Advertisement
Guest User

aaa

a guest
Mar 3rd, 2018
133
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.54 KB | None | 0 0
  1. server {
  2. listen 443 ssl http2;
  3. server_name www.filmszone.net;
  4.  
  5. # SSL
  6. ssl_certificate /etc/nginx/ssl/canhme_com/ssl-bundle.crt;
  7. ssl_certificate_key /etc/nginx/ssl/canhme_com/private.key;
  8. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  9. ssl_prefer_server_ciphers on;
  10. ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  11. rewrite ^(.*) https://filmszone.net$1 permanent;
  12. }
  13.  
  14. server {
  15. listen 80;
  16.  
  17. server_name filmszone.net www.filmszone.net;
  18. rewrite ^(.*) https://filmszone.net$1 permanent;
  19. }
  20.  
  21. server {
  22. listen 443 ssl http2 default_server;
  23.  
  24. # access_log off;
  25. access_log /home/filmszone.net/logs/access.log;
  26. # error_log off;
  27. error_log /home/filmszone.net/logs/error.log;
  28.  
  29. root /home/filmszone.net/public_html;
  30. index index.php index.html index.htm;
  31. server_name filmszone.net;
  32.  
  33. # SSL
  34. ssl_certificate /etc/nginx/ssl/canhme_com/ssl-bundle.crt;
  35. ssl_certificate_key /etc/nginx/ssl/canhme_com/private.key;
  36. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  37. ssl_prefer_server_ciphers on;
  38. ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  39.  
  40. # Improve HTTPS performance with session resumption
  41. ssl_session_cache shared:SSL:50m;
  42. ssl_session_timeout 1d;
  43.  
  44. # DH parameters
  45. ssl_dhparam /etc/nginx/ssl/dhparam.pem;
  46.  
  47. # Enable HSTS
  48. add_header Strict-Transport-Security "max-age=31536000" always;
  49.  
  50. location / {
  51. try_files $uri $uri/ /index.php?$args;
  52. }
  53.  
  54. # Custom configuration
  55. include /home/filmszone.net/public_html/*.conf;
  56.  
  57. location ~ \.php$ {
  58. fastcgi_split_path_info ^(.+\.php)(/.+)$;
  59. include /etc/nginx/fastcgi_params;
  60. fastcgi_pass 127.0.0.1:9000;
  61. fastcgi_index index.php;
  62. fastcgi_connect_timeout 1000;
  63. fastcgi_send_timeout 1000;
  64. fastcgi_read_timeout 1000;
  65. fastcgi_buffer_size 256k;
  66. fastcgi_buffers 4 256k;
  67. fastcgi_busy_buffers_size 256k;
  68. fastcgi_temp_file_write_size 256k;
  69. fastcgi_intercept_errors on;
  70. fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
  71. }
  72.  
  73. location /nginx_status {
  74. stub_status on;
  75. access_log off;
  76. allow 127.0.0.1;
  77. allow 45.77.160.140;
  78. deny all;
  79. }
  80.  
  81. location /php_status {
  82. fastcgi_pass 127.0.0.1:9000;
  83. fastcgi_index index.php;
  84. fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
  85. include /etc/nginx/fastcgi_params;
  86. allow 127.0.0.1;
  87. allow 45.77.160.140;
  88. deny all;
  89. }
  90.  
  91. # Disable .htaccess and other hidden files
  92. location ~ /\.(?!well-known).* {
  93. deny all;
  94. access_log off;
  95. log_not_found off;
  96. }
  97.  
  98. location = /favicon.ico {
  99. log_not_found off;
  100. access_log off;
  101. }
  102.  
  103. location = /robots.txt {
  104. allow all;
  105. log_not_found off;
  106. access_log off;
  107. }
  108.  
  109. location ~* \.(3gp|gif|jpg|jpeg|png|ico|wmv|avi|asf|asx|mpg|mpeg|mp4|pls|mp3|mid|wav|swf|flv|exe|zip|tar|rar|gz|tgz|bz2|uha|7z|doc|docx|xls|xlsx|pdf|iso|eot|svg|ttf|woff)$ {
  110. gzip_static off;
  111. add_header Pragma public;
  112. add_header Cache-Control "public, must-revalidate, proxy-revalidate";
  113. access_log off;
  114. expires 30d;
  115. break;
  116. }
  117.  
  118. location ~* \.(txt|js|css)$ {
  119. add_header Pragma public;
  120. add_header Cache-Control "public, must-revalidate, proxy-revalidate";
  121. access_log off;
  122. expires 30d;
  123. break;
  124. }
  125. }
  126.  
  127. server {
  128. listen 2017 ssl http2;
  129.  
  130. access_log off;
  131. log_not_found off;
  132. error_log /home/filmszone.net/logs/nginx_error.log;
  133.  
  134. root /home/filmszone.net/private_html;
  135. index index.php index.html index.htm;
  136. server_name filmszone.net;
  137.  
  138. error_page 497 https://$server_name:2017$request_uri;
  139.  
  140. # SSL
  141. ssl_certificate /etc/nginx/ssl/canhme_com/ssl-bundle.crt;
  142. ssl_certificate_key /etc/nginx/ssl/canhme_com/private.key;
  143. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  144. ssl_prefer_server_ciphers on;
  145. ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  146.  
  147. auth_basic "Restricted";
  148. auth_basic_user_file /home/filmszone.net/private_html/hocvps/.htpasswd;
  149.  
  150. location / {
  151. autoindex on;
  152. try_files $uri $uri/ /index.php;
  153. }
  154.  
  155. location ~ \.php$ {
  156. fastcgi_split_path_info ^(.+\.php)(/.+)$;
  157. include /etc/nginx/fastcgi_params;
  158. fastcgi_pass 127.0.0.1:9000;
  159. fastcgi_index index.php;
  160. fastcgi_connect_timeout 1000;
  161. fastcgi_send_timeout 1000;
  162. fastcgi_read_timeout 1000;
  163. fastcgi_buffer_size 256k;
  164. fastcgi_buffers 4 256k;
  165. fastcgi_busy_buffers_size 256k;
  166. fastcgi_temp_file_write_size 256k;
  167. fastcgi_intercept_errors on;
  168. fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
  169. }
  170.  
  171. location ~ /\. {
  172. deny all;
  173. }
  174. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement