Commit 565e8c2db8
565e8c2db8e79197ffb49554a70e209fa1ead16e
parent: 6783d54468
Verified · cmc
cmc <hello@cleberg.net> · 2026-08-03 05:31 UTC
chore: cleanup
Layout: unified · split
linux/nginx/etc/nginx/conf.d/cleberg.dev.conf
+1 −1
| @@ -1,7 +1,7 @@ |
| 1 | |
1 | |
| 2 | |
2 | |
| 3 | server { |
3 | server { |
| 4 | listen 10010; |
4 | listen 127.0.0.1:10010; |
| 5 | server_name cleberg.dev; |
5 | server_name cleberg.dev; |
| 6 | root /var/www/cleberg.dev/; |
6 | root /var/www/cleberg.dev/; |
| 7 | include custom.d/basic.conf; |
7 | include custom.d/basic.conf; |
linux/nginx/etc/nginx/conf.d/cleberg.io.conf
deleted
−1
linux/nginx/etc/nginx/conf.d/cleberg.net.conf
+7 −15
| @@ -1,11 +1,14 @@ |
| 1 | server { |
1 | server { |
| 2 | listen 10011; |
2 | listen 127.0.0.1:10011; |
| 3 | server_name cleberg.net paske4urhs6nttrtlkuwa5cowum3fjkc6yv6kl4ncx3mjxcd77764nqd.onion; |
3 | server_name cleberg.net paske4urhs6nttrtlkuwa5cowum3fjkc6yv6kl4ncx3mjxcd77764nqd.onion; |
| 4 | error_log /var/log/nginx/cleberg.net.error.log; |
4 | |
| |
5 | # No per-vhost error_log: it overrode the global "off" and wrote visitor |
| |
6 | # IPs to disk. |
| |
7 | |
| |
8 | # basic.conf now carries HSTS + Permissions-Policy. CSP stays explicit -- |
| |
9 | # the shared policy is written for this vhost (it allows img.cleberg.net). |
| 5 | include custom.d/basic.conf; |
10 | include custom.d/basic.conf; |
| 6 | include custom.d/security/strict-transport-security.conf; |
| |
| 7 | include custom.d/security/content-security-policy.conf; |
11 | include custom.d/security/content-security-policy.conf; |
| 8 | include custom.d/security/permissions-policy.conf; |
| |
| 9 | root /var/www/cleberg.net/; |
12 | root /var/www/cleberg.net/; |
| 10 | include custom.d/redirects/blog.conf; |
13 | include custom.d/redirects/blog.conf; |
| 11 | port_in_redirect off; |
14 | port_in_redirect off; |
| @@ -48,14 +51,3 @@ server { |
| 48 | try_files $uri =404; |
51 | try_files $uri =404; |
| 49 | } |
52 | } |
| 50 | } |
53 | } |
| 51 | |
| |
| 52 | server { |
| |
| 53 | listen 10012; |
| |
| 54 | server_name hutch.cleberg.net; |
| |
| 55 | include custom.d/basic.conf; |
| |
| 56 | include custom.d/security/strict-transport-security.conf; |
| |
| 57 | include custom.d/security/content-security-policy.conf; |
| |
| 58 | include custom.d/security/permissions-policy.conf; |
| |
| 59 | location = /privacy.html { return 301 https://zerolabs.sh/hutch/privacy-policy/; } |
| |
| 60 | location = / { return 301 https://zerolabs.sh/hutch/; } |
| |
| 61 | } |
| |
linux/nginx/etc/nginx/conf.d/cleberg.net_wildcard.conf
deleted
−1
linux/nginx/etc/nginx/conf.d/cv.conf
+2 −2
| @@ -1,5 +1,5 @@ |
| 1 | server { |
1 | server { |
| 2 | listen 10014; |
2 | listen 127.0.0.1:10014; |
| 3 | server_name cv.cleberg.net; |
3 | server_name cv.cleberg.net; |
| 4 | add_header Onion-Location "http://xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion$request_uri" always; |
4 | add_header Onion-Location "http://xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion$request_uri" always; |
| 5 | include custom.d/basic.conf; |
5 | include custom.d/basic.conf; |
| @@ -9,7 +9,7 @@ server { |
| 9 | } |
9 | } |
| 10 | |
10 | |
| 11 | server { |
11 | server { |
| 12 | listen 10015; |
12 | listen 127.0.0.1:10015; |
