webman项目nginx配置,ssl证书

upstream webman {
    server 127.0.0.1:9506;
    keepalive 10240;
}


server {

  listen 80;
  listen [::]:80;
  listen 443 ssl http2;
  listen [::]:443 ssl http2;
  server_name ask.xxx.cn;


  ssl_certificate /usr/local/nginx/conf/ssl/ask.xxx.cn.pem;
  ssl_certificate_key /usr/local/nginx/conf/ssl/ask.xxx.cn.key;
  ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
  ssl_ciphers TLS13-AES-256-GCM-SHA384:TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-128-GCM-SHA256:TLS13-AES-128-CCM-8-SHA256:TLS13-AES-128-CCM-SHA256:EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;
  ssl_prefer_server_ciphers on;
  ssl_session_timeout 10m;
  ssl_session_cache builtin:1000 shared:SSL:10m;
  ssl_buffer_size 1400;
  add_header Strict-Transport-Security max-age=15768000;
  ssl_stapling on;
  ssl_stapling_verify on;
  if ($ssl_protocol = "") { return 301 https://$host$request_uri; }


  add_header Strict-Transport-Security max-age=15768000;
  access_log /data/wwwlogs/ask.nbfuli.cn_nginx.log combined;
  index index.html index.htm index.php;
  root /www/askme-webman/public;

  if ($is_bot) {
    return 403;
  }

  #error_page 404 /404.html;
  #error_page 502 /502.html;
	location ^~ / {
	  proxy_set_header X-Real-IP $remote_addr;
	  proxy_set_header Host $host;
	  proxy_set_header X-Forwarded-Proto $scheme;
	  proxy_http_version 1.1;
	  proxy_set_header Connection "";
	  if (!-f $request_filename){
	      proxy_pass http://webman;
	  }
	}  


  location ~ .*\.(gif|jpg|jpeg|png|bmp|swf|flv|mp4|ico)$ {
    expires 30d;
    access_log off;
  }
  location ~ .*\.(js|css)?$ {
    expires 7d;
    access_log off;
  }
  location ~ /(\.user\.ini|\.ht|\.git|\.svn|\.project|LICENSE|README\.md) {
    deny all;
  }
  location /.well-known {
    allow all;
  }
}

所有用户都可以去薅羊毛,192元充值200元话费!先到先得!导航栏话费充值,正规可靠,快充慢充自由选择。
欧阳逸资源站 » webman项目nginx配置,ssl证书

发表评论