Skip to content

Commit bdd1cc8

Browse files
author
Bryan Kendall
committed
add certificates for blue.user_content_domain
1 parent 4d96f1f commit bdd1cc8

2 files changed

Lines changed: 21 additions & 1 deletion

File tree

ansible/group_vars/alpha-proxy-socket-server.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,5 +15,6 @@ docker_container_run_opts: >
1515
-v /etc/nginx/sites-available/:/etc/nginx/sites-enabled/:ro
1616
-v /etc/nginx/ssl/dhparam.pem:/etc/nginx/ssl/dhparam.pem:ro
1717
-v /etc/ssl/certs/{{ domain }}:/etc/ssl/certs/{{ domain }}:ro
18+
-v /etc/ssl/certs/{{ user_content_domain }}:/etc/ssl/certs/{{ user_content_domain }}:ro
1819
-v /etc/ssl/private:/etc/ssl/private:ro
1920
-v /var/log/nginx:/var/log/nginx

ansible/roles/user-content-pixel/templates/90-user-content-pixel.conf

Lines changed: 20 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,25 @@
11
server {
2-
listen 80;
2+
listen 443 ssl;
33
server_name blue.{{ user_content_domain }};
4+
gzip off;
5+
6+
ssl on;
7+
ssl_certificate /etc/ssl/certs/{{ user_content_domain }}/{{ user_content_domain }}.chained.crt;
8+
ssl_certificate_key /etc/ssl/private/{{ user_content_domain }}.key;
9+
ssl_trusted_certificate /etc/ssl/certs/{{ user_content_domain }}/ca.pem;
10+
11+
ssl_session_cache shared:SSL:10m;
12+
ssl_session_timeout 10m;
13+
14+
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
15+
ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
16+
ssl_prefer_server_ciphers on;
17+
ssl_dhparam /etc/nginx/ssl/dhparam.pem;
18+
19+
ssl_stapling on;
20+
ssl_stapling_verify on;
21+
resolver 8.8.8.8 8.8.4.4 valid=300s;
22+
resolver_timeout 5s;
423

524
location = /pixel.gif {
625
add_header Set-Cookie "isModerating=1; Domain=.{{ user_content_domain }}; Path=/; HttpOnly; Secure;";

0 commit comments

Comments
 (0)