# {{ ansible_managed }} # certificate settings ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA'; ssl_prefer_server_ciphers on; ssl_protocols TLSv1.2; ssl_session_cache shared:SSL:10m; {% if nginx_tls_enabled and nginx_tls_ocsp_enabled %} ssl_stapling on; ssl_trusted_certificate /pfad/bundle.ca.pem; ssl_stapling_verify on; {% endif %}