nginx_ssl
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| nginx_ssl [2015/04/06 14:04] – luke7858 | nginx_ssl [2024/05/23 07:26] (current) – external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | You will need two server blocks | + | ==Files: |
| + | ^ Directive | ||
| + | | ssl_certificate | ||
| + | | ssl_certificate_key | ||
| + | ssl_certificate = .crt + .ca \\ | ||
| + | ssl_certificate = 'cat Intermediate.txt >> your_domain_com.bundle' | ||
| + | ------------ | ||
| + | \\ | ||
| + | To configure and redirect nginx properly and cleanly you need 3 nginx server blocks. | ||
| + | \\ | ||
| + | The blocks below show a site that is redirected to https:// | ||
| + | \\ | ||
| + | A quick overview of these nginx blocks can be found below: | ||
| + | < | ||
| + | server 80 -> Used to redirect | ||
| + | Domains | ||
| + | DocRoot specified: NO (: YES if site is combo of http and https) | ||
| + | Redirect | ||
| + | |||
| + | server 443 -> Used to redirect | ||
| + | Domains | ||
| + | DocRoot specified: NO | ||
| + | Redirect | ||
| + | |||
| + | server 443 -> Delivers content | ||
| + | Domains | ||
| + | DocRoot specified: YES | ||
| + | Redirect | ||
| + | </ | ||
| + | \\ | ||
| + | ------------ | ||
| + | \\ | ||
| + | \\ | ||
| + | If the customers application is taking care of the redirects then we can use the following example. \\ | ||
| + | The example below shows configuration with 2 nginx files | ||
| <sxh bash> | <sxh bash> | ||
| Line 14: | Line 48: | ||
| access_log / | access_log / | ||
| - | error_log / | + | error_log / |
| + | location / { | ||
| + | index index.html index.htm index.php; | ||
| + | try_files $uri $uri/ =404; | ||
| + | } | ||
| ssl on; | ssl on; | ||
| ssl_certificate / | ssl_certificate / | ||
| ssl_certificate_key / | ssl_certificate_key / | ||
| + | ssl_protocols TLSv1 TLSv1.1 TLSv1.2; #used to prevent poodle attacks for outdated protocols | ||
| - | |||
| - | location / { | ||
| - | rewrite ^/ | ||
| - | rewrite ^/ | ||
| - | rewrite ^/ | ||
| - | rewrite ^/ | ||
| - | } | ||
| location ~ \.php$ { | location ~ \.php$ { | ||
| Line 37: | Line 69: | ||
| } | } | ||
| </ | </ | ||
| + | \\ | ||
| + | \\ | ||
nginx_ssl.1428329074.txt.gz · Last modified: 2024/05/23 07:26 (external edit)
