https-car.conf 923 B

12345678910111213141516171819202122232425262728
  1. # frpHTTPS
  2. server {
  3. #SSL 访问端口号为 443
  4. listen 443 ssl;
  5. #填写绑定证书的域名
  6. server_name car.caner.top;
  7. #目录
  8. root /var/www/car/;
  9. #证书文件名称
  10. ssl_certificate "/var/www/pki/car.caner.top_bundle.crt";
  11. #私钥文件名称
  12. ssl_certificate_key "/var/www/pki/car.caner.top.key";
  13. ssl_session_timeout 5m;
  14. #请按照以下协议配置
  15. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  16. #请按照以下套件配置,配置加密套件,写法遵循 openssl 标准。
  17. ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE;
  18. ssl_prefer_server_ciphers on;
  19. server_tokens off;
  20. # wss转发
  21. location ^~/socket.io {
  22. proxy_http_version 1.1;
  23. proxy_set_header Upgrade $http_upgrade;
  24. proxy_set_header Connection "upgrade";
  25. proxy_set_header X-Real-IP $remote_addr;
  26. proxy_pass http://127.0.0.1:49800;
  27. }
  28. }