利用observatory.mozilla.org提高本站安全性

  • 发布时间:
  • 作者:
  • 主题:

使用observatory.mozilla.org来分析了下网站,
发现Scan Summary的评价只有F,于是根据网站里面的解说稍稍改造了一下Web服务器设置,


Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Header set Content-Security-Policy "*"
Header set X-Content-Type-Options "nosniff"
Header set X-Frame-Options "SAMEORIGIN"
Header set X-XSS-Protection "1; mode=block"

于是评价升到了A-。
Content-Security-Policy里面如果把外部调用的域名都加上的话,应该结果能拿到A,
不过测试起来太麻烦,所以现在就先凑合一下。

TLS Observatory的Scan Summary结果也是F,利用Mozilla SSL Configuration Generator增加了些参数


SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-CM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS
#SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
#SSLHonorCipherOrder on
#SSLCompression off
#SSLSessionTickets off

也不见好转,不知道问什么?

有时间还需要再查查看。