server-configs-nginx/h5bp/ssl
Ewout van Mansom 9b369d23a5 Add eleptic curves for modern profile preset
prime256v1 (NIST P-256), secp384r1 (NIST P-384) and secp521r1 (NIST P-521) have been deemed insecure as per Daniel J. Bernstein's research (https://cr.yp.to/newelliptic/nistecc-20160106.pdf, https://safecurves.cr.yp.to/).

Despite that, the adoption of X25519 is too slim. Limiting to that curve would mean dropping compatibility with Safari, Edge and Internet Explorer.
2018-11-30 10:21:38 +01:00
..
certificate_files.conf Split SSL config 2018-11-29 10:39:33 +01:00
ocsp_stapling.conf Split SSL config 2018-11-29 10:39:33 +01:00
policy_intermediate.conf Split SSL config 2018-11-29 10:39:33 +01:00
policy_modern.conf Add eleptic curves for modern profile preset 2018-11-30 10:21:38 +01:00
ssl_engine.conf Split SSL config 2018-11-29 10:39:33 +01:00