blob: dd4f2cdcdef8a76f144b2783f9f4bd2184ae148c [file] [log] [blame]
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +03001parameters:
2 _param:
3 nginx_proxy_ssl_enabled: false
4 nginx_proxy_ssl:
5 mode: 'strict'
6 enabled: ${_param:nginx_proxy_ssl_enabled}
7 engine: salt
8 dhparam:
9 enabled: True
10 numbits: 2048
11 ecdh_curve:
12 secp521r1:
13 name: 'secp521r1'
14 enabled: True
15 prefer_server_ciphers: "on"
16 protocols:
17 TLSv1:
18 name: 'TLSv1'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030019 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030020 TLSv1.1:
21 name: 'TLSv1.1'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030022 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030023 TLSv1.2:
24 name: 'TLSv1.2'
25 enabled: True
26 stapling: "on"
27 stapling_verify: "on"
28 ciphers:
29 ECDHE-ECDSA-CHACHA20-POLY1305:
30 name: 'ECDHE-ECDSA-CHACHA20-POLY1305'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030031 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030032 ECDHE-RSA-CHACHA20-POLY1305:
33 name: 'ECDHE-RSA-CHACHA20-POLY1305'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030034 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030035 ECDHE-ECDSA-AES128-GCM-SHA256:
36 name: 'ECDHE-ECDSA-AES128-GCM-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030037 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030038 ECDHE-RSA-AES128-GCM-SHA256:
39 name: 'ECDHE-RSA-AES128-GCM-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030040 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030041 ECDHE-ECDSA-AES256-GCM-SHA384:
42 name: 'ECDHE-ECDSA-AES256-GCM-SHA384'
43 enabled: True
44 ECDHE-RSA-AES256-GCM-SHA384:
45 name: 'ECDHE-RSA-AES256-GCM-SHA384'
46 enabled: True
47 DHE-RSA-AES128-GCM-SHA256:
48 name: 'DHE-RSA-AES128-GCM-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030049 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030050 DHE-RSA-AES256-GCM-SHA384:
51 name: 'DHE-RSA-AES256-GCM-SHA384'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030052 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030053 ECDHE-ECDSA-AES128-SHA256:
54 name: 'ECDHE-ECDSA-AES128-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030055 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030056 ECDHE-RSA-AES128-SHA256:
57 name: 'ECDHE-RSA-AES128-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030058 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030059 ECDHE-ECDSA-AES128-SHA:
60 name: 'ECDHE-ECDSA-AES128-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030061 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030062 ECDHE-RSA-AES256-SHA384:
63 name: 'ECDHE-RSA-AES256-SHA384'
64 enabled: True
65 ECDHE-RSA-AES128-SHA:
66 name: 'ECDHE-RSA-AES128-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030067 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030068 ECDHE-ECDSA-AES256-SHA384:
69 name: 'ECDHE-ECDSA-AES256-SHA384'
70 enabled: True
71 ECDHE-ECDSA-AES256-SHA:
72 name: 'ECDHE-ECDSA-AES256-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030073 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030074 ECDHE-RSA-AES256-SHA:
75 name: 'ECDHE-RSA-AES256-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030076 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030077 DHE-RSA-AES128-SHA256:
78 name: 'DHE-RSA-AES128-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030079 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030080 DHE-RSA-AES128-SHA:
81 name: 'DHE-RSA-AES128-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030082 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030083 DHE-RSA-AES256-SHA256:
84 name: 'DHE-RSA-AES256-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030085 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030086 DHE-RSA-AES256-SHA:
87 name: 'DHE-RSA-AES256-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030088 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030089 ECDHE-ECDSA-DES-CBC3-SHA:
90 name: 'ECDHE-ECDSA-DES-CBC3-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030091 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030092 ECDHE-RSA-DES-CBC3-SHA:
93 name: 'ECDHE-RSA-DES-CBC3-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030094 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030095 EDH-RSA-DES-CBC3-SHA:
96 name: 'EDH-RSA-DES-CBC3-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +030097 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +030098 AES128-GCM-SHA256:
99 name: 'AES128-GCM-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300100 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300101 AES256-GCM-SHA384:
102 name: 'AES256-GCM-SHA384'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300103 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300104 AES128-SHA256:
105 name: 'AES128-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300106 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300107 AES256-SHA256:
108 name: 'AES256-SHA256'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300109 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300110 AES256-SHA:
111 name: 'AES256-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300112 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300113 AES128-SHA:
114 name: 'AES128-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300115 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300116 DES-CBC3-SHA:
117 name: 'DES-CBC3-SHA'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300118 enabled: False
Mykyta Karpin6dc8dab2018-07-31 16:54:12 +0300119 removeDSS:
120 name: '!DSS'
Oleksandr Shyshkoa5f8d082019-05-23 17:44:28 +0300121 enabled: True