Nginx提高安全与性能的最好配置详解
主要展示在Nginx中配置X-Frame-Options、X-XSS-Protection、X-Content-Type-Options、Strict-Transport-Security、https等安全配置。
Nginx.conf配置如下
#不要将Nginx版本号在错误页面或服务器头部中显示 server_tokensoff; #不允许页面从框架frame或iframe中显示,这样能避免clickjacking #http://en.wikipedia.org/wiki/Clickjacking #如果你允许[i]frames,你能使用SAMEORIGIN或在ALLOW-FROM中设置你的允许的url #https://developer.mozilla.org/en-US/docs/HTTP/X-Frame-Options add_headerX-Frame-OptionsSAMEORIGIN; #当你的网站是用户提供的内容比如博客论坛等,使用X-Content-Type-Options:nosniff头部, #这是为了失效某些浏览器的内容类型探嗅 #https://www.owasp.org/index.php/List_of_useful_HTTP_headers #当前支持IE>8以上版本http://blogs.msdn.com/b/ie/archive/2008/09/02/ie8-security-part-vi-beta-2-update.aspx #http://msdn.microsoft.com/en-us/library/ie/gg622941(v=vs.85).aspx #Firefoxhttps://bugzilla.mozilla.org/show_bug.cgi?id=471020 add_headerX-Content-Type-Optionsnosniff; #防止跨站脚本Cross-sitescripting(XSS),目前已经被大多数浏览器支持 #默认是激活的,如果被用户失效,可以使用这个配置激活。 #https://www.owasp.org/index.php/List_of_useful_HTTP_headers add_headerX-XSS-Protection"1;mode=block"; #激活内容安全策略ContentSecurityPolicy(CSP),大部分浏览器支持 #告诉浏览器只能从本域名和你显式指定的网址下载脚本。 #http://www.html5rocks.com/en/tutorials/security/content-security-policy/#inline-code-considered-harmful add_headerContent-Security-Policy"default-src'self';script-src'self''unsafe-inline''unsafe-eval'https://ssl.google-analytics.comhttps://assets.zendesk.comhttps://connect.facebook.net;img-src'self'https://ssl.google-analytics.comhttps://s-static.ak.facebook.comhttps://assets.zendesk.com;style-src'self''unsafe-inline'https://fonts.googleapis.comhttps://assets.zendesk.com;font-src'self'https://themes.googleusercontent.com;frame-srchttps://assets.zendesk.comhttps://www.facebook.comhttps://s-static.ak.facebook.comhttps://tautt.zendesk.com;object-src'none'"; server{ listen443ssldefaultdeferred; server_name.forgott.com; ssl_certificate/etc/nginx/ssl/star_forgott_com.crt; ssl_certificate_key/etc/nginx/ssl/star_forgott_com.key; #激活会话重续提高https性能 #http://vincent.bernat.im/en/blog/2011-ssl-session-reuse-rfc5077.html ssl_session_cacheshared:SSL:50m; ssl_session_timeout5m; #Diffie-HellmanparameterforDHEciphersuites,recommended2048bits ssl_dhparam/etc/nginx/ssl/dhparam.pem; #激活服务器端保护免于BEAST攻击 #http://blog.ivanristic.com/2013/09/is-beast-still-a-threat.html ssl_prefer_server_cipherson; #失效SSLv3(自nginx0.8.19默认激活)http://en.wikipedia.org/wiki/Secure_Sockets_Layer#SSL_3.0 ssl_protocolsTLSv1TLSv1.1TLSv1.2; #为保密性和相容性选择密码 #http://blog.ivanristic.com/2013/08/configuring-apache-nginx-and-openssl-for-forward-secrecy.html ssl_ciphers"ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"; #激活ocspstapling(一种机制:一个网站可以保护隐私可扩展的方式传达的证书撤销信息给访问者)mechanismbywhichasitecanconveycertificaterevocationinformationtovisitorsinaprivacy-preserving,scalablemanner) #http://blog.mozilla.org/security/2013/07/29/ocsp-stapling-in-firefox/ resolver8.8.8.8; ssl_staplingon; ssl_trusted_certificate/etc/nginx/ssl/star_forgott_com.crt; #配置激活HSTS(HTTPStrictTransportSecurity)https://developer.mozilla.org/en-US/docs/Security/HTTP_Strict_Transport_Security #避免sslstrippinghttps://en.wikipedia.org/wiki/SSL_stripping#SSL_stripping add_headerStrict-Transport-Security"max-age=31536000;includeSubdomains;"; #...therestofyourconfiguration } #redirectallhttptraffictohttps server{ listen80; server_name.forgott.com; return301https://$host$request_uri; }
以上就是本文的全部内容,希望对大家的学习有所帮助,也希望大家多多支持毛票票。