diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Refuse unknown and spoofed hostnames in nginx.conf
Diffstat (limited to 'custom')
-rw-r--r--custom/servers/nginx.conf31
1 file changed, 31 insertions, 0 deletions
diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf
index f26598c..cf1e49f 100644
--- a/custom/servers/nginx.conf
+++ b/custom/servers/nginx.conf
@@ -80,6 +80,37 @@ http {
gzip_types text/css text/javascript text/plain application/atom+xml;
+ # Requests carrying a Host header this config does not serve, a raw IP or
+ # an invented name from a scanning bot, land in these two blocks and are
+ # dropped without a response. cgit keys its page cache on the Host header
+ # so clone URLs stay honest, which means every invented hostname reaching
+ # it would mint a cache entry of its own and evict a real page to make
+ # room. Refusing strangers here keeps the cache to the names the site
+ # actually answers to. 444 is nginx shorthand for closing the connection
+ # without replying.
+ server {
+ listen 80 default_server;
+ listen [::]:80 default_server;
+ server_name _;
+ return 444;
+ }
+
+ server {
+ listen 443 ssl default_server;
+ listen [::]:443 ssl default_server;
+ server_name _;
+ # Refuse the TLS handshake itself when the SNI name is unknown, which
+ # also spares this block from needing a certificate. Requires nginx
+ # 1.19.4 or newer. On older builds point ssl_certificate at any cert,
+ # a self-signed one included, and rely on the return below.
+ ssl_reject_handshake on;
+ # A client can still handshake against a real name and then send some
+ # other Host header. Those requests route here after the handshake,
+ # past the rejection above, so close them too.
+ return 444;
+ }
+
+
# Bounce plain HTTP up to HTTPS. Delete this whole server block if you
# serve plain HTTP only.
server {