diff options
author | Gareth Rees <gareth@mysociety.org> | 2014-08-20 11:03:04 +0100 |
---|---|---|
committer | Gareth Rees <gareth@mysociety.org> | 2014-08-20 11:03:04 +0100 |
commit | 40abf0831fdf9cd6dee2f8d412be6d19558c46d7 (patch) | |
tree | e93cbba29e9d9290b11146c4e5cefcfeee414472 /config/nginx-ssl.conf.example | |
parent | a4d343096231d62e8d91a1b23ba9e1997e9136c0 (diff) |
Rename nginx ssl config file
Use .example to avoid conflicts with internal deployment system
Diffstat (limited to 'config/nginx-ssl.conf.example')
-rw-r--r-- | config/nginx-ssl.conf.example | 32 |
1 files changed, 32 insertions, 0 deletions
diff --git a/config/nginx-ssl.conf.example b/config/nginx-ssl.conf.example new file mode 100644 index 000000000..c623c8e96 --- /dev/null +++ b/config/nginx-ssl.conf.example @@ -0,0 +1,32 @@ +upstream alaveteli { + server 127.0.0.1:3000; +} + +server { + listen 443; + server_name www.example.com; + root /var/www/alaveteli/alaveteli/public; + + server_tokens off; + + try_files $uri/index.html $uri @alaveteli; + + access_log /var/log/nginx/alaveteli_ssl_access.log; + error_log /var/log/nginx/alaveteli_ssl_error.log error; + + ssl on; + ssl_certificate /etc/ssl/certs/www.example.com.cert; + ssl_certificate_key /etc/ssl/private/www.example.com.key; + ssl_ciphers ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM; + + location @alaveteli { + proxy_set_header Host $http_host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto https; + proxy_set_header X-Sendfile-Type X-Accel-Redirect; + proxy_set_header X-Accel-Mapping /var/www/alaveteli/alaveteli/cache/zips/production/download=/download; + proxy_redirect off; + proxy_pass http://alaveteli; + } +} |