Valid SSL Certificate with letsencrypt (example)

# /etc/nginx/sites-enabled/sylo.space.conf 
server {  
    listen 80;
    server_name ~^sylo\.space(\.dev)?$;
    return 301 https://$host$request_uri;
}

server {  
    listen 443 ssl;

    server_name ~^sylo\.space(\.dev)?$;
    root /var/www/vhosts/sylo.space/httpdocs;

    ssl                 on;
    ssl_certificate     /etc/letsencrypt/live/sylo.space/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/sylo.space/privkey.pem;

    ssl_session_timeout  5m;

    ssl_protocols TLSv1.1 TLSv1.2;
    ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA';
    ssl_prefer_server_ciphers on;

    index index.html index.php;

    location / {
        try_files $uri $uri/ /index.php$is_args$args;
    }

    include /var/www/config/nginx/snippets/php7.0-fpm.conf;
}
comments powered by Disqus