Set up SSL

This commit is contained in:
Ben Sturmfels 2023-04-18 11:22:20 +10:00
parent f16b33cf17
commit 83356e5ac6
Signed by: bsturmfels
GPG key ID: 023C05E2C9C068F0

View file

@ -3,19 +3,19 @@ upstream {{ site_name }}_django_wsgi {
server unix:/run/symposion/{{ site_name }}_uwsgi.sock; server unix:/run/symposion/{{ site_name }}_uwsgi.sock;
} }
# server { server {
# listen 80; listen 80;
# server_name {{ env.domain }}; server_name {{ env.domain }};
# return 301 https://{{ env.domain }}$request_uri; return 301 https://{{ env.domain }}$request_uri;
# } }
server { server {
listen 80; # 443 ssl http2; listen 443 ssl http2;
server_name {{ env.domain }}; server_name {{ env.domain }};
client_max_body_size 50M; client_max_body_size 50M;
# ssl_certificate /etc/letsencrypt/live/{{ env.domain }}/fullchain.pem; ssl_certificate /etc/letsencrypt/live/{{ env.domain }}/fullchain.pem;
# ssl_certificate_key /etc/letsencrypt/live/{{ env.domain }}/privkey.pem; ssl_certificate_key /etc/letsencrypt/live/{{ env.domain }}/privkey.pem;
# Ask for HTTPS for 180 days. # Ask for HTTPS for 180 days.
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains"; add_header Strict-Transport-Security "max-age=15552000; includeSubDomains";