مجاني · الشبكات والبنية التحتية لتقنية المعلومات
مولّد إعدادات TLS / SSL.
أنشئ إعدادات HTTPS آمنة لـ Nginx وApache وHAProxy وCaddy: TLS 1.2 و1.3 وخوارزميات تشفير بسرية أمامية وHSTS وHTTP/2 وHTTP/3.
Configuration
server {
listen 80;
listen [::]:80;
server_name example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
listen [::]:443 ssl;
http2 on;
server_name example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305;
ssl_prefer_server_ciphers off;
ssl_ecdh_curve X25519:prime256v1:secp384r1;
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:10m;
ssl_session_tickets off;
add_header Strict-Transport-Security "max-age=63072000" always;
}- TLS 1.2 is limited to forward-secret AEAD cipher suites (ECDHE with AES-GCM or ChaCha20-Poly1305). TLS 1.3 suites are all modern and need no list.
- Session tickets are off so that a stolen ticket key cannot decrypt past sessions; session caching keeps resumption fast.
- OCSP stapling is omitted: Let’s Encrypt stopped OCSP in 2025 and browsers rely on other revocation mechanisms. Add it if your CA still provides OCSP.
- Verify after reloading with testssl.sh or an online TLS scanner.
طريقة الاستخدام: مولّد إعدادات TLS / SSL
أدخل بياناتك أو اختر الملف. عدّل الخيارات ثم أنشئ النتيجة وراجعها قبل النسخ أو التنزيل.
الحدود والصيغ المدعومة
تُعالج بياناتك على جهازك.
ملاحظات تقنية بالإنجليزية
Original configuration following current best practice; verify with testssl.sh or a TLS scanner. Post-quantum hybrid key exchange needs OpenSSL 3.5 or later. Everything is calculated in your browser; nothing is sent or probed on the network.
The profile chooses protocol versions and, for TLS 1.2, AEAD cipher suites with ECDHE key exchange; the rest of the file adds certificates, redirects, session settings and headers in each server’s syntax.
The intermediate profile for Nginx enables TLS 1.2 and 1.3 with ECDHE AES-GCM and ChaCha20 suites, disables session tickets and redirects HTTP to HTTPS.