PasteZap
🌐 English
Free · No account

FREE · NETWORK & IT INFRASTRUCTURE

TLS / SSL Config Generator.

Generate secure HTTPS configuration for Nginx, Apache, HAProxy and Caddy: TLS 1.2/1.3, forward-secret ciphers, HSTS, HTTP/2 and HTTP/3.

Limits & supported formats

Original configuration following current best practice; verify with testssl.sh or a TLS scanner. Post-quantum hybrid key exchange needs OpenSSL 3.5 or later. Everything is calculated in your browser; nothing is sent or probed on the network.

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED
ProtocolsTLS 1.2 + 1.3nginx

Configuration

server {
    listen 80;
    listen [::]:80;
    server_name example.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl;
    listen [::]:443 ssl;
    http2 on;
    server_name example.com;

    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305;
    ssl_prefer_server_ciphers off;
    ssl_ecdh_curve X25519:prime256v1:secp384r1;
    ssl_session_timeout 1d;
    ssl_session_cache shared:SSL:10m;
    ssl_session_tickets off;
    add_header Strict-Transport-Security "max-age=63072000" always;
}
  • TLS 1.2 is limited to forward-secret AEAD cipher suites (ECDHE with AES-GCM or ChaCha20-Poly1305). TLS 1.3 suites are all modern and need no list.
  • Session tickets are off so that a stolen ticket key cannot decrypt past sessions; session caching keeps resumption fast.
  • OCSP stapling is omitted: Let’s Encrypt stopped OCSP in 2025 and browsers rely on other revocation mechanisms. Add it if your CA still provides OCSP.
  • Verify after reloading with testssl.sh or an online TLS scanner.

How to use TLS / SSL Config Generator

Pick the server, profile (intermediate or TLS 1.3 only), domain and certificate paths, then options such as HSTS, HTTP/3 and post-quantum key exchange.

How it works

The profile chooses protocol versions and, for TLS 1.2, AEAD cipher suites with ECDHE key exchange; the rest of the file adds certificates, redirects, session settings and headers in each server’s syntax.

Example

The intermediate profile for Nginx enables TLS 1.2 and 1.3 with ECDHE AES-GCM and ChaCha20 suites, disables session tickets and redirects HTTP to HTTPS.

Questions about TLS / SSL Config Generator

Is TLS / SSL Config Generator free, and do I need an account?

Yes. This tool is free to use in your browser without an account. Processing takes place on your device.

What are the limits and what should I check?

Original configuration following current best practice; verify with testssl.sh or a TLS scanner. Post-quantum hybrid key exchange needs OpenSSL 3.5 or later. Everything is calculated in your browser; nothing is sent or probed on the network. Review the result before using it in your work.

Is my input sent to a server?

Your input is processed in your browser and is not uploaded by this tool. Files and pasted text are cleared when the page is refreshed. Normal website requests are still required to load the page and its libraries. Read the privacy explanation.