Pour tout problème contactez-nous par mail : support@froggit.fr | La FAQ :grey_question: | Rejoignez-nous sur le Chat :speech_balloon:

Skip to content
Snippets Groups Projects
nginx.conf 2.02 KiB
Newer Older
peter_rabbit's avatar
peter_rabbit committed
user  nginx;
worker_processes  1;

error_log  /var/log/nginx/error.log warn;
pid        /var/run/nginx.pid;


events {
    worker_connections  1024;
}

http {
    include       /etc/nginx/mime.types;
    default_type  application/octet-stream;

    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';

    access_log  /var/log/nginx/access.log  main;

    sendfile        on;
    #tcp_nopush     on;

    keepalive_timeout  65;

    #gzip  on;
	
    include /etc/nginx/conf.d/*.conf;
peter_rabbit's avatar
peter_rabbit committed

    server {
peter_rabbit's avatar
peter_rabbit committed
        listen 80;
peter_rabbit's avatar
peter_rabbit committed
        root   /usr/share/nginx/html;
        index  index.html index.htm;
        server_name kuadrado-software.fr www.kuadrado-software.fr;
        location / {
            return 301 https://$host$request_uri;
        }
        location /.well-known/acme-challenge/ {
            root /var/www/certbot;
        }
    server {
        listen 443 ssl;
peter_rabbit's avatar
peter_rabbit committed
        root   /usr/share/nginx/html;
        server_name kuadrado-software.fr www.kuadrado-software.fr;
        index  index.html index.htm;
        ssl_certificate /etc/letsencrypt/live/kuadrado-software.fr/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/kuadrado-software.fr/privkey.pem;
peter_rabbit's avatar
peter_rabbit committed

        # https://github.com/certbot/certbot/blob/master/certbot-nginx/certbot_nginx/_internal/tls_configs/options-ssl-nginx.conf
        ssl_session_cache shared:le_nginx_SSL:10m;
        ssl_session_timeout 1440m;
        ssl_session_tickets off;
        ssl_protocols TLSv1.2 TLSv1.3;
        ssl_prefer_server_ciphers off;
        ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384";
        ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
        location / {
            proxy_pass http://kuadrado-software.fr;
        }
    }
peter_rabbit's avatar
peter_rabbit committed
}