steven_zhu_25

Let's Encrypt Forum 130260

Aug 5th, 2020 (edited)
77
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Nginx 1.85 KB | None | 0 0
  1. server {
  2.  
  3.     # Listen to HTTP at port 80
  4.     listen [::]:80;
  5.     listen 80;
  6.     # Listen to HTTPS at port 443
  7.     listen [::]:443 ssl http2;
  8.     listen 443 ssl http2;
  9.  
  10.     # tell users to go to SSL version this time
  11.     if ($ssl_protocol = "") {
  12.         rewrite     ^   https://www.ravindrabhargava.com$request_uri? permanent;
  13.     }
  14.  
  15.     server_name ravindrabhargava.com www.ravindrabhargava.com;
  16.  
  17.     ssl_certificate /etc/letsencrypt/live/ravindrabhargava.com/fullchain.pem;
  18.     ssl_certificate_key /etc/letsencrypt/live/ravindrabhargava.com/privkey.pem;
  19.  
  20.     access_log /var/log/nginx/nginx/access.log;
  21.     error_log /var/log/nginx/nginx/error.log;
  22.  
  23.     root /usr/share/nginx/ravindrabhargava.com/;
  24.     index index.html index.php;
  25.  
  26.     location / {
  27.         try_files $uri $uri/ /index.php?$args;
  28.     }
  29.  
  30.     location ~ \.php$ {
  31.         try_files $uri =404;
  32.         fastcgi_split_path_info ^(.+\.php)(/.+)$;
  33.         fastcgi_pass unix:/run/php/php7.4-fpm.sock;
  34.         fastcgi_index index.php;
  35.         include fastcgi_params;
  36.  
  37.         add_header Content-Security-Policy "img-src * 'self' data: blob: https:; default-src 'self' https://*.googleapis.com https://*.googletagmanager.com https://*.google-analytics.com https://s.ytimg.com https://www.youtube.com https://www.ravindrabhargava.com https://*.googleapis.com https://*.gstatic.com https://*.gravatar.com https://*.w.org data: 'unsafe-inline' 'unsafe-eval';" always;
  38.         add_header X-Xss-Protection "1; mode=block" always;
  39.         add_header X-Frame-Options "SAMEORIGIN" always;
  40.         add_header X-Content-Type-Options "nosniff" always;
  41.         add_header Access-Control-Allow-Origin "https://www.ravindrabhargava.com";
  42.         add_header Referrer-Policy "origin-when-cross-origin" always;
  43.         add_header Strict-Transport-Security "max-age=31536000; includeSubdomains; preload";
  44.     }
  45. }
Add Comment
Please, Sign In to add comment