使用observatory.mozilla.org来分析了下网站,
发现Scan Summary的评价只有F,于是根据网站里面的解说稍稍改造了一下Web服务器设置,
如
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Header set Content-Security-Policy "*"
Header set X-Content-Type-Options "nosniff"
Header set X-Frame-Options "SAMEORIGIN"
Header set X-XSS-Protection "1; mode=block"
于是评价升到了A-。
Content-Security-Policy里面如果把外部调用的域名都加上的话,应该结果能拿到A,
不过测试起来太麻烦,所以现在就先凑合一下。
支 持 本 站: 捐赠服务器等运维费用,需要您的支持!
TLS Observatory的Scan Summary结果也是F,利用Mozilla SSL Configuration Generator增加了些参数
SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-CM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS
#SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
#SSLHonorCipherOrder on
#SSLCompression off
#SSLSessionTickets off
也不见好转,不知道问什么?
有时间还需要再查查看。
支 持 本 站: 捐赠服务器等运维费用,需要您的支持!
留言簿