Unless there is a good reason to support it, the nginx configuration should be changed to disallow it. The Mozilla wiki has a good guide for [recommended cipher suites](https://wiki.mozilla.org/Security/Server_Side_TLS#Modern_compatibility). Hyneck Schlawack also has a [good guide](https://hynek.me/articles/hardening-your-web-servers-ssl-ciphers/).