首先要升級你的 nignx 到 1.9.5 以上
最簡單的方法就是用 yum 設定 repo,並且修改你的 repo 如下
[nginx] name=nginx repo baseurl=http://nginx.org/packages/mainline/centos/6/$basearch/ gpgcheck=0 enabled=1
如果你是別的 OS,可以參考這邊的說明: http://nginx.org/en/linux_packages.html
[nginx] name=nginx repo baseurl=http://nginx.org/packages/mainline/centos/6/$basearch/ gpgcheck=0 enabled=1
yum upgrade nginx
listen 443 ssl http2; listen [::]:443 ssl http2;
# 產生 DH parameters openssl dhparam 4096 -out /etc/nginx/cert/dhparam.pem
ssl_dhparam /etc/nginx/cert/dhparam.pem;
ssl_dhparam /etc/nginx/cert/dhparam.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";
# 產生 dhparam cd /etc/ssl/certs openssl dhparam -out dhparam.pem 4096 # 把下列設定加到 ssl.conf SSLOpenSSLConfCmd DHParameters "/etc/ssl/certs/dhparam.pem"