DHE-RSA-AES128-SHA256:
74 name: 'DHE-RSA-AES128-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030075 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030076 DHE-RSA-AES128-SHA:
77 name: 'DHE-RSA-AES128-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030078 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030079 DHE-RSA-AES256-SHA256:
80 name: 'DHE-RSA-AES256-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030081 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030082 DHE-RSA-AES256-SHA:
83 name: 'DHE-RSA-AES256-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030084 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030085 ECDHE-ECDSA-DES-CBC3-SHA:
86 name: 'ECDHE-ECDSA-DES-CBC3-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030087 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030088 ECDHE-RSA-DES-CBC3-SHA:
89 name: 'ECDHE-RSA-DES-CBC3-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030090 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030091 EDH-RSA-DES-CBC3-SHA:
92 name: 'EDH-RSA-DES-CBC3-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030093 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030094 AES128-GCM-SHA256:
95 name: 'AES128-GCM-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030096 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030097 AES256-GCM-SHA384:
98 name: 'AES256-GCM-SHA384'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030099 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300100 AES128-SHA256:
101 name: 'AES128-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300102 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300103 AES256-SHA256:
104 name: 'AES256-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300105 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300106 AES256-SHA:
107 name: 'AES256-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300108 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300109 AES128-SHA:
110 name: 'AES128-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300111 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300112 DES-CBC3-SHA:
113 name: 'DES-CBC3-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300114 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300115 removeDSS:
116 name: '!DSS'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300117 enabled: True