Update nginx SSL settings, includes
This commit is contained in:
		
					parent
					
						
							
								eed7317b0c
							
						
					
				
			
			
				commit
				
					
						28efaaafdc
					
				
			
		
					 4 changed files with 17 additions and 5 deletions
				
			
		
							
								
								
									
										4
									
								
								roles/nginx/files/etc/nginx/include/ssl_rewrite.conf
									
										
									
									
									
										Normal file
									
								
							
							
						
						
									
										4
									
								
								roles/nginx/files/etc/nginx/include/ssl_rewrite.conf
									
										
									
									
									
										Normal file
									
								
							|  | @ -0,0 +1,4 @@ | |||
| # Generischer Rewrite von HTTP nach HTTPS | ||||
| location / { | ||||
|     return 302 https://$server_name$request_uri; | ||||
| } | ||||
|  | @ -1,84 +0,0 @@ | |||
| user www-data; | ||||
| worker_processes auto; | ||||
| pid /run/nginx.pid; | ||||
| 
 | ||||
| events { | ||||
|         worker_connections 768; | ||||
|         # multi_accept on; | ||||
| } | ||||
| 
 | ||||
| http { | ||||
| 
 | ||||
|         ## | ||||
|         # Basic Settings | ||||
|         ## | ||||
| 
 | ||||
|         sendfile on; | ||||
|         tcp_nopush on; | ||||
|         tcp_nodelay on; | ||||
|         keepalive_timeout 65; | ||||
|         types_hash_max_size 2048; | ||||
|         server_tokens off; | ||||
| 
 | ||||
|         # server_names_hash_bucket_size 64; | ||||
|         # server_name_in_redirect off; | ||||
| 
 | ||||
|         include /etc/nginx/mime.types; | ||||
|         default_type application/octet-stream; | ||||
| 
 | ||||
|         ## | ||||
|         # SSL Settings | ||||
|         ## | ||||
| 
 | ||||
|         ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # Dropping SSLv3, ref: POODLE | ||||
|         ssl_prefer_server_ciphers on; | ||||
| 
 | ||||
|         ## | ||||
|         # Logging Settings | ||||
|         ## | ||||
| 
 | ||||
|         include /etc/nginx/include/no_logging.conf; | ||||
| 
 | ||||
|         ## | ||||
|         # Gzip Settings | ||||
|         ## | ||||
| 
 | ||||
|         gzip on; | ||||
|         gzip_disable "msie6"; | ||||
| 
 | ||||
|         # gzip_vary on; | ||||
|         # gzip_proxied any; | ||||
|         # gzip_comp_level 6; | ||||
|         # gzip_buffers 16 8k; | ||||
|         # gzip_http_version 1.1; | ||||
|         # gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript; | ||||
| 
 | ||||
|         ## | ||||
|         # Virtual Host Configs | ||||
|         ## | ||||
| 
 | ||||
|         include /etc/nginx/conf.d/*.conf; | ||||
|         include /etc/nginx/sites-enabled/*; | ||||
| } | ||||
| 
 | ||||
| 
 | ||||
| #mail { | ||||
| #       # See sample authentication script at: | ||||
| #       # http://wiki.nginx.org/ImapAuthenticateWithApachePhpScript | ||||
| # | ||||
| #       # auth_http localhost/auth.php; | ||||
| #       # pop3_capabilities "TOP" "USER"; | ||||
| #       # imap_capabilities "IMAP4rev1" "UIDPLUS"; | ||||
| # | ||||
| #       server { | ||||
| #               listen     localhost:110; | ||||
| #               protocol   pop3; | ||||
| #               proxy      on; | ||||
| #       } | ||||
| # | ||||
| #       server { | ||||
| #               listen     localhost:143; | ||||
| #               protocol   imap; | ||||
| #               proxy      on; | ||||
| #       } | ||||
| #} | ||||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue
	
	 Alexander Dietrich
				Alexander Dietrich