Advertisement
Guest User

Untitled

a guest
May 26th, 2016
75
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.54 KB | None | 0 0
  1. upstream thelounge_public {
  2. server 10.8.10.101:9001;
  3. }
  4.  
  5. server {
  6. listen 80;
  7. listen [::]:80;
  8. server_name webchat.<removed>.net;
  9. return 301 https://$server_name$request_uri;
  10. }
  11.  
  12. server {
  13. listen 443 http2 ssl;
  14. listen [::]:443 http2 ssl;
  15. server_name webchat.<removed>.net;
  16.  
  17. ssl_certificate /usr/local/etc/nginx/ssl/webchat.<removed>.net.pem;
  18. ssl_certificate_key /usr/local/etc/nginx/ssl/webchat.<removed>.net.key;
  19. ssl_dhparam /usr/local/etc/nginx/ssl/dhparam.pem;
  20.  
  21. ssl_session_cache shared:SSL:20m;
  22. ssl_session_timeout 60m;
  23.  
  24. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  25. ssl_ciphers EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;
  26. ssl_prefer_server_ciphers on;
  27.  
  28. ssl_stapling on;
  29. ssl_stapling_verify on;
  30. ssl_trusted_certificate /usr/local/etc/nginx/ssl/trustchain.crt;
  31. resolver 8.8.8.8 8.8.4.4;
  32.  
  33. add_header Strict-Transport-Security "max-age=63072000";
  34.  
  35. location / {
  36. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  37. proxy_set_header Host $http_host;
  38. proxy_set_header X-NginX-Proxy true;
  39. proxy_http_version 1.1;
  40. proxy_set_header Upgrade $http_upgrade;
  41. proxy_set_header Connection "upgrade";
  42. proxy_max_temp_file_size 0;
  43. proxy_pass http://thelounge_public/;
  44. proxy_redirect off;
  45. proxy_read_timeout 240s;
  46. }
  47.  
  48. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement