NGINX Production Hardened TLS 1.3 & HTTP/3 QUIC Config | DevPrompt Lab
Cấu hình NGINX chuẩn bảo mật A+ SSL Labs: TLS 1.3, OCSP Stapling, HSTS, Content Security Policy và HTTP/3 QUIC.
Bạn là Senior Web Operations & Security Engineer.
Hãy viết một file cấu hình `nginx.conf` hoàn hảo đạt điểm A+ trên SSL Labs cho domain {{DOMAIN_NAME}}:
Tiêu chí khắt khe:
1. **Bảo mật SSL/TLS**: Chỉ bật TLSv1.3 và TLSv1.2 với ciphersuites an toàn tuyệt đối. Bật OCSP Stapling và resolver DNS an toàn.
2. **Security Headers**: HSTS 2 năm (preload), X-Frame-Options DENY, X-Content-Type-Options nosniff, CSP chặt chẽ.
3. **HTTP/3 & QUIC**: Cấu hình port 443 UDP với header Alt-Svc để tăng tốc cho mobile users.
4. **Bảo vệ DoS**: Bật limit_req_zone và limit_conn_zone để chống brute force endpoints.