iuf.conf 2.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576
  1. ## Configuração para iuf.partidopirata.org
  2. server {
  3. listen 80;
  4. listen [::]:80;
  5. server_name iuf.partidopirata.org;
  6. root /var/www/git/desgovernanca-site/;
  7. location / {
  8. proxy_pass http://entwickler;
  9. proxy_set_header Host $host;
  10. proxy_set_header X-Forwarded-For $remote_addr;
  11. proxy_set_header X-Forwarded-Proto $scheme;
  12. }
  13. }
  14. server {
  15. listen 80;
  16. listen [::]:80;
  17. server_name *.iuf.partidopirata.org;
  18. return 301 http://iuf.partidopirata.org$request_uri;
  19. }
  20. ## SSL
  21. server {
  22. listen 443 ssl;
  23. listen [::]:443 ssl;
  24. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  25. ssl_prefer_server_ciphers on;
  26. ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";
  27. ssl_ecdh_curve secp384r1;
  28. ssl_session_cache shared:SSL:10m;
  29. ssl_session_tickets off;
  30. ssl_stapling on;
  31. ssl_stapling_verify on;
  32. resolver 208.67.220.220 208.67.222.222 valid=300s;
  33. resolver_timeout 5s;
  34. add_header Strict-Transport-Security "max-age=63072000; includeSubdomains; preload";
  35. add_header X-Frame-Options SAMEORIGIN;
  36. add_header X-Content-Type-Options nosniff;
  37. ssl_certificate /etc/letsencrypt/live/partidopirata.org/fullchain.pem;
  38. ssl_certificate_key /etc/letsencrypt/live/partidopirata.org/privkey.pem;
  39. ssl_trusted_certificate /etc/letsencrypt/live/partidopirata.org/chain.pem;
  40. server_name iuf.partidopirata.org;
  41. root /var/www/git/desgovernanca-site/;
  42. location / {
  43. proxy_pass http://entwickler;
  44. proxy_set_header Host $host;
  45. proxy_set_header X-Forwarded-For $remote_addr;
  46. proxy_set_header X-Forwarded-Proto $scheme;
  47. }
  48. }
  49. ## Tor
  50. #server {
  51. # listen 127.0.0.1:42907;
  52. # allow 127.0.0.1;
  53. # deny all;
  54. #
  55. # add_header X-Frame-Options SAMEORIGIN;
  56. # add_header X-Content-Type-Options nosniff;
  57. #
  58. # server_name iufywjvpmxty53fy.onion;
  59. # root /var/www/git/desgovernanca-site/;
  60. #}
  61. #server {
  62. # listen 127.0.0.1:42904;
  63. # allow 127.0.0.1;
  64. # deny all;
  65. #
  66. # add_header X-Frame-Options SAMEORIGIN;
  67. # add_header X-Content-Type-Options nosniff;
  68. #
  69. # server_name v27tzey35klcfrpw.onion;
  70. # return 301 http://iufywjvpmxty53fy.onion$request_uri;
  71. #}