| 13 | server_name xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion; |
13 | server_name xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion; |
| 14 | include custom.d/basic.conf; |
14 | include custom.d/basic.conf; |
| 15 | root /var/www/cv/; |
15 | root /var/www/cv/; |
linux/nginx/etc/nginx/conf.d/files.conf
+7 −3
| @@ -1,6 +1,10 @@ |
| 1 | server { |
1 | server { |
| 2 | listen 10017; |
2 | listen 127.0.0.1:10017; |
| 3 | server_name files.cleberg.net; |
3 | # files.cleberg.net was retired 2026-08-03: it and files.krz.sh both routed |
| |
4 | # here, so one origin served byte-identical content under both identities. |
| |
5 | # The real-name hostname was removed; this vhost is krz-only now. Named |
| |
6 | # explicitly rather than left to default-server fallback. |
| |
7 | server_name files.krz.sh; |
| 4 | add_header Onion-Location "http://yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion$request_uri" always; |
8 | add_header Onion-Location "http://yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion$request_uri" always; |
| 5 | include custom.d/basic.conf; |
9 | include custom.d/basic.conf; |
| 6 | root /var/www/files/; |
10 | root /var/www/files/; |
| @@ -9,7 +13,7 @@ server { |
| 9 | } |
13 | } |
| 10 | |
14 | |
| 11 | server { |
15 | server { |
| 12 | listen 10018; |
16 | listen 127.0.0.1:10018; |
| 13 | server_name yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion; |
17 | server_name yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion; |
| 14 | include custom.d/basic.conf; |
18 | include custom.d/basic.conf; |
| 15 | root /var/www/files/; |
19 | root /var/www/files/; |
linux/nginx/etc/nginx/conf.d/git.conf
+12 −5
| @@ -3,13 +3,14 @@ |
| 3 | # Repos are scanned from /git (scan-path in /etc/cgitrc). |
3 | # Repos are scanned from /git (scan-path in /etc/cgitrc). |
| 4 | |
4 | |
| 5 | server { |
5 | server { |
| 6 | listen 10046; |
6 | listen 127.0.0.1:10046; |
| 7 | server_name git.krz.sh; |
7 | server_name git.krz.sh; |
| 8 | error_log /var/log/nginx/git.krz.sh.error.log; |
| |
| 9 | |
8 | |
| |
9 | # No per-vhost error_log: it overrode the global "off" and wrote visitor |
| |
10 | # IPs to disk for the pseudonymous vhost. |
| |
11 | |
| |
12 | # basic.conf now carries HSTS + Permissions-Policy. |
| 10 | include custom.d/basic.conf; |
13 | include custom.d/basic.conf; |
| 11 | include custom.d/security/strict-transport-security.conf; |
| |
| 12 | include custom.d/security/permissions-policy.conf; |
| |
| 13 | |
14 | |
| 14 | # The shared CSP (default-src 'self', no style-src) breaks cgit: the |
15 | # The shared CSP (default-src 'self', no style-src) breaks cgit: the |
| 15 | # pygments source-filter writes an inline <style> block into every blob |
16 | # pygments source-filter writes an inline <style> block into every blob |
| @@ -51,8 +52,14 @@ server { |
| 51 | fastcgi_pass unix:/run/fcgiwrap.socket; |
52 | fastcgi_pass unix:/run/fcgiwrap.socket; |
| 52 | fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend; |
53 | fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend; |
| 53 | fastcgi_param GIT_PROJECT_ROOT /git; |
54 | fastcgi_param GIT_PROJECT_ROOT /git; |
| 54 | fastcgi_param GIT_HTTP_EXPORT_ALL 1; |
| |
| 55 | fastcgi_param PATH_INFO $uri; |
55 | fastcgi_param PATH_INFO $uri; |
| |
56 | |
| |
57 | # GIT_HTTP_EXPORT_ALL is deliberately absent. git-http-backend tests |
| |
58 | # it with getenv(), so ANY value -- including "0" -- exports every |
| |
59 | # repo under GIT_PROJECT_ROOT. The variable must simply not be set. |
| |
60 | # Export is now opt-in per repo via a git-daemon-export-ok marker, |
| |
61 | # so a repo dropped into /git is not published by accident. |
| |
62 | |
| 56 | fastcgi_param QUERY_STRING $args; |
63 | fastcgi_param QUERY_STRING $args; |
| 57 | |
64 | |
| 58 | # /git is owned by uid 1001, which maps to no account on this host, |
65 | # /git is owned by uid 1001, which maps to no account on this host, |
linux/nginx/etc/nginx/conf.d/hn.conf
+3 −6
| @@ -1,11 +1,8 @@ |
| 1 | server { |
1 | server { |
| 2 | listen 10023; |
2 | listen 127.0.0.1:10023; |
| 3 | listen 10024; |
3 | listen 127.0.0.1:10024; |
| 4 | server_name hn.zerolabs.sh r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion hn.cleberg.net; |
4 | server_name hn.zerolabs.sh r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion; |
| 5 | |
5 | |
| 6 | if ($host = hn.cleberg.net) { |
| |
| 7 | return 301 https://hn.zerolabs.sh$request_uri; |
| |
| 8 | } |
| |
| 9 | root /var/www/hn/output/; |
6 | root /var/www/hn/output/; |
| 10 | autoindex on; |
7 | autoindex on; |
| 11 | add_header Onion-Location "http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion$request_uri" always; |
8 | add_header Onion-Location "http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion$request_uri" always; |
linux/nginx/etc/nginx/conf.d/img.conf
+2 −2
| @@ -1,5 +1,5 @@ |
| 1 | server { |
1 | server { |
| 2 | listen 10025; |
2 | listen 127.0.0.1:10025; |
| 3 | server_name img.cleberg.net; |
3 | server_name img.cleberg.net; |
| 4 | add_header Onion-Location "http://ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion$request_uri" always; |
4 | add_header Onion-Location "http://ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion$request_uri" always; |
| 5 | include custom.d/basic.conf; |
5 | include custom.d/basic.conf; |
| @@ -9,7 +9,7 @@ server { |
| 9 | } |
9 | } |
| 10 | |
10 | |
| 11 | server { |
11 | server { |
| 12 | listen 10026; |
12 | listen 127.0.0.1:10026; |
| 13 | server_name ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion; |
13 | server_name ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion; |
| 14 | include custom.d/basic.conf; |
14 | include custom.d/basic.conf; |
| 15 | root /var/www/img/; |
15 | root /var/www/img/; |
linux/nginx/etc/nginx/conf.d/krz.sh.conf
+1 −1
| @@ -1,5 +1,5 @@ |
| 1 | server { |
1 | server { |
| 2 | listen 10047; |
2 | listen 127.0.0.1:10047; |
| 3 | server_name krz.sh; |
3 | server_name krz.sh; |
| 4 | root /var/www/krz.sh/; |
4 | root /var/www/krz.sh/; |
| 5 | absolute_redirect off; |
5 | absolute_redirect off; |
linux/nginx/etc/nginx/conf.d/office.conf
+3 −6
| @@ -1,17 +1,14 @@ |
| 1 | server { |
1 | server { |
| 2 | listen 10031; |
2 | listen 127.0.0.1:10031; |
| 3 | server_name office.zerolabs.sh office.cleberg.net; |
3 | server_name office.zerolabs.sh; |
| 4 | |
4 | |
| 5 | if ($host = office.cleberg.net) { |
| |
| 6 | return 301 https://office.zerolabs.sh$request_uri; |
| |
| 7 | } |
| |
| 8 | add_header Onion-Location "http://uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion$request_uri" always; |
5 | add_header Onion-Location "http://uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion$request_uri" always; |
| 9 | root /var/www/office/; |
6 | root /var/www/office/; |
| 10 | include custom.d/basic.conf; |
7 | include custom.d/basic.conf; |
| 11 | location / { try_files $uri $uri/ /index.html; } |
8 | location / { try_files $uri $uri/ /index.html; } |
| 12 | } |
9 | } |
| 13 | server { |
10 | server { |
| 14 | listen 10032; |
11 | listen 127.0.0.1:10032; |
| 15 | server_name uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion; |
12 | server_name uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion; |
| 16 | include custom.d/basic.conf; |
13 | include custom.d/basic.conf; |
| 17 | root /var/www/office/; |
14 | root /var/www/office/; |
linux/nginx/etc/nginx/conf.d/org.conf
+3 −6
| @@ -1,17 +1,14 @@ |
| 1 | server { |
1 | server { |
| 2 | listen 10033; |
2 | listen 127.0.0.1:10033; |
| 3 | server_name org.zerolabs.sh org.cleberg.net; |
3 | server_name org.zerolabs.sh; |
| 4 | |
4 | |
| 5 | if ($host = org.cleberg.net) { |
| |
| 6 | return 301 https://org.zerolabs.sh$request_uri; |
| |
| 7 | } |
| |
| 8 | add_header Onion-Location "http://7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion$request_uri" always; |
5 | add_header Onion-Location "http://7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion$request_uri" always; |
| 9 | root /var/www/org/; |
6 | root /var/www/org/; |
| 10 | include custom.d/basic.conf; |
7 | include custom.d/basic.conf; |
| 11 | location / { try_files $uri $uri/ /index.html; } |
8 | location / { try_files $uri $uri/ /index.html; } |
| 12 | } |
9 | } |
| 13 | server { |
10 | server { |
| 14 | listen 10034; |
11 | listen 127.0.0.1:10034; |
| 15 | server_name 7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion; |
12 | server_name 7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion; |
| 16 | include custom.d/basic.conf; |
13 | include custom.d/basic.conf; |
| 17 | root /var/www/org/; |
14 | root /var/www/org/; |
linux/nginx/etc/nginx/conf.d/projects.conf
+3 −6
| @@ -1,10 +1,7 @@ |
| 1 | server { |
1 | server { |
| 2 | listen 10040; |
2 | listen 127.0.0.1:10040; |
| 3 | server_name projects.zerolabs.sh projects.cleberg.net; |
3 | server_name projects.zerolabs.sh; |
| 4 | |
4 | |
| 5 | if ($host = projects.cleberg.net) { |
| |
| 6 | return 301 https://projects.zerolabs.sh$request_uri; |
| |
| 7 | } |
| |
| 8 | add_header Onion-Location "http://krednuajd2wpt67ozmkollddpbdphpeyh74hbenagzoxqjncrtrgxkid.onion$request_uri" always; |
5 | add_header Onion-Location "http://krednuajd2wpt67ozmkollddpbdphpeyh74hbenagzoxqjncrtrgxkid.onion$request_uri" always; |
| 9 | root /var/www/projects/; |
6 | root /var/www/projects/; |
| 10 | autoindex on; |
7 | autoindex on; |
| @@ -13,7 +10,7 @@ server { |
| 13 | } |
10 | } |
| 14 | |
11 | |
| 15 | server { |
12 | server { |
| 16 | listen 10041; |
13 | listen 127.0.0.1:10041; |
| 17 | server_name krednuajd2wpt67ozmkollddpbdphpeyh74hbenagzoxqjncrtrgxkid.onion; |
14 | server_name krednuajd2wpt67ozmkollddpbdphpeyh74hbenagzoxqjncrtrgxkid.onion; |
| 18 | include custom.d/basic.conf; |
15 | include custom.d/basic.conf; |
| 19 | root /var/www/projects/; |
16 | root /var/www/projects/; |
linux/nginx/etc/nginx/conf.d/reminiscecleberg.com.conf
+1 −1
| @@ -1,7 +1,7 @@ |
| 1 | |
1 | |
| 2 | |
2 | |
| 3 | server { |
3 | server { |
| 4 | listen 10043; |
4 | listen 127.0.0.1:10043; |
| 5 | server_name reminiscecleberg.com; |
5 | server_name reminiscecleberg.com; |
| 6 | root /var/www/reminiscecleberg.com/; |
6 | root /var/www/reminiscecleberg.com/; |
| 7 | include custom.d/basic.conf; |
7 | include custom.d/basic.conf; |
linux/nginx/etc/nginx/conf.d/rogue.conf
+1 −1
| @@ -1,5 +1,5 @@ |
| 1 | server { |
1 | server { |
| 2 | listen 10001; |
2 | listen 127.0.0.1:10001; |
| 3 | server_name rogue.krz.sh; |
3 | server_name rogue.krz.sh; |
| 4 | |
4 | |
| 5 | root /var/www/rogue; |
5 | root /var/www/rogue; |
linux/nginx/etc/nginx/conf.d/rss.conf
+2 −5
| @@ -1,11 +1,8 @@ |
| 1 | upstream freshrss { server 127.0.0.1:8099; keepalive 64; } |
1 | upstream freshrss { server 127.0.0.1:8099; keepalive 64; } |
| 2 | server { |
2 | server { |
| 3 | listen 10045; |
3 | listen 127.0.0.1:10045; |
| 4 | server_name rss.zerolabs.sh rss.cleberg.net; |
4 | server_name rss.zerolabs.sh; |
| 5 | |
5 | |
| 6 | if ($host = rss.cleberg.net) { |
| |
| 7 | return 301 https://rss.zerolabs.sh$request_uri; |
| |
| 8 | } |
| |
| 9 | include custom.d/basic.conf; |
6 | include custom.d/basic.conf; |
| 10 | location / { |
7 | location / { |
| 11 | proxy_pass http://freshrss/; |
8 | proxy_pass http://freshrss/; |
linux/nginx/etc/nginx/conf.d/zerolabs.sh.conf
+6 −1
| @@ -5,8 +5,13 @@ map $host $krz_target { |
| 5 | } |
5 | } |
| 6 | |
6 | |
| 7 | server { |
7 | server { |
| 8 | listen 10000; |
8 | listen 127.0.0.1:10000; |
| 9 | server_name zerolabs.sh *.zerolabs.sh; |
9 | server_name zerolabs.sh *.zerolabs.sh; |
| 10 | |
10 | |
| |
11 | # This vhost is a bare redirect and does not include basic.conf, so HSTS |
| |
12 | # is set explicitly -- otherwise the redirect hop is the one response on |
| |
13 | # this domain without it. |
| |
14 | include custom.d/security/strict-transport-security.conf; |
| |
15 | |
| 11 | return 301 https://$krz_target$request_uri; |
16 | return 301 https://$krz_target$request_uri; |
| 12 | } |
17 | } |
linux/nginx/etc/nginx/custom.d/basic.conf
+8
| @@ -4,5 +4,13 @@ |
| 4 | include custom.d/security/referrer-policy.conf; |
4 | include custom.d/security/referrer-policy.conf; |
| 5 | include custom.d/security/x-content-type-options.conf; |
5 | include custom.d/security/x-content-type-options.conf; |
| 6 | include custom.d/security/x-frame-options.conf; |
6 | include custom.d/security/x-frame-options.conf; |
| |
7 | include custom.d/security/strict-transport-security.conf; |
| |
8 | include custom.d/security/permissions-policy.conf; |
| 7 | include custom.d/location/security_file_access.conf; |
9 | include custom.d/location/security_file_access.conf; |
| 8 | #include custom.d/cross-origin/requests.conf; |
10 | #include custom.d/cross-origin/requests.conf; |
| |
11 | |
| |
12 | # HSTS and Permissions-Policy live here, not per-vhost: every vhost is HTTPS |
| |
13 | # via the tunnel, so the commitment is universal. CSP is deliberately NOT |
| |
14 | # here -- it is content-type-mapped and a blanket policy breaks app UIs, so |
| |
15 | # it stays per-vhost until the per-app pass. Note that rogue.conf does not |
| |
16 | # include this file (intentional: it strips headers as a byte-size test). |
linux/nginx/etc/nginx/custom.d/tls/certificate_files.conf
deleted
−2
| @@ -1,2 +0,0 @@ |
