Advertisement
Guest User

Untitled

a guest
Jun 2nd, 2017
116
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.37 KB | None | 0 0
  1. server {
  2. listen 443 ssl http2;
  3. server_name www.anonyviet.com;
  4.  
  5. # SSL
  6. ssl_certificate /etc/ssl/anonyviet_com.crt;
  7. ssl_certificate_key /etc/ssl/private/anonyviet.com.key;
  8. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  9. ssl_prefer_server_ciphers on;
  10. ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  11. rewrite ^(.*) https://anonyviet.com$1 permanent;
  12. }
  13.  
  14. server {
  15. listen 80;
  16. server_name anonyviet.com www.anonyviet.com;
  17. rewrite ^(.*) https://anonyviet.com$1 permanent;
  18. }
  19.  
  20. server {
  21. listen 443 ssl http2;
  22.  
  23. access_log off;
  24. # access_log /home/anonyviet.com/logs/access.log;
  25. error_log off;
  26. # error_log /home/anonyviet.com/logs/error.log;
  27.  
  28. root /home/anonyviet.com/public_html;
  29. index index.php index.html index.htm;
  30. server_name anonyviet.com;
  31.  
  32. # SSL
  33. ssl_certificate /etc/ssl/anonyviet_com.crt;
  34. ssl_certificate_key /etc/ssl/private/anonyviet.com.key;
  35. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  36. ssl_prefer_server_ciphers on;
  37. ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  38.  
  39. # Improve HTTPS performance with session resumption
  40. ssl_session_cache shared:SSL:50m;
  41. ssl_session_timeout 1d;
  42.  
  43. # DH parameters
  44. ssl_dhparam /etc/ssl/dhparam.pem;
  45.  
  46. # Enable HSTS
  47. add_header Strict-Transport-Security "max-age=31536000" always;
  48.  
  49.  
  50.  
  51. location / {
  52. try_files $uri $uri/ /index.php?$args;
  53. }
  54.  
  55. # Custom configuration
  56. include /home/anonyviet.com/public_html/*.conf;
  57.  
  58. location ~ \.php$ {
  59. fastcgi_split_path_info ^(.+\.php)(/.+)$;
  60. include /etc/nginx/fastcgi_params;
  61. fastcgi_pass 127.0.0.1:9000;
  62. fastcgi_index index.php;
  63. fastcgi_connect_timeout 1000;
  64. fastcgi_send_timeout 1000;
  65. fastcgi_read_timeout 1000;
  66. fastcgi_buffer_size 256k;
  67. fastcgi_buffers 4 256k;
  68. fastcgi_busy_buffers_size 256k;
  69. fastcgi_temp_file_write_size 256k;
  70. fastcgi_intercept_errors on;
  71. fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
  72. }
  73. location /nginx_status {
  74. stub_status on;
  75. access_log off;
  76. allow 127.0.0.1;
  77. allow 103.63.213.156;
  78. deny all;
  79. }
  80. location /php_status {
  81. fastcgi_pass 127.0.0.1:9000;
  82. fastcgi_index index.php;
  83. fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
  84. include /etc/nginx/fastcgi_params;
  85. allow 127.0.0.1;
  86. allow 103.63.213.156;
  87. deny all;
  88. }
  89. location ~ /\. {
  90. deny all;
  91. }
  92. location = /favicon.ico {
  93. log_not_found off;
  94. access_log off;
  95. }
  96. location = /robots.txt {
  97. allow all;
  98. log_not_found off;
  99. access_log off;
  100. }
  101. location ~* \.(3gp|gif|jpg|jpeg|png|ico|wmv|avi|asf|asx|mpg|mpeg|mp4|pls|mp3|mid|wav|swf|flv|exe|zip|tar|rar|gz|tgz|bz2|uha|7z|doc|docx|xls|xlsx|pdf|iso|eot|svg|ttf|woff)$ {
  102. gzip_static off;
  103. add_header Pragma public;
  104. add_header Cache-Control "public, must-revalidate, proxy-revalidate";
  105. access_log off;
  106. expires 30d;
  107. break;
  108. }
  109.  
  110. location ~* \.(txt|js|css)$ {
  111. add_header Pragma public;
  112. add_header Cache-Control "public, must-revalidate, proxy-revalidate";
  113. access_log off;
  114. expires 30d;
  115. break;
  116. }
  117. }
  118.  
  119. server {
  120. listen 9999 ssl http2;
  121.  
  122. access_log off;
  123. log_not_found off;
  124. error_log /home/anonyviet.com/logs/nginx_error.log;
  125.  
  126. root /home/anonyviet.com/private_html;
  127. index index.php index.html index.htm;
  128. server_name anonyviet.com;
  129.  
  130. error_page 497 https://$server_name:9999$request_uri;
  131. # SSL
  132. ssl_certificate /etc/ssl/anonyviet_com.crt;
  133. ssl_certificate_key /etc/ssl/private/anonyviet.com.key;
  134. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  135. ssl_prefer_server_ciphers on;
  136. ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  137.  
  138. auth_basic "Restricted";
  139. auth_basic_user_file /home/anonyviet.com/private_html/hocvps/.htpasswd;
  140.  
  141. location / {
  142. autoindex on;
  143. try_files $uri $uri/ /index.php;
  144. }
  145.  
  146. location ~ \.php$ {
  147. fastcgi_split_path_info ^(.+\.php)(/.+)$;
  148. include /etc/nginx/fastcgi_params;
  149. fastcgi_pass 127.0.0.1:9000;
  150. fastcgi_index index.php;
  151. fastcgi_connect_timeout 1000;
  152. fastcgi_send_timeout 1000;
  153. fastcgi_read_timeout 1000;
  154. fastcgi_buffer_size 256k;
  155. fastcgi_buffers 4 256k;
  156. fastcgi_busy_buffers_size 256k;
  157. fastcgi_temp_file_write_size 256k;
  158. fastcgi_intercept_errors on;
  159. fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
  160. }
  161.  
  162. location ~ /\. {
  163. deny all;
  164. }
  165. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement