# HTTPS
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
# https ssl
ssl_certificate ssl/server.lmsite.cn.crt;
ssl_certificate_key ssl/server.lmsite.cn.key;
include ssl/ssl_config.conf;
server_name server.lmsite.cn www.server.lmsite.cn;
access_log /data/weblogs/server.lmsite.cn_nginx.log combined;
# 代理 spug
location / {
include proxy_set_header.conf;
proxy_pass http://127.0.0.1:61208;
}
# 限制访问的文件
location ~ /(\.user\.ini|\.ht|\.git|\.svn|\.project|LICENSE|README\.md) {
deny all;
}
}
# http rewrite https
server {
listen 80;
listen [::]:80;
server_name server.lmsite.cn www.server.lmsite.cn;
rewrite ^(.*)$ https://${server_name}$1 permanent;
}