Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- server {
- server_name domain.net *.domain.net;
- return 301 https://www.domain.net$request_uri;
- }
- server {
- listen 111.111.111.111:443 ssl spdy default_server;
- server_name www.domain.net;
- ssl on;
- ssl_certificate /usr/local/nginx/conf/ssl/domain_net_positivessl/ssl-unified.crt;
- ssl_certificate_key /usr/local/nginx/conf/ssl/domain_net_positivessl/www_domain_net.key;
- ssl_dhparam /usr/local/nginx/conf/ssl/dhparam.pem;
- ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
- ssl_session_cache shared:SSL:20m;
- ssl_session_timeout 10m;
- ssl_prefer_server_ciphers on;
- ssl_ciphers ECDH+AESGCM:ECDH+AES256:ECDH+AES128:DH+3DES:RSA+3DES:!ADH:!AECDH:!MD5;
- add_header Alternate-Protocol 443:npn-spdy/3;
- spdy_headers_comp 1;
- ssl_buffer_size 4k;
- # ocsp stapling
- ssl_stapling on;
- ssl_stapling_verify on;
- ssl_stapling_responder http://ocsp.comodoca.com/;
- ssl_trusted_certificate /usr/local/nginx/conf/ssl/domain_net_positivessl/ssl-trusted.crt;
- resolver 8.8.8.8 8.8.4.4;
- # custom added
- add_header Strict-Transport-Security "max-age=31536000";
- add_header X-Content-Type-Options "nosniff";
- add_header X-XSS-Protection '1; mode=block';
- add_header X-Frame-Options SAMEORIGIN;
- # ngx_pagespeed & ngx_pagespeed handler
- include /usr/local/nginx/conf/pagespeed.conf;
- include /usr/local/nginx/conf/pagespeedhandler.conf;
- include /usr/local/nginx/conf/pagespeedstatslog.conf;
- # logs
- access_log off;
- error_log /home/nginx/domains/domain.net/log/error.log;
- root /home/nginx/domains/domain.net/public;
- # Start XenForo
- location / {
- include /usr/local/nginx/conf/block.conf;
- index index.php index.html index.htm;
- try_files $uri $uri/ /index.php?$uri&$args;
- }
- location /internal_data/ {
- internal;
- allow 127.0.0.1;
- deny all;
- }
- location /library/ {
- internal;
- allow 127.0.0.1;
- deny all;
- }
- location /data/taigachat/ {
- open_file_cache off;
- }
- # End Xenforo
- include /usr/local/nginx/conf/staticfiles.conf;
- include /usr/local/nginx/conf/php.conf;
- include /usr/local/nginx/conf/drop.conf;
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement