Skip to content

Commit b5d01fe

Browse files
committed
Require SNI for tls-v1 and tls-v1-1 subdomains for now. Addresses #176.
In particular, this helps avoid unexpected behaviour in modern browsers.
1 parent 466d11d commit b5d01fe

File tree

5 files changed

+6
-4
lines changed

5 files changed

+6
-4
lines changed

domains/protocol/ssl-v2.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ server {
1919

2020
server {
2121
listen 1002;
22-
server_name expired.{{ site.domain }};
22+
server_name ssl-v2.{{ site.domain }};
2323

2424
include {{ site.serving-path }}/nginx-includes/wildcard.normal.conf;
2525
include {{ site.serving-path }}/nginx-includes/ssl-v2.conf;

domains/protocol/ssl-v3.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ server {
1919

2020
server {
2121
listen 1003;
22-
server_name expired.{{ site.domain }};
22+
server_name ssl-v3.{{ site.domain }};
2323

2424
include {{ site.serving-path }}/nginx-includes/wildcard.normal.conf;
2525
include {{ site.serving-path }}/nginx-includes/ssl-v3.conf;

domains/protocol/tls-v1-1.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ server {
1919

2020
server {
2121
listen 1011;
22-
server_name expired.{{ site.domain }};
22+
server_name tls-v1-1.{{ site.domain }};
2323

2424
include {{ site.serving-path }}/nginx-includes/wildcard.normal.conf;
2525
include {{ site.serving-path }}/nginx-includes/tls-v1-1.conf;

domains/protocol/tls-v1.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ server {
1919

2020
server {
2121
listen 1010;
22-
server_name expired.{{ site.domain }};
22+
server_name tls-v1.{{ site.domain }};
2323

2424
include {{ site.serving-path }}/nginx-includes/wildcard.normal.conf;
2525
include {{ site.serving-path }}/nginx-includes/tls-v1.conf;

fallback.conf

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,8 @@ server {
1010

1111
server {
1212
listen 443;
13+
listen 1010; # TLS 1.0, which supports SNI
14+
listen 1011; # TLS 1.1, which supports SNI
1315
server_name *.{{ site.domain }};
1416

1517
include {{ site.serving-path }}/nginx-includes/wildcard.fallback.conf;

0 commit comments

Comments
 (0)