|  | @@ -9,6 +9,12 @@ server {
 | 
		
	
		
			
			| 9 | 9 |      listen 443 ssl;
 | 
		
	
		
			
			| 10 | 10 |      server_name jitsi-meet.example.com;
 | 
		
	
		
			
			| 11 | 11 |  
 | 
		
	
		
			
			|  | 12 | +    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
 | 
		
	
		
			
			|  | 13 | +    ssl_prefer_server_ciphers on;
 | 
		
	
		
			
			|  | 14 | +    ssl_ciphers "EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA256:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EDH+aRSA+AESGCM:EDH+aRSA+SHA256:EDH+aRSA:EECDH:!aNULL:!eNULL:!MEDIUM:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS:!RC4:!SEED";
 | 
		
	
		
			
			|  | 15 | +
 | 
		
	
		
			
			|  | 16 | +    add_header Strict-Transport-Security "max-age=31536000";
 | 
		
	
		
			
			|  | 17 | +
 | 
		
	
		
			
			| 12 | 18 |      ssl_certificate /var/lib/prosody/jitsi-meet.example.com.crt;
 | 
		
	
		
			
			| 13 | 19 |      ssl_certificate_key /var/lib/prosody/jitsi-meet.example.com.key;
 | 
		
	
		
			
			| 14 | 20 |  
 |