| 1 | # Legacy include name: cleberg.net certificate (most zerolabs/cleberg.net vhosts). |
| |
| 2 | include certificate_files_cleberg_net.conf; |
| |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_dev.conf
deleted
−3
| @@ -1,3 +0,0 @@ |
| 1 | ssl_certificate /etc/letsencrypt/live/cleberg.dev/fullchain.pem; |
| |
| 2 | ssl_certificate_key /etc/letsencrypt/live/cleberg.dev/privkey.pem; |
| |
| 3 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.dev/chain.pem; |
| |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_io.conf
deleted
−3
| @@ -1,3 +0,0 @@ |
| 1 | ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem; |
| |
| 2 | ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem; |
| |
| 3 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem; |
| |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_net.conf
deleted
−16
| @@ -1,16 +0,0 @@ |
| 1 | # ---------------------------------------------------------------------- |
| |
| 2 | # | Certificate files — cleberg.net | |
| |
| 3 | # ---------------------------------------------------------------------- |
| |
| 4 | |
| |
| 5 | # This default SSL certificate will be served whenever the client lacks support |
| |
| 6 | # for SNI (Server Name Indication). |
| |
| 7 | # |
| |
| 8 | # (1) Certificate and key files location |
| |
| 9 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate |
| |
| 10 | # |
| |
| 11 | # (2) Intermediate certificate for OCSP stapling |
| |
| 12 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_trusted_certificate |
| |
| 13 | |
| |
| 14 | ssl_certificate /etc/letsencrypt/live/cleberg.net/fullchain.pem; |
| |
| 15 | ssl_certificate_key /etc/letsencrypt/live/cleberg.net/privkey.pem; |
| |
| 16 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.net/chain.pem; |
| |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_reminiscecleberg_com.conf
deleted
−3
| @@ -1,3 +0,0 @@ |
| 1 | ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem; |
| |
| 2 | ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem; |
| |
| 3 | ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem; |
| |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_zerolabs_sh.conf
deleted
−3
| @@ -1,3 +0,0 @@ |
| 1 | ssl_certificate /etc/letsencrypt/live/zerolabs.sh/fullchain.pem; |
| |
| 2 | ssl_certificate_key /etc/letsencrypt/live/zerolabs.sh/privkey.pem; |
| |
| 3 | ssl_trusted_certificate /etc/letsencrypt/live/zerolabs.sh/chain.pem; |
| |
linux/nginx/etc/nginx/custom.d/tls/ocsp_stapling.conf
deleted
−34
| @@ -1,34 +0,0 @@ |
| 1 | # ---------------------------------------------------------------------- |
| |
| 2 | # | Online Certificate Status Protocol stapling | |
| |
| 3 | # ---------------------------------------------------------------------- |
| |
| 4 | |
| |
| 5 | # OCSP is a lightweight, only one record to help clients verify the validity of |
| |
| 6 | # the server certificate. |
| |
| 7 | # OCSP stapling allows the server to send its cached OCSP record during the TLS |
| |
| 8 | # handshake, without the need of 3rd party OCSP responder. |
| |
| 9 | # |
| |
| 10 | # https://wiki.mozilla.org/Security/Server_Side_TLS#OCSP_Stapling |
| |
| 11 | # https://tools.ietf.org/html/rfc6066#section-8 |
| |
| 12 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling |
| |
| 13 | # |
| |
| 14 | # (1) Use Cloudflare 1.1.1.1 DNS resolver |
