IT

nginx ssl 설정 값

노트에버 2020. 3. 12. 17:10

server {
        listen          443 ssl;
        server_name naver.com;

        #access_log  /var/log/nginx/ssl.access.log       main;
        error_log       /var/log/nginx/ssl.error.log      warn;

        ssl on;
        ssl_certificate     ssl/ssl_key_.pem;
        ssl_certificate_key ssl/ssl_key_20190607.pem;
        ssl_protocols       TLSv1 TLSv1.1 TLSv1.2;
        ssl_ciphers         HIGH:!aNULL:!MD5;
        ssl_prefer_server_ciphers   on;
        ssl_dhparam                                     ssl/dhparam.pem;
        ssl_ecdh_curve                          secp384r1;
        ssl_session_cache                       shared:SSL:30m;
        ssl_session_timeout                     30m;
        ssl_session_tickets                     off;
        ssl_stapling                            on;
        ssl_stapling_verify                     on;
        resolver                                        168.126.63.1 8.8.8.8 valid=300s;
        resolver_timeout                        5s;
        add_header                                      Strict-Transport-Security 'max-age=31536000; includeSubDomains';


        location / {
                proxy_pass http://127.0.0.1:815/;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto https;
        }


}