1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52
| server { listen 443 ssl; server_name stkit.cn; index index.html index.htm index.php; root /home/zxsign; #start - SSL证书 配置 ssl_certificate ../cert/aliyun_stkit.cn.pem; ssl_certificate_key ../cert/aliyun_stkit.cn.key;
ssl_session_cache shared:SSL:1m; ssl_session_timeout 5m; # 表示使用的TLS协议的类型 ssl_protocols TLSv1.2; #ssl_protocols TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; # 表示使用的加密套件的类型 #ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4; ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384; #end - SSL证书 配置 include enable-php.conf;
location /nginx_status { stub_status on; access_log off; }
location ~ .*\.(gif|jpg|jpeg|png|bmp|swf)$ { expires 30d; }
location ~ .*\.(js|css)?$ { expires 12h; }
location ~ /.well-known { allow all; }
location ~ /\. { deny all; }
access_log /home/wwwlogs/zxsign-access.log; }
|