Advertisement
kazeuraki

vietphuong.info.conf

Jan 18th, 2017
154
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. server {
  2.     listen   443 ssl http2;
  3.     server_name www.vietphuong.info;
  4.  
  5.     # SSL
  6.         ssl_certificate /etc/nginx/ssl/vietphuong_info/vp-ssl-bundle.crt;
  7.         ssl_certificate_key /etc/nginx/ssl/vietphuong_info/vietphuong.info.key;
  8.         ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  9.         ssl_prefer_server_ciphers on;
  10.     ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  11.  
  12.     rewrite ^(.*) https://vietphuong.info$1 permanent;
  13. }
  14. server {
  15.     listen   80;
  16.    
  17.     server_name vietphuong.info www.vietphuong.info;
  18.     rewrite ^(.*) https://vietphuong.info$1 permanent;
  19.         }
  20. server {
  21.     listen   443 ssl http2;
  22.  
  23.         # access_log off;
  24.     access_log /home/vietphuong.info/logs/access.log;
  25.         # error_log off;
  26.         error_log /home/vietphuong.info/logs/error.log;
  27.    
  28.         root /home/vietphuong.info/public_html;
  29.     index index.php index.html index.htm;
  30.         server_name vietphuong.info;
  31.     # SSL
  32.         ssl_certificate /etc/nginx/ssl/vietphuong_info/vp-ssl-bundle.crt;
  33.         ssl_certificate_key /etc/nginx/ssl/vietphuong_info/vietphuong.info.key;
  34.         ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  35.         ssl_prefer_server_ciphers on;
  36.     ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  37.  
  38.         ## OCSP Stapling
  39.         resolver 127.0.0.1;
  40.         ssl_stapling on;
  41.         ssl_stapling_verify on;
  42.         ssl_trusted_certificate /etc/nginx/ssl/vietphuong_info/vp-ssl-bundle.crt;
  43.  
  44.         # Improve HTTPS performance with session resumption
  45.         ssl_session_cache shared:SSL:50m;
  46.         ssl_session_timeout 1d;
  47.      
  48.         # DH parameters
  49.         ssl_dhparam /etc/nginx/cert/dhparam.pem;
  50.  
  51.         # Enable HSTS (https://developer.mozilla.org/en-US/docs/Security/HTTP_Strict_Transport_Security)
  52.         add_header Strict-Transport-Security "max-age=31536000" always;
  53.         location / {
  54.         try_files $uri $uri/ /index.php?$args;
  55.     }
  56.    
  57.     # Custom configuration
  58.     include /home/vietphuong.info/public_html/*.conf;
  59.  
  60.         location ~ \.php$ {
  61.         fastcgi_split_path_info ^(.+\.php)(/.+)$;
  62.             include /etc/nginx/fastcgi_params;
  63.             fastcgi_pass 127.0.0.1:9000;
  64.             fastcgi_index index.php;
  65.         fastcgi_connect_timeout 300;
  66.         fastcgi_send_timeout 300;
  67.         fastcgi_read_timeout 300;
  68.         fastcgi_buffer_size 32k;
  69.         fastcgi_buffers 8 16k;
  70.         fastcgi_busy_buffers_size 32k;
  71.         fastcgi_temp_file_write_size 32k;
  72.         fastcgi_intercept_errors on;
  73.             fastcgi_param SCRIPT_FILENAME /home/vietphuong.info/public_html$fastcgi_script_name;
  74.         }
  75.     location ~ /\. {
  76.         deny all;
  77.     }
  78.     location = /favicon.ico {
  79.         log_not_found off;
  80.         access_log off;
  81.     }
  82.     location = /robots.txt {
  83.         allow all;
  84.         log_not_found off;
  85.         access_log off;
  86.     }
  87.     location ~* \.(3gp|gif|jpg|jpeg|png|ico|wmv|avi|asf|asx|mpg|mpeg|mp4|pls|mp3|mid|wav|swf|flv|exe|zip|tar|rar|gz|tgz|bz2|uha|7z|doc|docx|xls|xlsx|pdf|iso|eot|svg|ttf|woff)$ {
  88.         gzip_static off;
  89.         add_header Pragma public;
  90.         add_header Cache-Control "public, must-revalidate, proxy-revalidate";
  91.         access_log off;
  92.         expires 30d;
  93.         break;
  94.         }
  95.  
  96.         location ~* \.(txt|js|css)$ {
  97.             add_header Pragma public;
  98.         add_header Cache-Control "public, must-revalidate, proxy-revalidate";
  99.         access_log off;
  100.         expires 30d;
  101.         break;
  102.         }
  103.     }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement