worker_processes 1; events { worker_connections 1024; } http { include mime.types; default_type application/octet-stream; sendfile on; keepalive_timeout 65; upstream tomcat_server_pool{ server 127.0.0.1:1002 weight=10; } server { #SSL 访问端口号为 443 listen 443 ssl; #填写绑定证书的域名 server_name yourheart.xyz; #证书文件名称 ssl_certificate 7397156_yourheart.xyz.pem; #私钥文件名称 ssl_certificate_key 7397156_yourheart.xyz.key; ssl_session_timeout 5m; #请按照以下协议配置 ssl_protocols TLSv1 TLSv1.1 TLSv1.2; #请按照以下套件配置,配置加密套件,写法遵循 openssl 标准。 ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE; ssl_prefer_server_ciphers on; location / { proxy_pass http://tomcat_server_pool; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Host $http_host; root html; index index.html index.htm; } } server { listen 80; #填写绑定证书的域名 server_name yourheart.xyz; #把http的域名请求转成https return 301 https://$host$request_uri; } }
tomcat_server_pool表示反向代理服务器的ip
标签:文件,http,ssl,xyz,server,nginx,proxy,conf From: https://www.cnblogs.com/q202105271618/p/16981046.html