diff --git a/configuration/reverseproxy/nginx/dot-stream b/configuration/reverseproxy/nginx/dot-stream index 6e3c639..7874589 100644 --- a/configuration/reverseproxy/nginx/dot-stream +++ b/configuration/reverseproxy/nginx/dot-stream @@ -8,7 +8,9 @@ upstream dns { server { listen 853 ssl; listen [::]:853 ssl; - ssl_protocols TLSv1.3; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384; + ssl_prefer_server_ciphers off; ssl_certificate /go/to/ket/; ssl_certificate_key /go/to/ket/; proxy_pass dns;