Advertisement
Guest User

Untitled

a guest
Aug 20th, 2019
111
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.67 KB | None | 0 0
  1. server {
  2. listen 80;
  3. listen [::]:80;
  4. server_name int.example.com;
  5.  
  6. location / {
  7. rewrite ^ https://$host$request_uri? permanent;
  8. }
  9.  
  10. #for certbot challenges (renewal process)
  11. location ~ /.well-known/acme-challenge {
  12. allow all;
  13. root /data/letsencrypt;
  14. }
  15. }
  16.  
  17.  
  18.  
  19. #https://int.example.com
  20. server {
  21. listen 443 ssl http2;
  22. listen [::]:443 ssl http2;
  23. server_name int.example.com;
  24. server_tokens off;
  25.  
  26. ssl_certificate /etc/letsencrypt/live/int.example.com/fullchain.pem;
  27. ssl_certificate_key /etc/letsencrypt/live/int.example.com/privkey.pem;
  28.  
  29. ssl_buffer_size 8k;
  30.  
  31. ssl_dhparam /etc/ssl/certs/dhparam-2048.pem;
  32.  
  33. ssl_protocols TLSv1.2 TLSv1.1 TLSv1;
  34. ssl_prefer_server_ciphers on;
  35.  
  36. ssl_ciphers ECDH+AESGCM:ECDH+AES256:ECDH+AES128:DH+3DES:!ADH:!AECDH:!MD5;
  37.  
  38. ssl_ecdh_curve secp384r1;
  39. ssl_session_tickets off;
  40.  
  41. # OCSP stapling
  42. ssl_stapling on;
  43. ssl_stapling_verify on;
  44. resolver 8.8.8.8;
  45.  
  46. ssl_certificate /etc/letsencrypt/live/int.example.com/fullchain.pem;
  47. ssl_certificate_key /etc/letsencrypt/live/int.example.com/privkey.pem;
  48.  
  49. root /usr/share/nginx/html;
  50. index index.html
  51.  
  52. return 301 https://int.example.com$request_uri;
  53.  
  54.  
  55.  
  56. location /homeassist/ {
  57.  
  58. proxy_pass http://192.168.1.199:8123;
  59. proxy_http_version 1.1;
  60. proxy_set_header Host $host;
  61. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  62. proxy_set_header Upgrade $http_upgrade;
  63. proxy_set_header Connection "upgrade";
  64. proxy_set_header X-Real-IP $remote_addr;
  65. include /etc/nginx/mime.types;
  66. include /etc/nginx/fastcgi_params;
  67. }
  68.  
  69.  
  70. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement