Skip to content

Commit 85f5475

Browse files
author
Kristan Kenney
authored
Merge pull request hestiacp#1316 from myrevery/main
[Security] Avoid SNI leak (for the server)
2 parents 1b63456 + 3a6d327 commit 85f5475

File tree

2 files changed

+3
-1
lines changed

2 files changed

+3
-1
lines changed

install/deb/nginx/unassigned.inc

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,7 @@ server {
3737
server_name _;
3838
ssl_certificate /usr/local/hestia/ssl/certificate.crt;
3939
ssl_certificate_key /usr/local/hestia/ssl/certificate.key;
40+
ssl_reject_handshake on;
4041

4142
return 301 http://$host$request_uri;
4243

install/deb/templates/web/nginx/proxy_ip.tpl

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,10 +13,11 @@ server {
1313
}
1414

1515
server {
16-
listen %ip%:%proxy_ssl_port% ssl http2;
16+
listen %ip%:%proxy_ssl_port% ssl http2 default;
1717
server_name _;
1818
ssl_certificate /usr/local/hestia/ssl/certificate.crt;
1919
ssl_certificate_key /usr/local/hestia/ssl/certificate.key;
20+
ssl_reject_handshake on;
2021
2122
return 301 http://$host$request_uri;
2223

0 commit comments

Comments
 (0)