server
{
        listen 443;
        ssl on;
#需按情况修改为真实证书路径
        ssl_certificate /www/ssl/pan.lovexu.ooo/fullchain.pem;        
        ssl_certificate_key /www/ssl/pan.lovexu.ooo/privkey.pem;       
        ssl_session_cache  builtin:1000  shared:SSL:10m;
        ssl_ciphers HIGH:!aNULL:!eNULL:!EXPORT:!CAMELLIA:!DES:!MD5:!PSK:!RC4;
        ssl_prefer_server_ciphers on;
        server_name pan.lovexu.ooo;
        location /
		{
        proxy_pass https://pan.lovexu.ooo:8443;  #frp代理地址和端口,需与frp配置文件中域名相同
        proxy_ssl_server_name on;
        proxy_ssl_session_reuse off;
        proxy_set_header Host $http_host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Fprwarded-Proto $scheme;
        proxy_ssl_verify   off;
        proxy_redirect http:// $scheme://;
        proxy_ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
        }

}

之前网上找了好多都是错误的,比如说下面这列:

server {
       listen 443;  
       server_name pan.lovexu.ooo;
       ssl on;       
       ssl_certificate /www/ssl/pan.lovexu.ooo/fullchain.pem;        
       ssl_certificate_key /www/ssl/pan.lovexu.ooo/privkey.pem;          
       ssl_session_timeout 5m;       
       ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;       
       ssl_protocols TLSv1 TLSv1.1 TLSv1.2;       
       ssl_prefer_server_ciphers on; 
       location /        
          {           
          proxy_pass https://127.0.0.1:8443;            
          proxy_redirect https://$host/ https://$http_host/;           
          proxy_set_header X-Real-IP $remote_addr;           
          proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;           
          proxy_set_header Host $host; 
          proxy_set_header X-Forwarded-proto https;
          }    
         }

 

届ける言葉を今は育ててる
最后更新于 2018-07-18