<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.eddyn.net/index.php?action=history&amp;feed=atom&amp;title=Strong_Ciphers_For_Common_Linux_Server_Configurations</id>
	<title>Strong Ciphers For Common Linux Server Configurations - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.eddyn.net/index.php?action=history&amp;feed=atom&amp;title=Strong_Ciphers_For_Common_Linux_Server_Configurations"/>
	<link rel="alternate" type="text/html" href="https://wiki.eddyn.net/index.php?title=Strong_Ciphers_For_Common_Linux_Server_Configurations&amp;action=history"/>
	<updated>2026-05-21T01:41:25Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.40.0</generator>
	<entry>
		<id>https://wiki.eddyn.net/index.php?title=Strong_Ciphers_For_Common_Linux_Server_Configurations&amp;diff=86&amp;oldid=prev</id>
		<title>Eddynetweb: Created page and added resources.</title>
		<link rel="alternate" type="text/html" href="https://wiki.eddyn.net/index.php?title=Strong_Ciphers_For_Common_Linux_Server_Configurations&amp;diff=86&amp;oldid=prev"/>
		<updated>2020-05-26T14:34:27Z</updated>

		<summary type="html">&lt;p&gt;Created page and added resources.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;These are strong ciphers for common Linux server applications.  &lt;br /&gt;
&lt;br /&gt;
== Examples ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;apache&amp;quot;&amp;gt;&lt;br /&gt;
SSLCipherSuite EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH&lt;br /&gt;
SSLProtocol All -SSLv2 -SSLv3 -TLSv1 -TLSv1.1&lt;br /&gt;
SSLHonorCipherOrder On&lt;br /&gt;
Header always set Strict-Transport-Security &amp;quot;max-age=63072000; includeSubDomains; preload&amp;quot;&lt;br /&gt;
Header always set X-Frame-Options DENY&lt;br /&gt;
Header always set X-Content-Type-Options nosniff&lt;br /&gt;
# Requires Apache &amp;gt;= 2.4&lt;br /&gt;
SSLCompression off&lt;br /&gt;
SSLUseStapling on&lt;br /&gt;
SSLStaplingCache &amp;quot;shmcb:logs/stapling-cache(150000)&amp;quot;&lt;br /&gt;
# Requires Apache &amp;gt;= 2.4.11&lt;br /&gt;
SSLSessionTickets Off &lt;br /&gt;
&amp;lt;/source&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;apache&amp;quot;&amp;gt;&lt;br /&gt;
ssl_protocols TLSv1.3;# Requires nginx &amp;gt;= 1.13.0 else use TLSv1.2&lt;br /&gt;
ssl_prefer_server_ciphers on; &lt;br /&gt;
ssl_dhparam /etc/nginx/dhparam.pem; # openssl dhparam -out /etc/nginx/dhparam.pem 4096&lt;br /&gt;
ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384;&lt;br /&gt;
ssl_ecdh_curve secp384r1; # Requires nginx &amp;gt;= 1.1.0&lt;br /&gt;
ssl_session_timeout  10m;&lt;br /&gt;
ssl_session_cache shared:SSL:10m;&lt;br /&gt;
ssl_session_tickets off; # Requires nginx &amp;gt;= 1.5.9&lt;br /&gt;
ssl_stapling on; # Requires nginx &amp;gt;= 1.3.7&lt;br /&gt;
ssl_stapling_verify on; # Requires nginx =&amp;gt; 1.3.7&lt;br /&gt;
resolver $DNS-IP-1 $DNS-IP-2 valid=300s;&lt;br /&gt;
resolver_timeout 5s; &lt;br /&gt;
add_header Strict-Transport-Security &amp;quot;max-age=63072000; includeSubDomains; preload&amp;quot;;&lt;br /&gt;
add_header X-Frame-Options DENY;&lt;br /&gt;
add_header X-Content-Type-Options nosniff;&lt;br /&gt;
add_header X-XSS-Protection &amp;quot;1; mode=block&amp;quot;;&lt;br /&gt;
add_header X-Robots-Tag none; &lt;br /&gt;
&amp;lt;/source&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;apache&amp;quot;&amp;gt;&lt;br /&gt;
ssl.honor-cipher-order = &amp;quot;enable&amp;quot;&lt;br /&gt;
ssl.cipher-list = &amp;quot;EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH&amp;quot;&lt;br /&gt;
ssl.use-compression = &amp;quot;disable&amp;quot;&lt;br /&gt;
setenv.add-response-header = (&lt;br /&gt;
    &amp;quot;Strict-Transport-Security&amp;quot; =&amp;gt; &amp;quot;max-age=63072000; includeSubDomains; preload&amp;quot;,&lt;br /&gt;
    &amp;quot;X-Frame-Options&amp;quot; =&amp;gt; &amp;quot;DENY&amp;quot;,&lt;br /&gt;
    &amp;quot;X-Content-Type-Options&amp;quot; =&amp;gt; &amp;quot;nosniff&amp;quot;&lt;br /&gt;
)&lt;br /&gt;
ssl.use-sslv2 = &amp;quot;disable&amp;quot;&lt;br /&gt;
ssl.use-sslv3 = &amp;quot;disable&amp;quot; &lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;/div&gt;</summary>
		<author><name>Eddynetweb</name></author>
	</entry>
</feed>