SSL/TLS settings for nginx

ssl_protocols TLSv1.3 TLSv1.2;
ssl_prefer_server_ciphers on; 
ssl_ciphers ECHACHA20+POLY1305:ECDH+AESGCM:EDH+AESGCM;

# openssl dhparam -out /etc/nginx/dhparam.pem 4096
ssl_dhparam /etc/nginx/dhparam.pem;
ssl_ecdh_curve X448:secp521r1:secp384r1:prime256v1;

ssl_session_timeout  10m;
ssl_session_cache shared:SSL:10m;
ssl_session_tickets off;

ssl_stapling on;
ssl_stapling_verify on;

add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload";
add_header X-Frame-Options SAMEORIGIN;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-Protection "1; mode=block";