http {
include mime.types;
default_type application/octet-stream;
sendfile on;
upstream web_pool{
server 192.168.120.69:8080;
}
upstream bg_pool{
server 192.168.120.69:8088;
}
server {
listen 80;
server_name www.abcd.com abcd.com api.abcd.com;
rewrite ^(.*)$ https://$host$1 permanent;
}
server {
listen 443;
server_name www.abcd.com abcd.com;
ssl on;
root html;
ssl_certificate /cert/web/1965820_www.abcd.com.pem;
ssl_certificate_key /cert/web/1965820_www.abcd.com.key;
ssl_session_timeout 5m;
ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_prefer_server_ciphers on;
location / {
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_pass http://web_pool;
}
}
server {
listen 443;
server_name api.abcd.com;
ssl on;
ssl_certificate /cert/bg/1979195_api.abcd.com.pem;
ssl_certificate_key /cert/bg/1979195_api.abcd.com.key;
ssl_session_timeout 5m;
ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_prefer_server_ciphers on;
location / {
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_pass http://bg_pool;
}
}
}
Nginx_配置ssl
最新推荐文章于 2024-07-18 16:26:45 发布