nginx.conf 1.5 KB

12345678910111213141516171819202122232425262728293031323334353637
  1. # haeusle site configuration
  2. # ! Do not remove this header !
  3. server {
  4. listen 80;
  5. listen [::]:80;
  6. server_tokens off;
  7. root /var/www/haeusle;
  8. #server_name haeusle.svhub.de;
  9. #return 301 https://haeusle.svhub.de/$request_uri;
  10. server_name haeusle.hinz.casa;
  11. return 301 https://haeusle.hinz.casa/$request_uri;
  12. }
  13. server {
  14. listen 443;
  15. listen [::]:443;
  16. #server_name haeusle.svhub.de;
  17. server_name haeusle.hinz.casa;
  18. server_tokens off;
  19. ssl on;
  20. #ssl_certificate /etc/letsencrypt/live/haeusle.svhub.de/fullchain.pem;
  21. #ssl_certificate_key /etc/letsencrypt/live/haeusle.svhub.de/privkey.pem;
  22. ssl_certificate /etc/letsencrypt/live/haeusle.hinz.casa/fullchain.pem;
  23. ssl_certificate_key /etc/letsencrypt/live/haeusle.hinz.casa/privkey.pem;
  24. ssl_prefer_server_ciphers on;
  25. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  26. ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384";
  27. #ssl_dhparam /etc/ssl/mail/dhparams.pem;
  28. add_header Strict-Transport-Security max-age=15768000;
  29. ssl_session_timeout 30m;
  30. client_max_body_size 25m;
  31. location / {
  32. include uwsgi_params;
  33. uwsgi_pass unix:/home/sven/haeusle/app.sock;
  34. }
  35. }