Advertisement
Guest User

Untitled

a guest
Jun 26th, 2017
124
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.60 KB | None | 0 0
  1. server {
  2. listen 443 ssl http2;
  3. server_name www.musicisourdrug.net;
  4.  
  5. # SSL
  6. ssl_certificate /etc/nginx/ssl/musicisourdrug_net/ssl-bundle.crt;
  7. ssl_certificate_key /etc/nginx/ssl/musicisourdrug_net/private.key;
  8. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  9. ssl_prefer_server_ciphers on;
  10. ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  11. rewrite ^(.*) https://musicisourdrug.net$1 permanent;
  12. }
  13. server {
  14. listen 80;
  15. server_name musicisourdrug.net www.musicisourdrug.net;
  16. rewrite ^(.*) https://musicisourdrug.net$1 permanent;
  17. # SSL
  18. ssl_certificate /etc/nginx/ssl/musicisourdrug_net/ssl-bundle.crt;
  19. ssl_certificate_key /etc/nginx/ssl/musicisourdrug_net/private.key;
  20. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  21. ssl_prefer_server_ciphers on;
  22. ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  23.  
  24. # Improve HTTPS performance with session resumption
  25. ssl_session_cache shared:SSL:50m;
  26. ssl_session_timeout 1d;
  27.  
  28. # DH parameters
  29. ssl_dhparam /etc/nginx/ssl/dhparam.pem;
  30.  
  31. # Enable HSTS
  32. add_header Strict-Transport-Security "max-age=31536000" always;
  33. rewrite ^(.*) http://musicisourdrug.net$1 permanent;
  34. }
  35.  
  36. server {
  37. listen 443 ssl http2 default_server;
  38.  
  39. # access_log off;
  40. access_log /home/musicisourdrug.net/logs/access.log;
  41. # error_log off;
  42. error_log /home/musicisourdrug.net/logs/error.log;
  43.  
  44. root /home/musicisourdrug.net/public_html;
  45. index index.php index.html index.htm;
  46. server_name musicisourdrug.net;
  47.  
  48. location / {
  49. try_files $uri $uri/ /index.php?$args;
  50. }
  51.  
  52. # Custom configuration
  53. include /home/musicisourdrug.net/public_html/*.conf;
  54.  
  55. location ~ \.php$ {
  56. fastcgi_split_path_info ^(.+\.php)(/.+)$;
  57. include /etc/nginx/fastcgi_params;
  58. fastcgi_pass 127.0.0.1:9000;
  59. fastcgi_index index.php;
  60. fastcgi_connect_timeout 1000;
  61. fastcgi_send_timeout 1000;
  62. fastcgi_read_timeout 1000;
  63. fastcgi_buffer_size 256k;
  64. fastcgi_buffers 4 256k;
  65. fastcgi_busy_buffers_size 256k;
  66. fastcgi_temp_file_write_size 256k;
  67. fastcgi_intercept_errors on;
  68. fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
  69. }
  70.  
  71. location /nginx_status {
  72. stub_status on;
  73. access_log off;
  74. allow 127.0.0.1;
  75. allow 5.189.188.25;
  76. deny all;
  77. }
  78.  
  79. location /php_status {
  80. fastcgi_pass 127.0.0.1:9000;
  81. fastcgi_index index.php;
  82. fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
  83. include /etc/nginx/fastcgi_params;
  84. allow 127.0.0.1;
  85. allow 5.189.188.25;
  86. deny all;
  87. }
  88.  
  89. location ~ /\. {
  90. deny all;
  91. }
  92.  
  93. location = /favicon.ico {
  94. log_not_found off;
  95. access_log off;
  96. }
  97.  
  98. location = /robots.txt {
  99. allow all;
  100. log_not_found off;
  101. access_log off;
  102. }
  103.  
  104. location ~* \.(3gp|gif|jpg|jpeg|png|ico|wmv|avi|asf|asx|mpg|mpeg|mp4|pls|mp3|mid|wav|swf|flv|exe|zip|tar|rar|gz|tgz|bz2|uha|7z|doc|docx|xls|xlsx|pdf|iso|eot|svg|ttf|woff)$ {
  105. gzip_static off;
  106. add_header Pragma public;
  107. add_header Cache-Control "public, must-revalidate, proxy-revalidate";
  108. access_log off;
  109. expires 30d;
  110. break;
  111. }
  112.  
  113. location ~* \.(txt|js|css)$ {
  114. add_header Pragma public;
  115. add_header Cache-Control "public, must-revalidate, proxy-revalidate";
  116. access_log off;
  117. expires 30d;
  118. break;
  119. }
  120. }
  121.  
  122. server {
  123. listen 2006 ssl http2;
  124. access_log off;
  125. log_not_found off;
  126. error_log /home/musicisourdrug.net/logs/nginx_error.log;
  127.  
  128. root /home/musicisourdrug.net/private_html;
  129. index index.php index.html index.htm;
  130. server_name musicisourdrug.net;
  131. error_page 497 https://$server_name:2017$request_uri;
  132.  
  133. # SSL
  134. ssl_certificate /etc/nginx/ssl/musicisourdrug_net/ssl-bundle.crt;
  135. ssl_certificate_key /etc/nginx/ssl/musicisourdrug_net/private.key;
  136. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  137. ssl_prefer_server_ciphers on;
  138. ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  139.  
  140. auth_basic "Restricted";
  141. auth_basic_user_file /home/musicisourdrug.net/private_html/hocvps/.htpasswd;
  142.  
  143. location / {
  144. autoindex on;
  145. try_files $uri $uri/ /index.php;
  146. }
  147.  
  148. location ~ \.php$ {
  149. fastcgi_split_path_info ^(.+\.php)(/.+)$;
  150. include /etc/nginx/fastcgi_params;
  151. fastcgi_pass 127.0.0.1:9000;
  152. fastcgi_index index.php;
  153. fastcgi_connect_timeout 1000;
  154. fastcgi_send_timeout 1000;
  155. fastcgi_read_timeout 1000;
  156. fastcgi_buffer_size 256k;
  157. fastcgi_buffers 4 256k;
  158. fastcgi_busy_buffers_size 256k;
  159. fastcgi_temp_file_write_size 256k;
  160. fastcgi_intercept_errors on;
  161. fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
  162. }
  163.  
  164. location ~ /\. {
  165. deny all;
  166. }
  167. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement