diff --git a/nginx/nginx-ssl.conf b/nginx/nginx-ssl.conf index 7698a3a..ebc8999 100644 --- a/nginx/nginx-ssl.conf +++ b/nginx/nginx-ssl.conf @@ -1,6 +1,6 @@ server { listen 80; - server_name yalarba.ru www.yalarba.ru auth.yalarba.ru www.auth.yalarba.ru valitovgaziz.ru www.valitovgaziz.ru easysite102.ru www.easysite102.ru; + server_name yalarba.ru www.yalarba.ru valitovgaziz.ru www.valitovgaziz.ru easysite102.ru www.easysite102.ru; location /.well-known/acme-challenge/ { root /var/www/certbot; @@ -18,6 +18,11 @@ server { ssl_certificate /etc/letsencrypt/live/yalarba.ru/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/yalarba.ru/privkey.pem; + # Дополнительные SSL настройки + ssl_protocols TLSv1.2 TLSv1.3; + ssl_prefer_server_ciphers on; + ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH"; + location / { root /usr/share/nginx/html; index index.html; @@ -45,6 +50,11 @@ server { ssl_certificate /etc/letsencrypt/live/valitovgaziz.ru/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/valitovgaziz.ru/privkey.pem; + # Те же SSL настройки, что и выше + ssl_protocols TLSv1.2 TLSv1.3; + ssl_prefer_server_ciphers on; + ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH"; + location / { root /usr/share/nginx/valitovgaziz/html; index index.html; @@ -57,11 +67,16 @@ server { server_name easysite102.ru www.easysite102.ru; ssl_certificate /etc/letsencrypt/live/easysite102.ru/fullchain.pem; - ssl_certificate_key /etc/letsencrypt/live/easysite102.ru/privkey.ptm; + ssl_certificate_key /etc/letsencrypt/live/easysite102.ru/privkey.pem; + + # Те же SSL настройки + ssl_protocols TLSv1.2 TLSv1.3; + ssl_prefer_server_ciphers on; + ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH"; location / { root /usr/share/nginx/easysite102/html; index index.html; - try_files $uri $uri/ /idnex.html; + try_files $uri $uri/ /index.html; } }