Advertisement
Guest User

Untitled

a guest
Apr 24th, 2017
62
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.31 KB | None | 0 0
  1. server {
  2. listen 80;
  3. listen [::]:80;
  4. server_name example.com;
  5. return 301 https://$server_name$request_uri;
  6. }
  7.  
  8. server {
  9. listen 443 ssl;
  10. listen [::]:443 ssl;
  11. server_name example.com;
  12.  
  13. ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
  14. ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
  15.  
  16. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  17. ssl_prefer_server_ciphers on;
  18. ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";
  19. ssl_ecdh_curve secp384r1;
  20. ssl_session_cache shared:SSL:10m;
  21. ssl_session_tickets off;
  22. ssl_stapling on;
  23. ssl_stapling_verify on;
  24. resolver 8.8.8.8 8.8.4.4 valid=300s;
  25. resolver_timeout 5s;
  26. add_header Strict-Transport-Security "max-age=63072000; includeSubdomains";
  27. add_header X-Frame-Options DENY;
  28. add_header X-Content-Type-Options nosniff;
  29.  
  30. ssl_dhparam /etc/ssl/certs/dhparam.pem;
  31.  
  32. location / {
  33. proxy_pass http://localhost:3010;
  34. proxy_http_version 1.1;
  35. proxy_set_header Upgrade $http_upgrade;
  36. proxy_set_header Connection 'upgrade';
  37. proxy_set_header Host $host;
  38. proxy_cache_bypass $http_upgrade;
  39. }
  40. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement