Enable HTTP2 and HSTS
This commit is contained in:
parent
4e5d452aff
commit
6bea5b7567
@ -1,7 +1,7 @@
|
|||||||
server {
|
server {
|
||||||
listen 80; # For Let's Encrypt
|
listen 80; # For Let's Encrypt
|
||||||
<% if File.exist?(@ssl_cert) && File.exist?(@ssl_key) -%>
|
<% if File.exist?(@ssl_cert) && File.exist?(@ssl_key) -%>
|
||||||
listen 443 ssl spdy;
|
listen 443 ssl http2;
|
||||||
<% end -%>
|
<% end -%>
|
||||||
|
|
||||||
server_name <%= @server_name %>;
|
server_name <%= @server_name %>;
|
||||||
|
@ -16,7 +16,7 @@ server {
|
|||||||
|
|
||||||
server {
|
server {
|
||||||
<% if File.exist?(@ssl_cert) && File.exist?(@ssl_key) -%>
|
<% if File.exist?(@ssl_cert) && File.exist?(@ssl_key) -%>
|
||||||
listen <%= @ipfs_external_api_port %> ssl spdy;
|
listen <%= @ipfs_external_api_port %> ssl http2;
|
||||||
<% else -%>
|
<% else -%>
|
||||||
listen 80;
|
listen 80;
|
||||||
<% end -%>
|
<% end -%>
|
||||||
|
@ -1,6 +1,6 @@
|
|||||||
server {
|
server {
|
||||||
listen 80;
|
listen 80;
|
||||||
listen 443 ssl;
|
listen 443 ssl http2;
|
||||||
server_name <%= @server_name %>;
|
server_name <%= @server_name %>;
|
||||||
|
|
||||||
access_log /var/log/nginx/<%= @server_name %>.access.log;
|
access_log /var/log/nginx/<%= @server_name %>.access.log;
|
||||||
@ -30,6 +30,7 @@ server {
|
|||||||
fastcgi_param HTTP_PROXY "";
|
fastcgi_param HTTP_PROXY "";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
add_header Strict-Transport-Security "max-age=15768000; includeSubDomains";
|
||||||
ssl_certificate <%= @ssl_cert %>;
|
ssl_certificate <%= @ssl_cert %>;
|
||||||
ssl_certificate_key <%= @ssl_key %>;
|
ssl_certificate_key <%= @ssl_key %>;
|
||||||
}
|
}
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
server {
|
server {
|
||||||
listen 80;
|
listen 80;
|
||||||
<% if File.exist?(@ssl_cert) && File.exist?(@ssl_key) -%>
|
<% if File.exist?(@ssl_cert) && File.exist?(@ssl_key) -%>
|
||||||
listen <%= @server_port %> ssl spdy;
|
listen <%= @server_port %> ssl http2;
|
||||||
<% end -%>
|
<% end -%>
|
||||||
server_name <%= @server_name %> <%= @server_aliases.join(" ") %>;
|
server_name <%= @server_name %> <%= @server_aliases.join(" ") %>;
|
||||||
|
|
||||||
@ -35,6 +35,7 @@ server {
|
|||||||
}
|
}
|
||||||
|
|
||||||
<% if File.exist?(@ssl_cert) && File.exist?(@ssl_key) -%>
|
<% if File.exist?(@ssl_cert) && File.exist?(@ssl_key) -%>
|
||||||
|
add_header Strict-Transport-Security "max-age=15768000; includeSubDomains";
|
||||||
ssl_certificate <%= @ssl_cert %>;
|
ssl_certificate <%= @ssl_cert %>;
|
||||||
ssl_certificate_key <%= @ssl_key %>;
|
ssl_certificate_key <%= @ssl_key %>;
|
||||||
<% end -%>
|
<% end -%>
|
||||||
|
@ -11,7 +11,7 @@ map $http_upgrade $connection_upgrade {
|
|||||||
server {
|
server {
|
||||||
listen 80; # For Let's Encrypt
|
listen 80; # For Let's Encrypt
|
||||||
<% if File.exist?(@ssl_cert) && File.exist?(@ssl_key) -%>
|
<% if File.exist?(@ssl_cert) && File.exist?(@ssl_key) -%>
|
||||||
listen <%= @sockethub_external_port %> ssl spdy;
|
listen <%= @sockethub_external_port %> ssl http2;
|
||||||
add_header Strict-Transport-Security "max-age=15768000";
|
add_header Strict-Transport-Security "max-age=15768000";
|
||||||
<% end -%>
|
<% end -%>
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user