vhost_ssl_header.erb 997 B

12345678910111213141516171819
  1. server {
  2. listen <%= ssl_port %><% if scope.lookupvar('nginx::params::nx_spdy') == 'on' %> ssl spdy<% end %>;
  3. <% if ipv6_enable == 'true' && (defined? ipaddress6) %>
  4. listen [<%= ipv6_listen_ip %>]:<%= ipv6_listen_port %> <% if @ipv6_listen_options %><%= ipv6_listen_options %><% end %> ipv6only=on;
  5. <% end %>
  6. server_name <%= rewrite_www_to_non_www ? name.gsub(/^www\./, '') : server_name.join(" ") %>;
  7. ssl on;
  8. ssl_certificate <%= ssl_cert %>;
  9. ssl_certificate_key <%= ssl_key %>;
  10. ssl_session_cache shared:SSL:10m;
  11. ssl_session_timeout 10m;
  12. ssl_ciphers RC4:HIGH:!aNULL:!MD5;
  13. ssl_prefer_server_ciphers on;
  14. <% if scope.lookupvar('nginx::params::nx_ssl_stapling') == 'on' %>ssl_stapling on;<% end %>
  15. <% if scope.lookupvar('nginx::params::nx_spdy') == 'on' %>spdy_headers_comp 1;<% end %>
  16. <% proxy_set_header.each do |header| %>
  17. proxy_set_header <%= header %>;<% end %>