rss.lmsite.cn.conf
server { listen 443 ssl http2; listen [::]:443 ssl http2; ssl_certificate ssl/rss.lmsite.cn_chain.crt; ssl_certificate_key ssl/rss.lmsite.cn_key.key; include ssl.conf; server_name rss.lmsite.cn; access_log /data/wwwlogs/rss.lmsite.cn_nginx.log combined; location / { proxy_pass http://127.0.0.1:1222; proxy_set_header Host $proxy_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } location ~ /(\.user\.ini|\.ht|\.git|\.svn|\.project|LICENSE|README\.md) { deny all; }}server { listen 80; listen [::]:80; server_name rss.lmsite.cn; if ($host = "rss.lmsite.cn") { rewrite ^/(.*)$ https://rss.lmsite.cn permanent; }}
ssl.conf
ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3; ssl_ciphers TLS13-AES-256-GCM-SHA384:TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-128-GCM-SHA256:TLS13-AES-128-CCM-8-SHA256:TLS13-AES-128-CCM-SHA256:EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5; ssl_prefer_server_ciphers on; ssl_session_timeout 10m; ssl_session_cache builtin:1000 shared:SSL:10m; ssl_buffer_size 1400; add_header Strict-Transport-Security max-age=15768000; ssl_stapling on; ssl_stapling_verify on;