Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- server {
- server_name load.sytes.net www.load.sytes.net;
- root /var/www/html/load.sytes.net/public;
- index index.php index.html;
- access_log /var/log/nginx/load.sytes.net.access.log;
- error_log /var/log/nginx/load.sytes.net.error.log;
- # Prevent access to hidden files
- location ~* /\.(?!well-known\/) {
- <------>deny all;
- }
- location /wp-admin {
- try_files $uri $uri/ =404;
- auth_basic "Administrator’s Area";
- auth_basic_user_file /etc/nginx/.htpasswd;.
- }
- # Prevent access to certain file extensions
- location ~\.(ini|log|conf)$ {
- <------>deny all;
- }
- # Enable WordPress Permananent Links
- location / {
- <------>try_files $uri $uri/ /index.php?$args;
- }
- location ~ \.php$ {
- include fastcgi_params;
- fastcgi_intercept_errors on;
- fastcgi_pass unix:/run/php/php7.4-fpm.sock;
- fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
- }
- listen 443 ssl; # managed by Certbot
- ssl_certificate /etc/letsencrypt/live/load.sytes.net/fullchain.pem; # managed by Certbot
- ssl_certificate_key /etc/letsencrypt/live/load.sytes.net/privkey.pem; # managed by Certbot
- include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
- ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
- }
- server {
- if ($host = load.sytes.net) {
- return 301 https://$host$request_uri;
- } # managed by Certbot
- server_name load.sytes.net www.load.sytes.net;
- listen 80;
- return 404; # managed by Certbot
- }
- *************************************************************************************************
- apt install -y nginx mc sudo
- systemctl restart nginx
- systemctl status nginx
- mkdir -p /web/sites/nginx.sytes.net/{www,log}
- chown -R www-data. /web/sites/
- openssl dhparam -out /etc/ssl/certs/dhparam.pem 2048
- Малый конфиг для установки ssl
- mcedit /etc/nginx/conf.d/nginx.sytes.net.conf
- server {
- listen 80;
- server_name nginx.sytes.net;
- root /web/sites/nginx.sytes.net/www/;
- index index.php index.html index.htm;
- access_log /web/sites/nginx.sytes.net/log/access.log;
- error_log /web/sites/nginx.sytes.net/log/error.log;
- location / {
- return 301 https://nginx.sytes.net$request_uri;
- }
- }
- sudo apt update
- sudo apt -y install snapd sudo
- sudo snap install core; sudo snap refresh core
- sudo snap install --classic certbot
- sudo ln -s /snap/bin/certbot /usr/bin/certbot
- sudo certbot --nginx
- ************************************************************
- После установки certbot заменить на этот
- mcedit /etc/nginx/conf.d/nginx.sytes.net.conf
- server {
- listen 80;
- server_name nginx.sytes.net;
- access_log /var/log/nginx/nginx.sytes.net-access.log;
- error_log /var/log/nginx/nginx.sytes.net-error.log;
- return 301 https://$server_name$request_uri; # редирект обычных запросов на https
- }
- server {
- listen 443 ssl http2;
- server_name nginx.sytes.net;
- access_log /var/log/nginx/nginx.sytes.net-ssl-access.log;
- error_log /var/log/nginx/nginx.sytes.net-ssl-error.log;
- ssl_certificate /etc/letsencrypt/live/nginx.sytes.net/fullchain.pem;
- ssl_certificate_key /etc/letsencrypt/live/nginx.sytes.net/privkey.pem;
- ssl_session_timeout 190m;
- ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
- ssl_dhparam /etc/ssl/certs/dhparam.pem;
- ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
- ssl_prefer_server_ciphers on;
- ssl_session_cache shared:SSL:10m;
- location / {
- proxy_pass http://10.20.7.125:80;
- proxy_set_header Host $host;
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement