mirror of
https://github.com/certbot/certbot.git
synced 2026-08-01 19:02:52 +02:00
Initial version of nginx parser roundtrip test
This commit is contained in:
+9
@@ -0,0 +1,9 @@
|
||||
#-*- mode: nginx; mode: flyspell-prog; mode: autopair; ispell-local-dictionary: "american" -*-
|
||||
### fastcgi configuration.
|
||||
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
||||
include fastcgi_params;
|
||||
fastcgi_buffers 256 4k;
|
||||
fastcgi_intercept_errors on;
|
||||
## allow 4 hrs - pass timeout responsibility to upstrea
|
||||
fastcgi_read_timeout 14400;
|
||||
fastcgi_index index.php;
|
||||
+32
@@ -0,0 +1,32 @@
|
||||
# -*- mode: conf; mode: flyspell-prog; ispell-local-dictionary: "american" -*-
|
||||
### fastcgi parameters.
|
||||
fastcgi_param QUERY_STRING $query_string;
|
||||
fastcgi_param REQUEST_METHOD $request_method;
|
||||
fastcgi_param CONTENT_TYPE $content_type;
|
||||
fastcgi_param CONTENT_LENGTH $content_length;
|
||||
|
||||
fastcgi_param SCRIPT_NAME $fastcgi_script_name;
|
||||
fastcgi_param REQUEST_URI $request_uri;
|
||||
fastcgi_param DOCUMENT_URI $document_uri;
|
||||
fastcgi_param DOCUMENT_ROOT $document_root;
|
||||
fastcgi_param SERVER_PROTOCOL $server_protocol;
|
||||
|
||||
fastcgi_param GATEWAY_INTERFACE CGI/1.1;
|
||||
fastcgi_param SERVER_SOFTWARE nginx/$nginx_version;
|
||||
|
||||
fastcgi_param REMOTE_ADDR $remote_addr;
|
||||
fastcgi_param REMOTE_PORT $remote_port;
|
||||
fastcgi_param SERVER_ADDR $server_addr;
|
||||
fastcgi_param SERVER_PORT $server_port;
|
||||
fastcgi_param SERVER_NAME $server_name;
|
||||
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
||||
|
||||
## PHP only, required if PHP was built with --enable-force-cgi-redirect
|
||||
fastcgi_param REDIRECT_STATUS 200;
|
||||
## HTTPS 'on' parameter. This requires Nginx version 1.1.11 or
|
||||
## later. The if_not_empty flag was introduced in 1.1.11. See:
|
||||
## http://nginx.org/en/CHANGES. If using a version that doesn't
|
||||
## support this comment out the line below.
|
||||
fastcgi_param HTTPS $https if_not_empty;
|
||||
## For Nginx versions below 1.1.11 uncomment the line below after commenting out the above.
|
||||
#fastcgi_param HTTPS $https
|
||||
+109
@@ -0,0 +1,109 @@
|
||||
|
||||
# This map is not a full koi8-r <> utf8 map: it does not contain
|
||||
# box-drawing and some other characters. Besides this map contains
|
||||
# several koi8-u and Byelorussian letters which are not in koi8-r.
|
||||
# If you need a full and standard map, use contrib/unicode2nginx/koi-utf
|
||||
# map instead.
|
||||
|
||||
charset_map koi8-r utf-8 {
|
||||
|
||||
80 E282AC ; # euro
|
||||
|
||||
95 E280A2 ; # bullet
|
||||
|
||||
9A C2A0 ; #
|
||||
|
||||
9E C2B7 ; # ·
|
||||
|
||||
A3 D191 ; # small yo
|
||||
A4 D194 ; # small Ukrainian ye
|
||||
|
||||
A6 D196 ; # small Ukrainian i
|
||||
A7 D197 ; # small Ukrainian yi
|
||||
|
||||
AD D291 ; # small Ukrainian soft g
|
||||
AE D19E ; # small Byelorussian short u
|
||||
|
||||
B0 C2B0 ; # °
|
||||
|
||||
B3 D081 ; # capital YO
|
||||
B4 D084 ; # capital Ukrainian YE
|
||||
|
||||
B6 D086 ; # capital Ukrainian I
|
||||
B7 D087 ; # capital Ukrainian YI
|
||||
|
||||
B9 E28496 ; # numero sign
|
||||
|
||||
