- Eliminate version leakage: Set server_tokens off in nginx.conf to prevent disclosing vulnerable software versions.
- Strict modern cryptography: Enforce TLSv1.2 and TLSv1.3 exclusively to achieve an A+ grade on SSL Labs testing.
- OWASP defense headers: Inject HSTS (with preload), Content-Security-Policy, and X-Frame-Options DENY into response headers.
- Application rate limiting: Apply limit_req_zone on sensitive paths to prevent L7 HTTP flood abuse.
Nginx is one of the most deployed web servers and reverse proxies worldwide. However, default configs expose version strings and outdated cipher suites. To fortify the operating system before installing Nginx, check our Linux VPS Server Hardening guide.
1. OWASP Recommended HTTP Security Headers
The table below lists the essential security headers that must be injected by the reverse proxy to protect clients from XSS, Clickjacking, and protocol downgrade attacks:
Table 1: Essential HTTP Security Headers in Nginx and Mitigated Threats
| HTTP Header | Recommended Value | Mitigated Threat |
|---|---|---|
| Strict-Transport-Security (HSTS) | max-age=63072000; includeSubDomains; preload | SSL Stripping and unencrypted traffic eavesdropping |
| X-Frame-Options | DENY / SAMEORIGIN | Clickjacking and unauthorized iframe embedding |
| X-Content-Type-Options | nosniff | Browser MIME-sniffing vulnerabilities |
| Content-Security-Policy (CSP) | default-src 'self'; script-src 'self' | Cross-Site Scripting (XSS) and rogue script injection |
2. Mask Server Version (Server Tokens)
Preventing Information Disclosure denies attackers easy knowledge of specific software releases:
http {
# Disable version tokens in responses and default error pages
server_tokens off;
# Cap request body size
client_max_body_size 10M;
# Strict timeouts to mitigate Slowloris attacks
client_body_timeout 10s;
client_header_timeout 10s;
keepalive_timeout 65s;
send_timeout 10s;
}3. Enforce Strict SSL/TLS (TLS 1.2 and TLS 1.3)
Deprecate legacy SSLv3, TLS 1.0, and TLS 1.1, enforcing modern cipher suites with Perfect Forward Secrecy (PFS):
# Allowed protocols
ssl_protocols TLSv1.2 TLSv1.3;
# Modern cipher suites (Mozilla Modern Configuration)
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
ssl_prefer_server_ciphers off;
# Session cache
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 1d;
ssl_session_tickets off;
# Diffie-Hellman 4096-bit parameters
ssl_dhparam /etc/ssl/certs/dhparam.pem;
# OCSP Stapling
ssl_stapling on;
ssl_stapling_verify on;
resolver 1.1.1.1 8.8.8.8 valid=300s;
resolver_timeout 5s;4. Rate Limiting Against Abuse and L7 Floods
Applying request rate limits prevents brute-force attempts and application-layer DoS. For packet-level filtering, consult our DDoS Attack Mitigation on Linux guide.
# Memory zone tracking per IP
limit_req_zone $binary_remote_addr zone=api_limit:10m rate=10r/s;
server {
listen 443 ssl http2;
server_name jorgebyte.com;
location /api/ {
limit_req zone=api_limit burst=20 nodelay;
limit_req_status 429;
proxy_pass http://backend_upstream;
}
}5. Interlinking with Enterprise Architecture
Nginx acts as the edge Ingress Proxy terminating TLS and delegating requests to the Go API Gateway and backend microservices. You can inspect this data flow live in our Interactive Architecture Visualizer.