Advertisement
Guest User

Untitled

a guest
Mar 14th, 2014
332
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.18 KB | None | 0 0
  1.  
  2. server {
  3. server_name domain.net *.domain.net;
  4. return 301 https://www.domain.net$request_uri;
  5. }
  6.  
  7. server {
  8. listen 111.111.111.111:443 ssl spdy default_server;
  9. server_name www.domain.net;
  10.  
  11. ssl on;
  12. ssl_certificate /usr/local/nginx/conf/ssl/domain_net_positivessl/ssl-unified.crt;
  13. ssl_certificate_key /usr/local/nginx/conf/ssl/domain_net_positivessl/www_domain_net.key;
  14. ssl_dhparam /usr/local/nginx/conf/ssl/dhparam.pem;
  15.  
  16. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  17. ssl_session_cache shared:SSL:20m;
  18. ssl_session_timeout 10m;
  19. ssl_prefer_server_ciphers on;
  20. ssl_ciphers ECDH+AESGCM:ECDH+AES256:ECDH+AES128:DH+3DES:RSA+3DES:!ADH:!AECDH:!MD5;
  21. add_header Alternate-Protocol 443:npn-spdy/3;
  22. spdy_headers_comp 1;
  23. ssl_buffer_size 4k;
  24.  
  25. # ocsp stapling
  26. ssl_stapling on;
  27. ssl_stapling_verify on;
  28. ssl_stapling_responder http://ocsp.comodoca.com/;
  29. ssl_trusted_certificate /usr/local/nginx/conf/ssl/domain_net_positivessl/ssl-trusted.crt;
  30. resolver 8.8.8.8 8.8.4.4;
  31.  
  32. # custom added
  33. add_header Strict-Transport-Security "max-age=31536000";
  34. add_header X-Content-Type-Options "nosniff";
  35. add_header X-XSS-Protection '1; mode=block';
  36. add_header X-Frame-Options SAMEORIGIN;
  37.  
  38. # ngx_pagespeed & ngx_pagespeed handler
  39. include /usr/local/nginx/conf/pagespeed.conf;
  40. include /usr/local/nginx/conf/pagespeedhandler.conf;
  41. include /usr/local/nginx/conf/pagespeedstatslog.conf;
  42.  
  43. # logs
  44. access_log off;
  45. error_log /home/nginx/domains/domain.net/log/error.log;
  46. root /home/nginx/domains/domain.net/public;
  47.  
  48.  
  49. # Start XenForo
  50. location / {
  51.  
  52. include /usr/local/nginx/conf/block.conf;
  53.  
  54. index index.php index.html index.htm;
  55. try_files $uri $uri/ /index.php?$uri&$args;
  56. }
  57.  
  58. location /internal_data/ {
  59. internal;
  60. allow 127.0.0.1;
  61. deny all;
  62. }
  63.  
  64. location /library/ {
  65. internal;
  66. allow 127.0.0.1;
  67. deny all;
  68. }
  69.  
  70. location /data/taigachat/ {
  71. open_file_cache off;
  72. }
  73. # End Xenforo
  74.  
  75. include /usr/local/nginx/conf/staticfiles.conf;
  76. include /usr/local/nginx/conf/php.conf;
  77. include /usr/local/nginx/conf/drop.conf;
  78. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement