2011-06-07 00:25:04 +02:00
|
|
|
server {
|
2012-10-18 15:33:07 +02:00
|
|
|
listen <%= ssl_port %>;
|
2012-11-08 19:59:17 +01:00
|
|
|
<% if ipv6_enable == 'true' && (defined? ipaddress6) %>
|
|
|
|
listen [<%= ipv6_listen_ip %>]:<%= ipv6_listen_port %> <% if @ipv6_listen_options %><%= ipv6_listen_options %><% end %> ipv6only=on;
|
|
|
|
<% end %>
|
|
|
|
server_name <%= rewrite_www_to_non_www ? name.gsub(/^www\./, '') : server_name.join(" ") %>;
|
2011-06-07 00:25:04 +02:00
|
|
|
|
|
|
|
ssl on;
|
2013-04-16 18:12:32 +02:00
|
|
|
|
|
|
|
ssl_certificate <%= scope.lookupvar('nginx::params::nx_conf_dir') %>/<%= scope.lookupvar('name') %>.crt;
|
|
|
|
ssl_certificate_key <%= scope.lookupvar('nginx::params::nx_conf_dir') %>/<%= scope.lookupvar('name') %>.key;
|
2011-06-07 00:25:04 +02:00
|
|
|
|
|
|
|
ssl_session_timeout 5m;
|
|
|
|
|
|
|
|
ssl_protocols SSLv3 TLSv1;
|
|
|
|
ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv3:+EXP;
|
|
|
|
ssl_prefer_server_ciphers on;
|