Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- server {
- listen 80 reuseport deferred;
- server_name onestopmarketing.club www.onestopmarketing.club 168.235.68.99;
- return 301 https://www.onestopmarketing.club$request_uri;
- }
- server {
- listen 443 http2 ;
- ssl on;
- ssl_certificate /etc/ssl/onestopmarketing.club.crt; #(or .pem)
- ssl_certificate_key /etc/ssl/onestopmarketing.club.key.nopass;
- server_name onestopmarketing.club ;
- return 301 $scheme://www.onestopmarketing.club$request_uri;
- }
- server {
- listen 443 ssl http2 default_server reuseport deferred;
- ssl_certificate /etc/ssl/onestopmarketing.club.crt; #(or .pem)
- ssl_certificate_key /etc/ssl/onestopmarketing.club.key.nopass;
- ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
- #keepalive_timeout 70;
- #ssl_ciphers ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4:HIGH:!MD5:!aNULL:!eNULL:!NULL:!DH:!EDH:!AESGCM;
- ssl_ciphers ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS;
- ssl_prefer_server_ciphers on;
- ssl_buffer_size 8k;
- ssl_session_cache shared:SSL:20m;
- ssl_dhparam /etc/ssl/dhparam.pem;
- ssl_session_timeout 45m;
- ssl_stapling on;
- ssl_stapling_verify on;
- ssl_trusted_certificate /etc/ssl/trustchain.crt;
- resolver 8.8.8.8 8.8.4.4 valid=300s;
- resolver_timeout 5s;
- add_header Strict-Transport-Security "max-age=31536000; includeSubDomains";
- server_name www.onestopmarketing.club;
- #rest of config goes there
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement