File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -13,7 +13,8 @@ import (
1313var fileKeys = []string {
1414 "/deis/platform/sshPrivateKey" ,
1515 "/deis/router/sslCert" ,
16- "/deis/router/sslKey" }
16+ "/deis/router/sslKey" ,
17+ "/deis/router/sslDhparam" }
1718
1819// b64Keys define config keys to be base64 encoded before stored
1920var b64Keys = []string {"/deis/platform/sshPrivateKey" }
Original file line number Diff line number Diff line change @@ -64,6 +64,7 @@ setting description
6464/deis/router/serverNameHashBucketSize nginx server_names_hash_bucket_size (default: 64)
6565/deis/router/sslCert cluster-wide SSL certificate
6666/deis/router/sslKey cluster-wide SSL private key
67+ /deis/router/sslDhparam cluster-wide SSL dhparam
6768/deis/router/workerProcesses nginx number of worker processes to start (default: auto i.e. available CPU cores)
6869/deis/router/proxyProtocol nginx PROXY protocol enabled
6970/deis/router/proxyRealIpCidr nginx IP with CIDR used by the load balancer in front of deis-router (default: 10.0.0.0/8)
Original file line number Diff line number Diff line change 1+ [template ]
2+ src = " dhparam.pem"
3+ dest = " /etc/ssl/dhparam.pem"
4+ uid = 0
5+ gid = 0
6+ mode = " 0644"
7+ keys = [
8+ " /deis/router" ,
9+ ]
10+ reload_cmd = " /opt/nginx/sbin/nginx -s reload"
Original file line number Diff line number Diff line change @@ -6,5 +6,8 @@ listen 80{{ if exists "/deis/router/proxyProtocol" }} proxy_protocol{{ end }};
66listen 443 ssl spdy{{ if exists "/deis/router/proxyProtocol" }} proxy_protocol{{ end }};
77ssl_certificate /etc/ssl/deis.cert;
88ssl_certificate_key /etc/ssl/deis.key;
9+ {{ if exists "/deis/router/sslDhparam" }}
10+ ssl_dhparam /etc/ssl/dhparam.pem;
11+ {{ end }}
912ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
1013{{ end }}
Original file line number Diff line number Diff line change 1+ {{ getv "/deis/router/sslDhparam" }}
You can’t perform that action at this time.
0 commit comments