server
    {
    listen 80;
    listen 443 ssl http2;
    server_name ws.studentwebsite.cn;
    index index.jsp index.php index.html index.htm default.php default.htm default.html;
    root /www/server/tomcat/webapps;

    #SSL-START SSL相关配置,请勿删除或修改下一行带注释的404规则
    #error_page 404/404.html;
    ssl_certificate /www/server/panel/vhost/cert/ws.studentwebsite.cn/fullchain.pem;
    ssl_certificate_key /www/server/panel/vhost/cert/ws.studentwebsite.cn/privkey.pem;
    ssl_protocols TLSv1.1 TLSv1.2 TLSv1.3;
    ssl_ciphers EECDH+CHACHA20:EECDH+CHACHA20-draft:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;
    ssl_prefer_server_ciphers on;
    ssl_session_cache shared:SSL:10m;
    ssl_session_timeout 10m;
    add_header Strict-Transport-Security “max-age=31536000”;
    error_page 497 https://$host$request_uri;

    1. #SSL-END<br /> <br /> #ERROR-PAGE-START 错误页配置,可以注释、删除或修改<br /> #error_page 404 /404.html;<br /> #error_page 502 /502.html;<br /> #ERROR-PAGE-END<br /> <br /> #PHP-INFO-START PHP引用配置,可以注释或修改<br /> #TOMCAT-START<br /> location /<br /> {<br /> proxy_pass "http://ws.studentwebsite.cn:8080";<br /> #proxy_set_header Host ws.studentwebsite.cn;<br /> #proxy_set_header X-Forwarded-For $remote_addr;<br /> proxy_http_version 1.1;<br /> proxy_set_header Upgrade $http_upgrade;<br /> proxy_set_header Connection "upgrade";<br /> <br /> proxy_connect_timeout 4s; <br /> proxy_read_timeout 7200s; <br /> proxy_send_timeout 12s; <br /> }<br /> location ~ .*\.(gif|jpg|jpeg|bmp|png|ico|txt|js|css)$<br /> {<br /> expires 12h;<br /> }<br /> <br /> location ~ .*\.war$<br /> {<br /> return 404;<br /> }<br /> #TOMCAT-END<br /> include enable-php-56.conf;<br /> #PHP-INFO-END<br /> <br /> #REWRITE-START URL重写规则引用,修改后将导致面板设置的伪静态规则失效<br /> include /www/server/panel/vhost/rewrite/ws.studentwebsite.cn.conf;<br /> #REWRITE-END<br /> <br /> #禁止访问的文件或目录<br /> location ~ ^/(\.user.ini|\.htaccess|\.git|\.svn|\.project|LICENSE|README.md)<br /> {<br /> return 404;<br /> }<br /> <br /> #一键申请SSL证书验证目录相关设置<br /> location ~ \.well-known{<br /> allow all;<br /> }<br /> <br /> location ~ .*\.(gif|jpg|jpeg|png|bmp|swf)$<br /> {<br /> expires 30d;<br /> error_log off;<br /> access_log /dev/null;<br /> }<br /> <br /> location ~ .*\.(js|css)?$<br /> {<br /> expires 12h;<br /> error_log off;<br /> access_log /dev/null; <br /> }<br /> access_log /www/wwwlogs/ws.studentwebsite.cn.log;<br /> error_log /www/wwwlogs/ws.studentwebsite.cn.error.log;<br />}