BD D290 ; # capital Ukrainian soft G
|
||||
BE D18E ; # capital Byelorussian short U
|
||||
|
||||
BF C2A9 ; # (C)
|
||||
|
||||
C0 D18E ; # small yu
|
||||
C1 D0B0 ; # small a
|
||||
C2 D0B1 ; # small b
|
||||
C3 D186 ; # small ts
|
||||
C4 D0B4 ; # small d
|
||||
C5 D0B5 ; # small ye
|
||||
C6 D184 ; # small f
|
||||
C7 D0B3 ; # small g
|
||||
C8 D185 ; # small kh
|
||||
C9 D0B8 ; # small i
|
||||
CA D0B9 ; # small j
|
||||
CB D0BA ; # small k
|
||||
CC D0BB ; # small l
|
||||
CD D0BC ; # small m
|
||||
CE D0BD ; # small n
|
||||
CF D0BE ; # small o
|
||||
|
||||
D0 D0BF ; # small p
|
||||
D1 D18F ; # small ya
|
||||
D2 D180 ; # small r
|
||||
D3 D181 ; # small s
|
||||
D4 D182 ; # small t
|
||||
D5 D183 ; # small u
|
||||
D6 D0B6 ; # small zh
|
||||
D7 D0B2 ; # small v
|
||||
D8 D18C ; # small soft sign
|
||||
D9 D18B ; # small y
|
||||
DA D0B7 ; # small z
|
||||
DB D188 ; # small sh
|
||||
DC D18D ; # small e
|
||||
DD D189 ; # small shch
|
||||
DE D187 ; # small ch
|
||||
DF D18A ; # small hard sign
|
||||
|
||||
E0 D0AE ; # capital YU
|
||||
E1 D090 ; # capital A
|
||||
E2 D091 ; # capital B
|
||||
E3 D0A6 ; # capital TS
|
||||
E4 D094 ; # capital D
|
||||
E5 D095 ; # capital YE
|
||||
E6 D0A4 ; # capital F
|
||||
E7 D093 ; # capital G
|
||||
E8 D0A5 ; # capital KH
|
||||
E9 D098 ; # capital I
|
||||
EA D099 ; # capital J
|
||||
EB D09A ; # capital K
|
||||
EC D09B ; # capital L
|
||||
ED D09C ; # capital M
|
||||
EE D09D ; # capital N
|
||||
EF D09E ; # capital O
|
||||
|
||||
F0 D09F ; # capital P
|
||||
F1 D0AF ; # capital YA
|
||||
F2 D0A0 ; # capital R
|
||||
F3 D0A1 ; # capital S
|
||||
F4 D0A2 ; # capital T
|
||||
F5 D0A3 ; # capital U
|
||||
F6 D096 ; # capital ZH
|
||||
F7 D092 ; # capital V
|
||||
F8 D0AC ; # capital soft sign
|
||||
F9 D0AB ; # capital Y
|
||||
FA D097 ; # capital Z
|
||||
FB D0A8 ; # capital SH
|
||||
FC D0AD ; # capital E
|
||||
FD D0A9 ; # capital SHCH
|
||||
FE D0A7 ; # capital CH
|
||||
FF D0AA ; # capital hard sign
|
||||
}
|
||||
+103
@@ -0,0 +1,103 @@
|
||||
|
||||
charset_map koi8-r windows-1251 {
|
||||
|
||||
80 88 ; # euro
|
||||
|
||||
95 95 ; # bullet
|
||||
|
||||
9A A0 ; #
|
||||
|
||||
9E B7 ; # ·
|
||||
|
||||
A3 B8 ; # small yo
|
||||
A4 BA ; # small Ukrainian ye
|
||||
|
||||
A6 B3 ; # small Ukrainian i
|
||||
A7 BF ; # small Ukrainian yi
|
||||
|
||||
AD B4 ; # small Ukrainian soft g
|
||||
AE A2 ; # small Byelorussian short u
|
||||
|
||||
B0 B0 ; # °
|
||||
|
||||
B3 A8 ; # capital YO
|
||||
B4 AA ; # capital Ukrainian YE
|
||||
|
||||
B6 B2 ; # capital Ukrainian I
|
||||
B7 AF ; # capital Ukrainian YI
|
||||
|
||||
B9 B9 ; # numero sign
|
||||
|
||||
BD A5 ; # capital Ukrainian soft G
|
||||
BE A1 ; # capital Byelorussian short U
|
||||
|
||||
BF A9 ; # (C)
|
||||
|
||||
C0 FE ; # small yu
|
||||
C1 E0 ; # small a
|
||||
C2 E1 ; # small b
|
||||
C3 F6 ; # small ts
|
||||
C4 E4 ; # small d
|
||||
C5 E5 ; # small ye
|
||||
C6 F4 ; # small f
|
||||
C7 E3 ; # small g
|
||||
C8 F5 ; # small kh
|
||||
C9 E8 ; # small i
|
||||
CA E9 ; # small j
|
||||
CB EA ; # small k
|
||||
CC EB ; # small l
|
||||
CD EC ; # small m
|
||||
CE ED ; # small n
|
||||
CF EE ; # small o
|
||||
|
||||
D0 EF ; # small p
|
||||
D1 FF ; # small ya
|
||||
D2 F0 ; # small r
|
||||
D3 F1 ; # small s
|
||||
D4 F2 ; # small t
|
||||
D5 F3 ; # small u
|
||||
D6 E6 ; # small zh
|
||||
D7 E2 ; # small v
|
||||
D8 FC ; # small soft sign
|
||||
D9 FB ; # small y
|
||||
DA E7 ; # small z
|
||||
DB F8 ; # small sh
|
||||
DC FD ; # small e
|
||||
DD F9 ; # small shch
|
||||
DE F7 ; # small ch
|
||||
DF FA ; # small hard sign
|
||||
|
||||
E0 DE ; # capital YU
|
||||
E1 C0 ; # capital A
|
||||
E2 C1 ; # capital B
|
||||
E3 D6 ; # capital TS
|
||||
E4 C4 ; # capital D
|
||||
E5 C5 ; # capital YE
|
||||
E6 D4 ; # capital F
|
||||
E7 C3 ; # capital G
|
||||
E8 D5 ; # capital KH
|
||||
E9 C8 ; # capital I
|
||||
EA C9 ; # capital J
|
||||
EB CA ; # capital K
|
||||
EC CB ; # capital L
|
||||
ED CC ; # capital M
|
||||
EE CD ; # capital N
|
||||
EF CE ; # capital O
|
||||
|
||||
F0 CF ; # capital P
|
||||
F1 DF ; # capital YA
|
||||
F2 D0 ; # capital R
|
||||
F3 D1 ; # capital S
|
||||
F4 D2 ; # capital T
|
||||
F5 D3 ; # capital U
|
||||
F6 C6 ; # capital ZH
|
||||
F7 C2 ; # capital V
|
||||
F8 DC ; # capital soft sign
|
||||
F9 DB ; # capital Y
|
||||
FA C7 ; # capital Z
|
||||
FB D8 ; # capital SH
|
||||
FC DD ; # capital E
|
||||
FD D9 ; # capital SHCH
|
||||
FE D7 ; # capital CH
|
||||
FF DA ; # capital hard sign
|
||||
}
|
||||
+7
@@ -0,0 +1,7 @@
|
||||
# -*- mode: conf; mode: flyspell-prog; ispell-local-dictionary: "american" -*-
|
||||
### Implement the $https_if_not_empty variable for Nginx versions below 1.1.11.
|
||||
|
||||
map $scheme $https {
|
||||
default '';
|
||||
https on;
|
||||
}
|
||||
+77
@@ -0,0 +1,77 @@
|
||||
# -*- mode: nginx; mode: flyspell-prog; mode: autopair; ispell-current-dictionary: american -*-
|
||||
types {
|
||||
text/html html htm shtml;
|
||||
text/css css;
|
||||
text/xml xml rss;
|
||||
image/gif gif;
|
||||
image/jpeg jpeg jpg;
|
||||
application/x-javascript js;
|
||||
application/atom+xml atom;
|
||||
|
||||
text/mathml mml;
|
||||
text/plain txt;
|
||||
text/vnd.sun.j2me.app-descriptor jad;
|
||||
text/vnd.wap.wml wml;
|
||||
text/x-component htc;
|
||||
|
||||
image/png png;
|
||||
image/tiff tif tiff;
|
||||
image/vnd.wap.wbmp wbmp;
|
||||
image/x-icon ico;
|
||||
image/x-jng jng;
|
||||
image/x-ms-bmp bmp;
|
||||
image/svg+xml svg svgz;
|
||||
|
||||
application/java-archive jar war ear;
|
||||
application/mac-binhex40 hqx;
|
||||
application/msword doc;
|
||||
application/pdf pdf;
|
||||
application/postscript ps eps ai;
|
||||
application/rtf rtf;
|
||||
application/vnd.ms-excel xls;
|
||||
application/vnd.ms-powerpoint ppt;
|
||||
application/vnd.wap.wmlc wmlc;
|
||||
application/vnd.wap.xhtml+xml xhtml;
|
||||
application/x-7z-compressed 7z;
|
||||
application/x-cocoa cco;
|
||||
application/x-java-archive-diff jardiff;
|
||||
application/x-java-jnlp-file jnlp;
|
||||
application/x-makeself run;
|
||||
application/x-perl pl pm;
|
||||
application/x-pilot prc pdb;
|
||||
application/x-rar-compressed rar;
|
||||
application/x-redhat-package-manager rpm;
|
||||
application/x-sea sea;
|
||||
application/x-shockwave-flash swf;
|
||||
application/x-stuffit sit;
|
||||
application/x-tcl tcl tk;
|
||||
application/x-x509-ca-cert der pem crt;
|
||||
application/x-xpinstall xpi;
|
||||
application/zip zip;
|
||||
|
||||
# Mime types for web fonts. Stolen from here:
|
||||
# http://seconddrawer.com.au/blog/ in part.
|
||||
application/x-font-ttf ttf;
|
||||
font/opentype otf;
|
||||
application/vnd.ms-fontobject eot;
|
||||
application/x-woff woff;
|
||||
|
||||
application/octet-stream bin exe dll;
|
||||
application/octet-stream deb;
|
||||
application/octet-stream dmg;
|
||||
application/octet-stream iso img;
|
||||
application/octet-stream msi msp msm;
|
||||
|
||||
audio/midi mid midi kar;
|
||||
audio/mpeg mp3;
|
||||
audio/x-realaudio ra;
|
||||
|
||||
video/3gpp 3gpp 3gp;
|
||||
video/mpeg mpeg mpg;
|
||||
video/quicktime mov;
|
||||
video/x-flv flv;
|
||||
video/x-mng mng;
|
||||
video/x-ms-asf asx asf;
|
||||
video/x-ms-wmv wmv;
|
||||
video/x-msvideo avi;
|
||||
}
|
||||
+119
@@ -0,0 +1,119 @@
|
||||
# -*- mode: nginx; mode: flyspell-prog; mode: autopair; ispell-local-dictionary: "american" -*-
|
||||
user www-data;
|
||||
worker_processes 4;
|
||||
|
||||
error_log /var/log/nginx/error.log;
|
||||
pid /var/run/nginx.pid;
|
||||
|
||||
worker_rlimit_nofile 8192;
|
||||
|
||||
events {
|
||||
worker_connections 4096;
|
||||
## epoll is preferred on 2.6 Linux
|
||||
## kernels. Cf. http://www.kegel.com/c10k.html#nb.epoll
|
||||
use epoll;
|
||||
## Accept as many connections as possible.
|
||||
multi_accept on;
|
||||
}
|
||||
|
||||
http {
|
||||
## MIME types.
|
||||
include /etc/nginx/mime.types;
|
||||
default_type application/octet-stream;
|
||||
|
||||
## FastCGI.
|
||||
include /etc/nginx/fastcgi.conf;
|
||||
|
||||
## Default log and error files.
|
||||
access_log /var/log/nginx/access.log;
|
||||
error_log /var/log/nginx/error.log;
|
||||
|
||||
## Use sendfile() syscall to speed up I/O operations and speed up
|
||||
## static file serving.
|
||||
sendfile on;
|
||||
## Handling of IPs in proxied and load balancing situations.
|
||||
set_real_ip_from 0.0.0.0/32; # all addresses get a real IP.
|
||||
real_ip_header X-Forwarded-For; # the ip is forwarded from the load balancer/proxy
|
||||
|
||||
## Define a zone for limiting the number of simultaneous
|
||||
## connections nginx accepts. 1m means 32000 simultaneous
|
||||
## sessions. We need to define for each server the limit_conn
|
||||
## value refering to this or other zones.
|
||||
## ** This syntax requires nginx version >=
|
||||
## ** 1.1.8. Cf. http://nginx.org/en/CHANGES. If using an older
|
||||
## ** version then use the limit_zone directive below
|
||||
## ** instead. Comment out this
|
||||
## ** one if not using nginx version >= 1.1.8.
|
||||
limit_conn_zone $binary_remote_addr zone=arbeit:10m;
|
||||
|
||||
## Timeouts.
|
||||
client_body_timeout 60;
|
||||
client_header_timeout 60;
|
||||
keepalive_timeout 10 10;
|
||||
send_timeout 60;
|
||||
|
||||
## Reset lingering timed out connections. Deflect DDoS.
|
||||
reset_timedout_connection on;
|
||||
|
||||
## Body size.
|
||||
client_max_body_size 10m;
|
||||
|
||||
## TCP options.
|
||||
tcp_nodelay on;
|
||||
tcp_nopush on;
|
||||
|
||||
## Compression.
|
||||
gzip on;
|
||||
gzip_buffers 16 8k;
|
||||
gzip_comp_level 1;
|
||||
gzip_http_version 1.1;
|
||||
gzip_min_length 10;
|
||||
gzip_types text/plain text/css application/x-javascript text/xml application/xml application/xml+rss text/javascript image/x-icon application/vnd.ms-fontobject font/opentype application/x-font-ttf;
|
||||
gzip_vary on;
|
||||
gzip_proxied any; # Compression for all requests.
|
||||
## No need for regexps. See
|
||||
## http://wiki.nginx.org/NginxHttpGzipModule#gzip_disable
|
||||
gzip_disable "msie6";
|
||||
|
||||
## Serve already compressed files directly, bypassing on-the-fly
|
||||
## compression.
|
||||
gzip_static on;
|
||||
|
||||
## Hide the Nginx version number.
|
||||
server_tokens off;
|
||||
|
||||
## Use a SSL/TLS cache for SSL session resume. This needs to be
|
||||
## here (in this context, for session resumption to work. See this
|
||||
## thread on the Nginx mailing list:
|
||||
## http://nginx.org/pipermail/nginx/2010-November/023736.html.
|
||||
ssl_session_cache shared:SSL:10m;
|
||||
ssl_session_timeout 10m;
|
||||
|
||||
## For the filefield_nginx_progress module to work. From the
|
||||
## README. Reserve 1MB under the name 'uploads' to track uploads.
|
||||
upload_progress uploads 1m;
|
||||
|
||||
## Enable clickjacking protection in modern browsers. Available in
|
||||
## IE8 also. See
|
||||
## https://developer.mozilla.org/en/The_X-FRAME-OPTIONS_response_header
|
||||
add_header X-Frame-Options sameorigin;
|
||||
|
||||
## Include the upstream servers for PHP FastCGI handling config.
|
||||
include upstream_phpcgi.conf;
|
||||
|
||||
## If using Nginx version >= 1.1.11 then there's a $https variable
|
||||
## that has the value 'on' if the used scheme is https and '' if not.
|
||||
## See: http://trac.nginx.org/nginx/changeset/4380/nginx
|
||||
## http://trac.nginx.org/nginx/changeset/4333/nginx and
|
||||
## http://trac.nginx.org/nginx/changeset/4334/nginx. If using a
|
||||
## previous version then uncomment out the line below.
|
||||
#include map_https_fcgi.conf;
|
||||
|
||||
## Include the upstream servers for Apache handling the PHP
|
||||
## processes. In this case Nginx functions as a reverse proxy.
|
||||
#include reverse_proxy.conf;
|
||||
#include upstream_phpapache.conf;
|
||||
|
||||
## Include all vhosts.
|
||||
include /etc/nginx/sites-enabled/*;
|
||||
}
|
||||
+10
@@ -0,0 +1,10 @@
|
||||
# -*- mode: nginx; mode: flyspell-prog; mode: autopair; ispell-local-dictionary: "american" -*-
|
||||
|
||||
### Configuration for reverse proxy. Passing the necessary headers to
|
||||
### the backend. Nginx doesn't tunnel the connection, it opens a new
|
||||
### one. Hence whe need to send these headers to the backend so that
|
||||
### the client(s) IP is available to them. The host is also sent.
|
||||
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header Host $http_host;
|
||||
+19
@@ -0,0 +1,19 @@
|
||||
# -*-mode: nginx; mode: flyspell-prog; mode: autopair; ispell-local-dictionary: "american" -*-
|
||||
### Block all illegal host headers. Taken from a discussion on nginx
|
||||
### forums. Cf. http://forum.nginx.org/read.php?2,3482,3518 following
|
||||
### a suggestion by Maxim Dounin. Also suggested in
|
||||
### http://nginx.org/en/docs/http/request_processing.html.
|
||||
server {
|
||||
listen [::]:80 default_server;
|
||||
# Uncomment the line below and comment the above if you're
|
||||
# running a Nginx version less than 0.8.20.
|
||||
# listen [::]:80 default;
|
||||
|
||||
# Accept redirects based on the value of the Host header. If
|
||||
# there's no valid vhost configuration file with a
|
||||
# corresponding server_name directive then signal an error and
|
||||
# fail silently. See:
|
||||
# http://wiki.nginx.org/NginxHttpCoreModule#server_name_in_redirect
|
||||
server_name_in_redirect off;
|
||||
return 444;
|
||||
}
|
||||
+102
@@ -0,0 +1,102 @@
|
||||
# -*- mode: nginx; mode: flyspell-prog; mode: autopair; ispell-local-dictionary: "american" -*-
|
||||
### Nginx configuration for Chive.
|
||||
|
||||
server {
|
||||
## This is to avoid the spurious if for sub-domain name
|
||||
## rewriting. See http://wiki.nginx.org/Pitfalls#Server_Name.
|
||||
listen 80; # IPv4
|
||||
|
||||
## Replace the IPv6 address by your own address. The address below
|
||||
## was stolen from the wikipedia page on IPv6.
|
||||
listen [fe80::202:b3ff:fe1e:8329]:80 ipv6only=on;
|
||||
|
||||
server_name www.chive.example.com;
|
||||
|
||||
return 301 $scheme://chive.example.com$request_uri;
|
||||
|
||||
} # server domain rewrite.
|
||||
|
||||
server {
|
||||
listen 80; # IPv4
|
||||
|
||||
## Replace the IPv6 address by your own address. The address below
|
||||
## was stolen from the wikipedia page on IPv6.
|
||||
listen [fe80::202:b3ff:fe1e:8329]:80 ipv6only=on;
|
||||
|
||||
limit_conn arbeit 32;
|
||||
server_name chive.example.com;
|
||||
|
||||
## Parameterization using hostname of access and log filenames.
|
||||
access_log /var/log/nginx/chive.example.com_access.log;
|
||||
error_log /var/log/nginx/chive.example.com_error.log;
|
||||
|
||||
root /var/www/sites/chive.example.com;
|
||||
index index.php index.html;
|
||||
|
||||
## Support for favicon. Return a 204 (No Content) if the favicon
|
||||
## doesn't exist.
|
||||
location = /favicon.ico {
|
||||
try_files /favicon.ico =204;
|
||||
}
|
||||
|
||||
## The main location is accessed using Basic Auth.
|
||||
location / {
|
||||
## Access is restricted.
|
||||
auth_basic "Restricted Access"; # auth realm
|
||||
auth_basic_user_file .htpasswd-users; # htpasswd file
|
||||
|
||||
## Use PATH_INFO for translating the requests to the
|
||||
## FastCGI. This config follows Igor's suggestion here:
|
||||
## http://forum.nginx.org/read.php?2,124378,124582.
|
||||
## This is preferable to using:
|
||||
## fastcgi_split_path_info ^(.+\.php)(.*)$
|
||||
## It saves one regex in the location. Hence it's faster.
|
||||
location ~ ^(?<script>.+\.php)(?<path_info>.*)$ {
|
||||
include fastcgi.conf;
|
||||
## The fastcgi_params must be redefined from the ones
|
||||
## given in fastcgi.conf. No longer standard names
|
||||
## but arbitrary: named patterns in regex.
|
||||
fastcgi_param SCRIPT_FILENAME $document_root$script;
|
||||
fastcgi_param SCRIPT_NAME $script;
|
||||
fastcgi_param PATH_INFO $path_info;
|
||||
## Passing the request upstream to the FastCGI
|
||||
## listener.
|
||||
fastcgi_pass phpcgi;
|
||||
}
|
||||
|
||||
## Protect these locations. Replicating the .htaccess
|
||||
## rules throughout the chive distro.
|
||||
location /protected {
|
||||
internal;
|
||||
}
|
||||
|
||||
location /yii {
|
||||
internal;
|
||||
}
|
||||
|
||||
## Static file handling.
|
||||
location ~* .+\.(?:css|gif|htc|js|jpe?g|png|swf)$ {
|
||||
expires max;
|
||||
## No need to bleed constant updates. Send the all shebang in one
|
||||
## fell swoop.
|
||||
tcp_nodelay off;
|
||||
## Set the OS file cache.
|
||||
open_file_cache max=100 inactive=120s;
|
||||
open_file_cache_valid 45s;
|
||||
open_file_cache_min_uses 2;
|
||||
open_file_cache_errors off;
|
||||
}
|
||||
}
|
||||
|
||||
## We need to capture the case where the index.php is missing,
|
||||
## hence we drop out of the path info thingie.
|
||||
location ~* /([^\.])$ {
|
||||
return 302 /index.php/$1;
|
||||
}
|
||||
|
||||
## Close up git repo access.
|
||||
location ^~ /.git {
|
||||
return 404;
|
||||
}
|
||||
|
||||
} # server
|
||||
+135
@@ -0,0 +1,135 @@
|
||||
# -*- mode: nginx; mode: flyspell-prog; mode: autopair; ispell-local-dictionary: "american" -*-
|
||||
### Nginx configuration for Chive with HTTPS.
|
||||
|
||||
server {
|
||||
## This is to avoid the spurious if for sub-domain name
|
||||
## rewriting. See http://wiki.nginx.org/Pitfalls#Server_Name.
|
||||
listen 80; # IPv4
|
||||
|
||||
## Replace the IPv6 address by your own address. The address below
|
||||
## was stolen from the wikipedia page on IPv6.
|
||||
listen [fe80::202:b3ff:fe1e:8329]:80 ipv6only=on;
|
||||
|
||||
server_name chive.example.com;
|
||||
return 301 https://chive.example.com$request_uri;
|
||||
|
||||
} # server domain rewrite.
|
||||
|
||||
server {
|
||||
## This is to avoid the spurious if for sub-domain name
|
||||
## rewriting. See http://wiki.nginx.org/Pitfalls#Server_Name.
|
||||
listen 80; # IPv4
|
||||
|
||||
## Replace the IPv6 address by your own address. The address below
|
||||
## was stolen from the wikipedia page on IPv6.
|
||||
listen [fe80::202:b3ff:fe1e:8329]:80 ipv6only=on;
|
||||
|
||||
listen 443 ssl; # IPv4
|
||||
## Replace the IPv6 address by your own address. The address below
|
||||
## was stolen from the wikipedia page on IPv6.
|
||||
listen [fe80::202:b3ff:fe1e:8329]:443 ssl ipv6only=on;
|
||||
|
||||
server_name www.chive.example.com;
|
||||
|
||||
## Server certificate and key.
|
||||
ssl_certificate /etc/ssl/certs/chive.example.com-cert.pem;
|
||||
ssl_certificate_key /etc/ssl/private/chive.example.com-key.pem;
|
||||
|
||||
## Use only HTTPS.
|
||||
return 301 https://chive.example.com$request_uri;
|
||||
|
||||
} # server domain rewrite.
|
||||
|
||||
server {
|
||||
listen 443 ssl; # IPv4
|
||||
## Replace the IPv6 address by your own address. The address below
|
||||
## was stolen from the wikipedia page on IPv6.
|
||||
listen [fe80::202:b3ff:fe1e:8329]:443 ssl ipv6only=on;
|
||||
|
||||
limit_conn arbeit 32;
|
||||
server_name chive.example.com;
|
||||
|
||||
## Keep alive timeout set to a greater value for SSL/TLS.
|
||||
keepalive_timeout 75 75;
|
||||
|
||||
## Parameterization using hostname of access and log filenames.
|
||||
access_log /var/log/nginx/chive.example.com_access.log;
|
||||
error_log /var/log/nginx/chive.example.com_error.log;
