利用observatory.mozilla.org提高本站安全性
使用observatory.mozilla.org来分析了下网站, 发现Scan Summary的评价只有F,于是根据网站里面的解说稍稍改造了一下Web服务器设置, 如
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" Header set Content-Security-Policy "*" Header set X-Content-Type-Options "nosniff" Header set X-Frame-Options "SAMEORIGIN" Header set X-XSS-Protection "1; mode=block"
于是评价升到了A-。 Content-Security-Policy里面如果把外部调用的域名都加上的话,应该结果能拿到A, 不过测试起来太麻烦,所以现在就先凑合一下。
TLS Observatory的Scan Summary结果也是F,利用Mozilla SSL Configuration Generator增加了些参数
SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-CM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS #SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 #SSLHonorCipherOrder on #SSLCompression off #SSLSessionTickets off
也不见好转,不知道问什么?
有时间还需要再查查看。