Last active
December 18, 2015 09:19
-
-
Save alghanmi/5760892 to your computer and use it in GitHub Desktop.
Nginx default configuration
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| server { | |
| listen 80; | |
| listen 443 default_server ssl spdy; | |
| ssl_certificate SITE_HOME/ssl/DOMAIN.crt; | |
| ssl_certificate_key SITE_HOME/ssl/DOMAIN.key; | |
| #Perfect Forward Secrecy | |
| ssl_prefer_server_ciphers on; | |
| ssl_protocols TLSv1 TLSv1.1 TLSv1.2; | |
| ssl_ciphers AES256+EECDH:AES256+EDH; | |
| #Cipher suite for backwards compatibility (IE6/WinXP) | |
| #ssl_ciphers ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4; | |
| #SSL Stapling | |
| ssl_stapling on; | |
| ssl_stapling_verify on; | |
| ssl_trusted_certificate SITE_HOME/ssl/DOMAIN_UNIFIED.crt; | |
| resolver 8.8.4.4 8.8.8.8 valid=300s; | |
| resolver_timeout 10s; | |
| #SSL Sessions | |
| ssl_session_cache shared:SSL:5m; | |
| ssl_session_timeout 10m; | |
| #Strict Transport Security | |
| add_header Strict-Transport-Security "max-age=31536000"; | |
| #Disable Framing over HTTPS | |
| add_header X-Frame-Options DENY; | |
| add_header X-Content-Type-Options nosniff; | |
| server_name DOMAIN; | |
| access_log SITE_HOME/logs/access.log; | |
| error_log SITE_HOME/logs/error.log warn; | |
| index index.html index.htm; | |
| root SITE_HOME/public_html; | |
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| server { | |
| listen 80 default_server; | |
| server_name ""; | |
| index index.html index.htm; | |
| server_name_in_redirect off; | |
| location / { | |
| root /home/www/default/public_html; | |
| } | |
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| server { | |
| listen 80; | |
| server_name DOMAIN; | |
| access_log SITE_HOME/logs/access.log; | |
| error_log SITE_HOME/logs/error.log warn; | |
| index index.html index.htm; | |
| root SITE_HOME/public_html; | |
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Turn off log access for: | |
| # - favicon | |
| # - robots.txt | |
| # - apple-touch-icon.png | |
| # - apple-touch-icon-precomposed.png | |
| location = /favicon.ico { | |
| access_log off; | |
| log_not_found off; | |
| } | |
| location = /robots.txt { | |
| access_log off; | |
| log_not_found off; | |
| } | |
| location = /apple-touch-icon.png { | |
| access_log off; | |
| log_not_found off; | |
| } | |
| location = /apple-touch-icon-precomposed.png { | |
| access_log off; | |
| log_not_found off; | |
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| user www-data www-data; | |
| worker_processes 1; | |
| error_log /var/log/nginx/error.log warn; | |
| pid /var/run/nginx.pid; | |
| events { | |
| worker_connections 1024; | |
| } | |
| http { | |
| include /etc/nginx/mime.types; | |
| default_type application/octet-stream; | |
| server_tokens off; | |
| log_format main '$remote_addr - $remote_user [$time_local] "$request" ' | |
| '$status $body_bytes_sent "$http_referer" ' | |
| '"$http_user_agent" "$http_x_forwarded_for"'; | |
| access_log /var/log/nginx/access.log main; | |
| server_names_hash_bucket_size 64; | |
| sendfile on; | |
| #tcp_nopush on; | |
| keepalive_timeout 65; | |
| gzip on; | |
| gzip_http_version 1.1; | |
| gzip_comp_level 3; | |
| gzip_types text/plain text/css text/xml | |
| application/x-javascript application/xml | |
| application/xml+rss text/javascript; | |
| gzip_vary on; | |
| include /etc/nginx/conf.d/*.conf; | |
| include /etc/nginx/sites-enabled/*.conf; | |
| } |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment