nginx https配置

2019-02-28  本文已影响0人  gurlan
server {
    listen 443;
    server_name  tiger.gitlay.com;

    access_log  /var/log/nginx/xiaohu.access.log  main;
    error_log  /var/log/nginx/xiaohu.error.log;
# ssl on
    ssl on;
    ssl_certificate   /etc/nginx/cert/tiger.gitlay.com.pem;
    ssl_certificate_key  /etc/nginx/cert/tiger.gitlay.com.key;
    ssl_session_timeout 5m;
    ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;
    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
    ssl_prefer_server_ciphers on;

    ## send request back to apache ##
    location / {
        proxy_pass  http://172.16.0.4:30003;
        #Proxy Settings
        proxy_redirect     off;
        proxy_set_header   Host             $host;
        proxy_set_header   X-Real-IP        $remote_addr;
        proxy_set_header   X-Forwarded-For  $proxy_add_x_forwarded_for;
        proxy_next_upstream error timeout invalid_header http_500 http_502 http_503 http_504;
        proxy_max_temp_file_size 0;
        proxy_connect_timeout      90;
        proxy_send_timeout         90;
        proxy_read_timeout         90;
        proxy_buffer_size          4k;
        proxy_buffers              4 32k;
        proxy_busy_buffers_size    64k;
        proxy_temp_file_write_size 64k;
   }
}

上一篇 下一篇

猜你喜欢

热点阅读