Skip to content
Cyberside
← Blog

Hardening

Hardening nginx in 2026 — 12 steps to SSL Labs A+

2026-07-12

Essentials

1. Disable TLS 1.0/1.1

2. HSTS with preload

3. CSP with nonce (no unsafe-inline scripts)

4. server_tokens off

5. COOP / CORP / COEP deliberately

6. security.txt

7. Rate-limit on auth

8. Logs without secrets

Also: cipher suites, OCSP, backup cert path.

Porozmawiajmy o Twoim projekcie