| |
| 15 | # https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1/ |
| |
| 16 | # |
| |
| 17 | # (2) Use Google 8.8.8.8 DNS resolver |
| |
| 18 | # https://developers.google.com/speed/public-dns/docs/using |
| |
| 19 | # |
| |
| 20 | # (3) Use OpenDNS resolver |
| |
| 21 | # https://use.opendns.com |
| |
| 22 | |
| |
| 23 | ssl_stapling on; |
| |
| 24 | ssl_stapling_verify on; |
| |
| 25 | |
| |
| 26 | resolver |
| |
| 27 | # (1) |
| |
| 28 | 1.1.1.1 1.0.0.1 [2606:4700:4700::1111] [2606:4700:4700::1001] |
| |
| 29 | # (2) |
| |
| 30 | 8.8.8.8 8.8.4.4 [2001:4860:4860::8888] [2001:4860:4860::8844] |
| |
| 31 | # (3) |
| |
| 32 | # 208.67.222.222 208.67.220.220 [2620:119:35::35] [2620:119:53::53] |
| |
| 33 | valid=60s; |
| |
| 34 | resolver_timeout 2s; |
| |
linux/nginx/etc/nginx/custom.d/tls/policy_balanced.conf
deleted
−20
| @@ -1,20 +0,0 @@ |
| 1 | # ---------------------------------------------------------------------- |
| |
| 2 | # | SSL policy - Balanced | |
| |
| 3 | # ---------------------------------------------------------------------- |
| |
| 4 | |
| |
| 5 | # For services that need to support a wide range of clients, this configuration |
| |
| 6 | # is reasonably balanced. |
| |
| 7 | # |
| |
| 8 | # (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak |
| |
| 9 | # and potentially vulnerable but are required to support Microsoft Edge |
| |
| 10 | # and Safari. |
| |
| 11 | # https://safecurves.cr.yp.to/ |
| |
| 12 | # |
| |
| 13 | # https://wiki.mozilla.org/Security/Server_Side_TLS#Recommended_configurations |
| |
| 14 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html |
| |
| 15 | |
| |
| 16 | ssl_protocols TLSv1.2; |
| |
| 17 | ssl_ciphers EECDH+CHACHA20:EECDH+AES; |
| |
| 18 | |
| |
| 19 | # (1) |
| |
| 20 | ssl_ecdh_curve X25519:prime256v1:secp521r1:secp384r1; |
| |
linux/nginx/etc/nginx/custom.d/tls/policy_strict.conf
deleted
−50
| @@ -1,50 +0,0 @@ |
| 1 | # ---------------------------------------------------------------------- |
| |
| 2 | # | SSL policy - Strict | |
| |
| 3 | # ---------------------------------------------------------------------- |
| |
| 4 | |
| |
| 5 | # For services that don't need backward compatibility, the parameters below |
| |
| 6 | # provide the highest level of security and performance. |
| |
| 7 | # |
| |
| 8 | # (!) This policy enforces a strong TLS configuration, which may raise |
| |
| 9 | # errors with old clients. |
| |
| 10 | # If a more compatible profile is required, use the "balanced" policy. |
| |
| 11 | # |
| |
| 12 | # (!) TLSv1.3 and its 0-RTT feature require NGINX >=1.15.4 and OpenSSL >=1.1.1 |
| |
| 13 | # to be installed. |
| |
| 14 | # |
| |
| 15 | # (!) Don't enable `ssl_early_data` blindly! Requests sent within early data are |
| |
| 16 | # subject to replay attacks. |
| |
| 17 | # |
| |
| 18 | # (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak |
| |
| 19 | # and potentially vulnerable. |
| |
| 20 | # |
| |
| 21 | # Add them back to the parameter `ssl_ecdh_curve` below to support |
| |
| 22 | # Microsoft Edge and Safari. |
| |
| 23 | # |
| |
| 24 | # https://safecurves.cr.yp.to/ |
| |
| 25 | # |
| |
| 26 | # (2) Enables TLS 1.3 0-RTT, allows for faster resumption of TLS sessions. |
| |
| 27 | # |
| |
| 28 | # (!) Requests sent within early data are subject to replay attacks. |