|
||||
|
||||
## Server certificate and key.
|
||||
ssl_certificate /etc/ssl/certs/chive.example.com-cert.pem;
|
||||
ssl_certificate_key /etc/ssl/private/chive.example.com-key.pem;
|
||||
|
||||
## Strict Transport Security header for enhanced security. See
|
||||
## http://www.chromium.org/sts.
|
||||
add_header Strict-Transport-Security "max-age=12960000";
|
||||
|
||||
root /var/www/sites/chive.example.com/;
|
||||
index index.php index.html;
|
||||
|
||||
## Support for favicon. Return a 204 (No Content) if the favicon
|
||||
## doesn't exist.
|
||||
location = /favicon.ico {
|
||||
try_files /favicon.ico =204;
|
||||
}
|
||||
|
||||
## The main location is accessed using Basic Auth.
|
||||
location / {
|
||||
## Access is restricted.
|
||||
auth_basic "Restricted Access"; # auth realm
|
||||
auth_basic_user_file .htpasswd-users; # htpasswd file
|
||||
|
||||
## Use PATH_INFO for translating the requests to the
|
||||
## FastCGI. This config follows Igor's suggestion here:
|
||||
## http://forum.nginx.org/read.php?2,124378,124582.
|
||||
## This is preferable to using:
|
||||
## fastcgi_split_path_info ^(.+\.php)(.*)$
|
||||
## It saves one regex in the location. Hence it's faster.
|
||||
location ~ ^(?<script>.+\.php)(?<path_info>.*)$ {
|
||||
include fastcgi.conf;
|
||||
## The fastcgi_params must be redefined from the ones
|
||||
## given in fastcgi.conf. No longer standard names
|
||||
## but arbitrary: named patterns in regex.
|
||||
fastcgi_param SCRIPT_FILENAME $document_root$script;
|
||||
fastcgi_param SCRIPT_NAME $script;
|
||||
fastcgi_param PATH_INFO $path_info;
|
||||
## Passing the request upstream to the FastCGI
|
||||
## listener.
|
||||
fastcgi_pass php-cgi;
|
||||
}
|
||||
|
||||
## Protect these locations. Replicating the .htaccess
|
||||
## rules throughout the chive distro.
|
||||
location /protected {
|
||||
internal;
|
||||
}
|
||||
location /yii {
|
||||
internal;
|
||||
}
|
||||
|
||||
## Static file handling.
|
||||
location ~* .+\.(?:css|gif|htc|js|jpe?g|png)$ {
|
||||
expires max;
|
||||
## No need to bleed constant updates. Send the all shebang in one
|
||||
## fell swoop.
|
||||
tcp_nodelay off;
|
||||
## Set the OS file cache.
|
||||
open_file_cache max=100 inactive=120s;
|
||||
open_file_cache_valid 45s;
|
||||
open_file_cache_min_uses 2;
|
||||
open_file_cache_errors off;
|
||||
}
|
||||
}
|
||||
|
||||
## We need to capture the case where the index.php is missing,
|
||||
## hence we drop out of the path info thingie.
|
||||
location ~* /([^\.])$ {
|
||||
return 302 /index.php/$1;
|
||||
}
|
||||
|
||||
## Close up git repo access.
|
||||
location ^~ /.git {
|
||||
return 404;
|
||||
}
|
||||
|
||||
} # server
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
# -*- mode: nginx; mode: flyspell-prog; mode: autopair; ispell-local-dictionary: "american" -*-
|
||||
|
||||
### Upstream configuration for Apache functioning has a PHP handler.
|
||||
|
||||
## Add as many servers as needed. Cf. http://wiki.nginx.org/HttpUpstreamModule.
|
||||
upstream phpapache {
|
||||
server 127.0.0.1:8080;
|
||||
}
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
# -*- mode: nginx; mode: flyspell-prog; mode: autopair; ispell-local-dictionary: "american" -*-
|
||||
|
||||
### Upstream configuration for PHP FastCGI.
|
||||
|
||||
## Add as many servers as needed. Cf. http://wiki.nginx.org/HttpUpstreamModule.
|
||||
upstream phpcgi {
|
||||
server unix:/var/run/php-fpm.sock;
