LNMP 1.7 tls1.3设置

#SSL session过期时间
        ssl_session_timeout 10m;
#只允许TLS协议
        ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
#由服务器协商最佳的加密算法  
        ssl_prefer_server_ciphers on;
        ssl_ciphers   TLS13-AES-256-GCM-SHA384:TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-128-GCM-SHA256:TLS13-AES-128-CCM-8-SHA256:TLS13-AES-128-CCM-SHA256:EECDH+CHACHA20:EECDH+CHACHA20-draft:EECDH+ECDSA+AES128:EECDH+aRSA+AES128:RSA+AES128:EECDH+ECDSA+AES256:EECDH+aRSA+AES256:RSA+AES256:EECDH+ECDSA+3DES:EECDH+aRSA+3DES:RSA+3DES:!MD5;        
        ssl_buffer_size 1400;

#Session Cache,将Session缓存到服务器,这可能会占用更多的服务器资源
        ssl_session_cache builtin:1000 shared:SSL:10m;
#开启浏览器的Session Ticket缓存
         ssl_session_tickets on;

#DH-Key交换密钥文件位置
        ssl_dhparam /usr/local/nginx/conf/ssl/dhparam.pem;
#启用CSP
	add_header  Content-Security-Policy "default-src *; img-src * data:; font-src * data:; script-src 'self' *.chenky.com *.cnzz.com *.google-analytics.com dn-staticfile.qbox.me 'unsafe-inline' 'unsafe-eval'; style-src 'self' *.chenky.com 'unsafe-inline'";        #error_page   404   /404.html;
#开启HSTS,并设置有效期为“6307200秒”(6个月),包括子域名(根据情况可删掉),预加载到浏览器缓存(根据情况可删掉)
        add_header Strict-Transport-Security "max-age=6307200; includeSubdomains; preload";
#OCSP Stapling开启,OCSP是用于在线查询证书吊销情况的服务,使用OCSP Stapling能将证书有效状态的信息缓存到服务器,提高TLS握手速度
         ssl_stapling on; 
#OCSP Stapling验证开启
         ssl_stapling_verify on;