Skip to content
Snippets Groups Projects
Commit e18754db authored by Eliot Berriot's avatar Eliot Berriot
Browse files

Merge branch 'master' into 'master'

Better with HTTPS

See merge request !1
parents e9b2870e 85216305
No related branches found
No related tags found
No related merge requests found
......@@ -4,9 +4,29 @@ upstream funkwhale-api {
}
server {
listen 80;
listen 80;
listen [::]:80;
server_name demo.funkwhale.audio;
# useful for Let's Encrypt
location /.well-known/acme-challenge/ { allow all; }
location / { return 301 https://$host$request_uri; }
}
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name demo.funkwhale.audio;
# TLS
ssl_protocols TLSv1.2;
ssl_ciphers HIGH:!MEDIUM:!LOW:!aNULL:!NULL:!SHA;
ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
# HSTS
add_header Strict-Transport-Security "max-age=31536000";
root /srv/funkwhale/front/dist;
location / {
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment