Add ECDH curve fallback for Android 7.0
authorGerhard Schlager <mail@gerhard-schlager.at>
Tue, 3 Oct 2017 10:49:49 +0000 (12:49 +0200)
committerGerhard Schlager <mail@gerhard-schlager.at>
Tue, 3 Oct 2017 10:49:49 +0000 (12:49 +0200)
templates/web.ssl.template.yml

index 681abdc8bc90173fdb233b14d7c09a78f01348fd..e5f6f8b76c1e47d6f7e0c4c9c6c5e2c1f607efd3 100644 (file)
@@ -21,7 +21,7 @@ run:
        ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
        ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES256-SHA;
        ssl_prefer_server_ciphers on;
-       ssl_ecdh_curve secp384r1;
+       ssl_ecdh_curve secp384r1:prime256v1;
 
        ssl_certificate /shared/ssl/ssl.crt;
        ssl_certificate_key /shared/ssl/ssl.key;