sul.conf 2.4 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283
  1. ## Configuração para sul.partidopirata.org
  2. server {
  3. listen 80;
  4. listen [::]:80;
  5. server_name sul.partidopirata.org;
  6. return 301 https://sul.partidopirata.org$request_uri;
  7. }
  8. server {
  9. listen 80;
  10. listen [::]:80;
  11. server_name *.sul.partidopirata.org;
  12. return 301 http://sul.partidopirata.org$request_uri;
  13. }
  14. ## SSL
  15. server {
  16. listen 443 ssl;
  17. listen [::]:443 ssl;
  18. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  19. ssl_prefer_server_ciphers on;
  20. ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";
  21. ssl_ecdh_curve secp384r1;
  22. ssl_session_cache shared:SSL:10m;
  23. ssl_session_tickets off;
  24. ssl_stapling on;
  25. ssl_stapling_verify on;
  26. resolver 208.67.220.220 208.67.222.222 valid=300s;
  27. resolver_timeout 5s;
  28. add_header Strict-Transport-Security "max-age=63072000; includeSubdomains; preload";
  29. add_header X-Frame-Options SAMEORIGIN;
  30. add_header X-Content-Type-Options nosniff;
  31. ssl_certificate /etc/letsencrypt/live/partidopirata.org/fullchain.pem;
  32. ssl_certificate_key /etc/letsencrypt/live/partidopirata.org/privkey.pem;
  33. ssl_trusted_certificate /etc/letsencrypt/live/partidopirata.org/chain.pem;
  34. server_name sul.partidopirata.org;
  35. root /var/www/public_html/sulpartidopirataxyz/;
  36. # location ~ \.cgi {
  37. # fastcgi_pass unix:/tmp/fcgi.socket;
  38. # # Fastcgi parameters, include the standard ones
  39. # include /etc/nginx/fastcgi_params;
  40. # # Adjust non standard parameters (SCRIPT_FILENAME)
  41. # fastcgi_param SCRIPT_FILENAME $fastcgi_script_name;
  42. # fastcgi_param SCRIPT_NAME /ikiwiki.cgi;
  43. # fastcgi_param AUTH_USER $remote_user;
  44. # fastcgi_param REMOTE_USER $remote_user;
  45. # }
  46. location / {
  47. proxy_pass http://entwickler;
  48. proxy_set_header Host $host;
  49. proxy_set_header X-Forwarded-For $remote_addr;
  50. proxy_set_header X-Forwarded-Proto $scheme;
  51. }
  52. }
  53. ## Tor
  54. #server {
  55. # listen 127.0.0.1:42913;
  56. # allow 127.0.0.1;
  57. # deny all;
  58. #
  59. # add_header X-Frame-Options SAMEORIGIN;
  60. # add_header X-Content-Type-Options nosniff;
  61. #
  62. # server_name sultytmrawcxcnw3.onion;
  63. #
  64. # root /var/www/public_html/sulpartidopirataxyz/;
  65. #
  66. # location ~ \.cgi {
  67. # fastcgi_pass unix:/tmp/fcgi.socket;
  68. # # Fastcgi parameters, include the standard ones
  69. # include /etc/nginx/fastcgi_params;
  70. # # Adjust non standard parameters (SCRIPT_FILENAME)
  71. # fastcgi_param SCRIPT_FILENAME $fastcgi_script_name;
  72. # fastcgi_param SCRIPT_NAME /ikiwiki.cgi;
  73. # fastcgi_param AUTH_USER $remote_user;
  74. # fastcgi_param REMOTE_USER $remote_user;
  75. # }
  76. #}