nginx module: Add dhParams option

This commit is contained in:
Tristan Helmich 2016-02-01 17:30:43 +01:00 committed by Robin Gloster
parent 35d76a72ab
commit c61157b7e6
1 changed files with 8 additions and 0 deletions

View File

@ -37,6 +37,7 @@ let
ssl_ciphers ${cfg.sslCiphers};
ssl_ecdh_curve secp521r1;
ssl_prefer_server_ciphers on;
${optionalString (cfg.sslDhparam != null) "ssl_dhparam ${cfg.sslDhparam};"}
ssl_stapling on;
ssl_stapling_verify on;
@ -204,6 +205,13 @@ in
description = "Allowed TLS protocol versions.";
};
sslDhparam = mkOption {
type = types.nullOr types.path;
default = null;
example = literalExample "/path/to/dhparams.pem";
description = "Path to DH parameters file.";
};
virtualHosts = mkOption {
type = types.attrsOf (types.submodule (import ./vhost-options.nix {
inherit lib;