| |
| 29 | # To protect against such attacks at the application layer, the |
| |
| 30 | # `$ssl_early_data` variable should be used: |
| |
| 31 | # |
| |
| 32 | # proxy_set_header Early-Data $ssl_early_data; |
| |
| 33 | # |
| |
| 34 | # The application should return response code 425 "Too Early" for anything |
| |
| 35 | # that could contain user supplied data. |
| |
| 36 | # |
| |
| 37 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/425 |
| |
| 38 | # |
| |
| 39 | # https://github.com/certbot/certbot/issues/6367 |
| |
| 40 | # https://github.com/mozilla/server-side-tls/issues/217 |
| |
| 41 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html |
| |
| 42 | |
| |
| 43 | ssl_protocols TLSv1.2 TLSv1.3; |
| |
| 44 | ssl_ciphers EECDH+CHACHA20:EECDH+AES; |
| |
| 45 | |
| |
| 46 | # (1) |
| |
| 47 | ssl_ecdh_curve X25519; |
| |
| 48 | |
| |
| 49 | # (2) |
| |
| 50 | #ssl_early_data on; |
| |
linux/nginx/etc/nginx/custom.d/tls/ssl_engine.conf
deleted
−47
| @@ -1,47 +0,0 @@ |
| 1 | # ---------------------------------------------------------------------- |
| |
| 2 | # | SSL engine | |
| |
| 3 | # ---------------------------------------------------------------------- |
| |
| 4 | |
| |
| 5 | # (1) Optimize SSL by caching session parameters for 24 hours. |
| |
| 6 | # This cuts down on the number of expensive SSL handshakes. |
| |
| 7 | # By enabling a cache, we tell the client to re-use the already |
| |
| 8 | # negotiated state. |
| |
| 9 | # Here 10m (10 MB) in ssl_session_cache is size value (not time). |
| |
| 10 | # 1 MB cache can store about 4000 sessions, so we can store 40000 sessions. |
| |
| 11 | # |
| |
| 12 | # (2) Use a higher keepalive timeout to reduce the need for repeated handshakes |
| |
| 13 | # (!) Shouldn't be done unless you serve primarily HTTPS. |
| |
| 14 | # Default is 75s |
| |
| 15 | # |
| |
| 16 | # (3) SSL buffer size |
| |
| 17 | # Set 1400 bytes to fit in one MTU. |
| |
| 18 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_buffer_size |
| |
| 19 | # |
| |
| 20 | # (4) Disable session tickets |
| |
| 21 | # Session tickets keys are not auto-rotated. Only a HUP / restart will do |
| |
| 22 | # so and when a restart is performed the previous key is lost, which resets |
| |
| 23 | # all previous sessions. |
| |
| 24 | # Only enable session tickets if you set up a manual rotation mechanism. |
| |
| 25 | # https://trac.nginx.org/nginx/changeset/1356a3b9692441e163b4e78be4e9f5a46c7479e9/nginx |
| |
| 26 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_tickets |
| |
| 27 | # |
| |
| 28 | # (5) The TLS 1.2 and 1.3 ciphers in use in current policies are not considered |
| |
| 29 | # dangerous. This directive let the client choose the one that best fits their needs. |
| |
| 30 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_prefer_server_ciphers |
| |
| 31 | # https://wiki.mozilla.org/Security/Server_Side_TLS |
| |
| 32 | |
| |
| 33 | # (1) |
| |
| 34 | ssl_session_timeout 24h; |
| |
| 35 | ssl_session_cache shared:SSL:10m; |
| |
| 36 | |
| |
| 37 | # (2) |
| |
| 38 | keepalive_timeout 300s; |
| |
| 39 | |
| |
| 40 | # (3) |
| |
| 41 | # ssl_buffer_size 1400; |
| |
| 42 | |
| |
| 43 | # (4) |
| |
| 44 | ssl_session_tickets off; |
| |
| 45 | |
| |
| 46 | # (5) |
| |
| 47 | ssl_prefer_server_ciphers off; |
| |