use new path for TLS session ticket keys

This commit is contained in:
Daniel Micay 2025-11-30 22:08:30 -05:00
parent afbca6363e
commit a99d913044

View file

@ -59,11 +59,11 @@ http {
ssl_certificate_key /etc/letsencrypt/live/matrix.grapheneos.org/privkey.pem;
# maintained by rotate-session-ticket-keys in noswap tmpfs
ssl_session_ticket_key /etc/session-ticket-keys/4.key;
ssl_session_ticket_key /etc/session-ticket-keys/3.key;
ssl_session_ticket_key /etc/session-ticket-keys/2.key;
ssl_session_ticket_key /etc/session-ticket-keys/1.key;
ssl_session_ticket_key /etc/session-ticket-keys/next.key;
ssl_session_ticket_key /etc/tls/session-ticket-keys/4.key;
ssl_session_ticket_key /etc/tls/session-ticket-keys/3.key;
ssl_session_ticket_key /etc/tls/session-ticket-keys/2.key;
ssl_session_ticket_key /etc/tls/session-ticket-keys/1.key;
ssl_session_ticket_key /etc/tls/session-ticket-keys/next.key;
ssl_session_timeout 1d;
ssl_buffer_size 4k;