From ceefb20769af4cbbd0cfefdbbf9482cc58534d01 Mon Sep 17 00:00:00 2001 From: valitovgaziz Date: Sun, 20 Jul 2025 01:33:19 +0500 Subject: [PATCH] modified: nginx/nginx-ssl.conf Add some ssl settings, fix bags with new easysite102.ru doman settings --- nginx/nginx-ssl.conf | 21 ++++++++++++++++++--- 1 file changed, 18 insertions(+), 3 deletions(-) diff --git a/nginx/nginx-ssl.conf b/nginx/nginx-ssl.conf index 7698a3a..ebc8999 100644 --- a/nginx/nginx-ssl.conf +++ b/nginx/nginx-ssl.conf @@ -1,6 +1,6 @@ server { listen 80; - server_name yalarba.ru www.yalarba.ru auth.yalarba.ru www.auth.yalarba.ru valitovgaziz.ru www.valitovgaziz.ru easysite102.ru www.easysite102.ru; + server_name yalarba.ru www.yalarba.ru valitovgaziz.ru www.valitovgaziz.ru easysite102.ru www.easysite102.ru; location /.well-known/acme-challenge/ { root /var/www/certbot; @@ -18,6 +18,11 @@ server { ssl_certificate /etc/letsencrypt/live/yalarba.ru/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/yalarba.ru/privkey.pem; + # Дополнительные SSL настройки + ssl_protocols TLSv1.2 TLSv1.3; + ssl_prefer_server_ciphers on; + ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH"; + location / { root /usr/share/nginx/html; index index.html; @@ -45,6 +50,11 @@ server { ssl_certificate /etc/letsencrypt/live/valitovgaziz.ru/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/valitovgaziz.ru/privkey.pem; + # Те же SSL настройки, что и выше + ssl_protocols TLSv1.2 TLSv1.3; + ssl_prefer_server_ciphers on; + ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH"; + location / { root /usr/share/nginx/valitovgaziz/html; index index.html; @@ -57,11 +67,16 @@ server { server_name easysite102.ru www.easysite102.ru; ssl_certificate /etc/letsencrypt/live/easysite102.ru/fullchain.pem; - ssl_certificate_key /etc/letsencrypt/live/easysite102.ru/privkey.ptm; + ssl_certificate_key /etc/letsencrypt/live/easysite102.ru/privkey.pem; + + # Те же SSL настройки + ssl_protocols TLSv1.2 TLSv1.3; + ssl_prefer_server_ciphers on; + ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH"; location / { root /usr/share/nginx/easysite102/html; index index.html; - try_files $uri $uri/ /idnex.html; + try_files $uri $uri/ /index.html; } }