Похожие чаты

Hi, I'm trying to configure 3 ssl sites under nginx

and have the ssl certs loaded accordingly to the domain name:
As now my default server config is:

server {
listen 1880;
listen 8443 ssl;

if ($host ~ ^www\.(?<domain>.+)$) {
rewrite / $scheme://$domain$request_uri permanent;
}
if ($scheme ~ http://) {
rewrite / https://$hostname:8443$request_uri permanent;
}
ssl_certificate /etc/letsencrypt/live/$hostname/cert.pem;
ssl_certificate_key /etc/letsencrypt/live/$hostname/privkey.pem;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
root /var/www/html/cdbd/web;
index index.html;

I'm new to nginx and probably not seeing something, the cert for one domain work but not for the other 2 and fails with error 0200100D, file rights access, nginx is started as a service, as root, the owner of the cert files

3 ответов

48 просмотров

Стикер

Стикер

The nginx is started as root, but it drops the permissions quickly after start. usually this is www-data. So the relevant owner of the certs is www-data. ssl_protocols should be tls1.3 and maybe 1.2, but everything else is an security issue

Похожие вопросы

Обсуждают сегодня

Господа, а что сейчас вообще с рынком труда на делфи происходит? Какова ситуация?
Rꙮman Yankꙮvsky
29
А вообще, что может смущать в самой Julia - бы сказал, что нет единого стандартного подхода по многим моментам, поэтому многое выглядит как "хаки" и произвол. Короче говоря, с...
Viktor G.
2
@Benzenoid can you tell me the easiest, and safest way to bu.y HEX now?
Živa Žena
20
This is a question from my wife who make a fortune with memes 😂😂 About the Migration and Tokens: 1. How will the old tokens be migrated to the new $LGCYX network? What is th...
🍿 °anton°
2
30500 за редактор? )
Владимир
47
а через ESC-код ?
Alexey Kulakov
29
What is the Dex situation? Agora team started with the Pnetwork for their dex which helped them both with integration. It’s completed but as you can see from the Pnetwork ann...
Ben
1
Гайс, вопрос для разносторонее развитых: читаю стрим с юарта, нада выделять с него фреймы с определенной структурой, если ли чо готовое, или долбаться с ринг буффером? нада у...
Vitaly
9
Anyone knows where there are some instructions or discort about failed bridge transactions ?
Jochem
21
@lozuk how do I get my phex copies of my ehex from a atomic wallet, to move to my rabby?
Justfrontin 👀
11
Карта сайта