|
||||
}
|
||||
+126
@@ -0,0 +1,126 @@
|
||||
|
||||
# This map is not a full windows-1251 <> utf8 map: it does not
|
||||
# contain Serbian and Macedonian letters. If you need a full map,
|
||||
# use contrib/unicode2nginx/win-utf map instead.
|
||||
|
||||
charset_map windows-1251 utf-8 {
|
||||
|
||||
82 E2809A ; # single low-9 quotation mark
|
||||
|
||||
84 E2809E ; # double low-9 quotation mark
|
||||
85 E280A6 ; # ellipsis
|
||||
86 E280A0 ; # dagger
|
||||
87 E280A1 ; # double dagger
|
||||
88 E282AC ; # euro
|
||||
89 E280B0 ; # per mille
|
||||
|
||||
91 E28098 ; # left single quotation mark
|
||||
92 E28099 ; # right single quotation mark
|
||||
93 E2809C ; # left double quotation mark
|
||||
94 E2809D ; # right double quotation mark
|
||||
95 E280A2 ; # bullet
|
||||
96 E28093 ; # en dash
|
||||
97 E28094 ; # em dash
|
||||
|
||||
99 E284A2 ; # trade mark sign
|
||||
|
||||
A0 C2A0 ; #
|
||||
A1 D18E ; # capital Byelorussian short U
|
||||
A2 D19E ; # small Byelorussian short u
|
||||
|
||||
A4 C2A4 ; # currency sign
|
||||
A5 D290 ; # capital Ukrainian soft G
|
||||
A6 C2A6 ; # borken bar
|
||||
A7 C2A7 ; # section sign
|
||||
A8 D081 ; # capital YO
|
||||
A9 C2A9 ; # (C)
|
||||
AA D084 ; # capital Ukrainian YE
|
||||
AB C2AB ; # left-pointing double angle quotation mark
|
||||
AC C2AC ; # not sign
|
||||
AD C2AD ; # soft hypen
|
||||
AE C2AE ; # (R)
|
||||
AF D087 ; # capital Ukrainian YI
|
||||
|
||||
B0 C2B0 ; # °
|
||||
B1 C2B1 ; # plus-minus sign
|
||||
B2 D086 ; # capital Ukrainian I
|
||||
B3 D196 ; # small Ukrainian i
|
||||
B4 D291 ; # small Ukrainian soft g
|
||||
B5 C2B5 ; # micro sign
|
||||
B6 C2B6 ; # pilcrow sign
|
||||
B7 C2B7 ; # ·
|
||||
B8 D191 ; # small yo
|
||||
B9 E28496 ; # numero sign
|
||||
BA D194 ; # small Ukrainian ye
|
||||
BB C2BB ; # right-pointing double angle quotation mark
|
||||
|
||||
BF D197 ; # small Ukrainian yi
|
||||
|
||||
C0 D090 ; # capital A
|
||||
C1 D091 ; # capital B
|
||||
C2 D092 ; # capital V
|
||||
C3 D093 ; # capital G
|
||||
C4 D094 ; # capital D
|
||||
C5 D095 ; # capital YE
|
||||
C6 D096 ; # capital ZH
|
||||
C7 D097 ; # capital Z
|
||||
C8 D098 ; # capital I
|
||||
C9 D099 ; # capital J
|
||||
CA D09A ; # capital K
|
||||
CB D09B ; # capital L
|
||||
CC D09C ; # capital M
|
||||
CD D09D ; # capital N
|
||||
CE D09E ; # capital O
|
||||
CF D09F ; # capital P
|
||||
|
||||
D0 D0A0 ; # capital R
|
||||
D1 D0A1 ; # capital S
|
||||
D2 D0A2 ; # capital T
|
||||
D3 D0A3 ; # capital U
|
||||
D4 D0A4 ; # capital F
|
||||
D5 D0A5 ; # capital KH
|
||||
D6 D0A6 ; # capital TS
|
||||
D7 D0A7 ; # capital CH
|
||||
D8 D0A8 ; # capital SH
|
||||
D9 D0A9 ; # capital SHCH
|
||||
DA D0AA ; # capital hard sign
|
||||
DB D0AB ; # capital Y
|
||||
DC D0AC ; # capital soft sign
|
||||
DD D0AD ; # capital E
|
||||
DE D0AE ; # capital YU
|
||||
DF D0AF ; # capital YA
|
||||
|
||||
E0 D0B0 ; # small a
|
||||
E1 D0B1 ; # small b
|
||||
E2 D0B2 ; # small v
|
||||
E3 D0B3 ; # small g
|
||||
E4 D0B4 ; # small d
|
||||
E5 D0B5 ; # small ye
|
||||
E6 D0B6 ; # small zh
|
||||
E7 D0B7 ; # small z
|
||||
E8 D0B8 ; # small i
|
||||
E9 D0B9 ; # small j
|
||||
EA D0BA ; # small k
|
||||
EB D0BB ; # small l
|
||||
EC D0BC ; # small m
|
||||
ED D0BD ; # small n
|
||||
EE D0BE ; # small o
|
||||
EF D0BF ; # small p
|
||||
|
||||
F0 D180 ; # small r
|
||||
F1 D181 ; # small s
|
||||
F2 D182 ; # small t
|
||||
F3 D183 ; # small u
|
||||
F4 D184 ; # small f
|
||||
F5 D185 ; # small kh
|
||||
F6 D186 ; # small ts
|
||||
F7 D187 ; # small ch
|
||||
F8 D188 ; # small sh
|
||||
F9 D189 ; # small shch
|
||||
FA D18A ; # small hard sign
|
||||
FB D18B ; # small y
|
||||
FC D18C ; # small soft sign
|
||||
FD D18D ; # small e
|
||||
FE D18E ; # small yu
|
||||
FF D18F ; # small ya
|
||||
}
|
||||
Reference in New Issue
Block a user