Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- user www-data;
- worker_processes auto;
- error_log /var/log/nginx/nginx_eroors.log;
- pid /var/run/nginx.pid;
- worker_rlimit_nofile 8192;
- events {
- worker_connections 8192;
- multi_accept on;
- }
- http {
- ##LOG CUSTOM
- #log_format compression '$remote_addr - $remote_user [$time_local] ' '"$request" $status ' '"$http_referer" "$http_user_agent" ';
- log_format main '$remote_addr - $remote_user [$time_local] $request '
- '"$status" $body_bytes_sent "$http_referer" '
- '"$http_user_agent" "$http_x_forwarded_for" "$gzip_ratio"'
- ' "$connection" "$connection_requests" "$request_time"';
- client_max_body_size 256m;
- more_set_headers "Server: nginx linuxiarz.pl";
- sendfile on;
- tcp_nopush on;
- tcp_nodelay on;
- types_hash_max_size 100240;
- #upload_progress uploads 1m;
- vhost_traffic_status_zone;
- access_log /var/log/nginx/global_access.log;
- error_log /var/log/nginx/global_errors.log;
- # server_names_hash_bucket_size 64;
- # server_name_in_redirect off;
- include /etc/nginx/mime.types;
- default_type application/octet-stream;
- ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # Dropping SSLv3, ref: POODLE
- #ssl_prefer_server_ciphers on;
- upload_progress uploads 1m;
- keepalive_timeout 8;
- keepalive_requests 1000;
- lingering_time 20s;
- lingering_timeout 5s;
- keepalive_disable msie6;
- gzip on;
- gzip_vary on;
- gzip_disable "MSIE [1-6]\.";
- gzip_static on;
- gzip_min_length 1400;
- gzip_buffers 32 8k;
- gzip_http_version 1.0;
- gzip_comp_level 5;
- gzip_proxied any;
- gzip_types text/plain text/css text/xml application/javascript application/x-javascript application/xml application/xml+rss application/ecmascript application/json image/svg+xml;
- client_body_buffer_size 256k;
- client_body_in_file_only off;
- client_body_timeout 10s;
- client_header_buffer_size 64k;
- client_header_timeout 8s;
- connection_pool_size 512;
- directio 4m;
- ignore_invalid_headers on;
- large_client_header_buffers 8 64k;
- output_buffers 8 256k;
- postpone_output 1460;
- proxy_temp_path /tmp/nginx_proxy/;
- request_pool_size 32k;
- reset_timedout_connection on;
- send_timeout 15s;
- server_names_hash_bucket_size 64;
- ## Hide the Nginx version number.
- server_tokens off;
- ## Curve to use for ECDH.
- ssl_ecdh_curve secp521r1;
- ## Enable OCSP stapling. A better way to revocate server certificates.
- ssl_stapling on;
- ## Fill in with your own resolver.
- resolver 8.8.8.8;
- include /etc/nginx/conf.d/*.conf;
- include /etc/nginx/sites-enabled/*;
- include /etc/nginx/pagespeed.conf;
- #include /etc/nginx/geoip.conf;
- ## LogJam
- ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA';
- ssl_prefer_server_ciphers on;
- ssl_dhparam /etc/nginx/dhparams.pem;
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement