default 649 B

12345678910111213141516171819202122232425262728
  1. server {
  2. listen 80 default_server;
  3. listen 65443 ssl;
  4. server_name _;
  5. ssl_certificate /etc/ocserv/server.crt.pem;
  6. ssl_certificate_key /etc/ocserv/server.key.pem;
  7. ssl_protocols TLSv1.3 TLSv1.2 TLSv1.1 TLSv1;
  8. ssl_ciphers EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5:!RC4;
  9. ssl_prefer_server_ciphers on;
  10. ssl_session_cache shared:SSL:16m;
  11. ssl_buffer_size 4k;
  12. ssl_stapling off;
  13. ssl_stapling_verify off;
  14. autoindex on;
  15. gzip off;
  16. root /var/www/html;
  17. index index.html;
  18. if ($scheme != "https") { return 302 "https://$host:65443$request_uri"; }
  19. location / {
  20. try_files $uri $uri/ =404;
  21. }
  22. }