diff --git a/vHost_friendica.conf b/vHost_friendica.conf index 23b8d10..be84688 100644 --- a/vHost_friendica.conf +++ b/vHost_friendica.conf @@ -17,9 +17,9 @@ server { #ssl on; ssl_stapling on; ssl_stapling_verify on; - ssl_trusted_certificate /etc/ssl/private/schuerz.at.cert; - ssl_certificate /etc/ssl/private/schuerz.at.cert; - ssl_certificate_key /etc/ssl/private/schuerz.at.key; + ssl_trusted_certificate ; + ssl_certificate ; + ssl_certificate_key ; ssl_session_timeout 5m; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_ciphers ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS; @@ -41,9 +41,6 @@ server { # allow uploads up to 20MB in size client_max_body_size 20m; client_body_buffer_size 128k; - # add_header 'Access-Control-Allow-Origin' 'https://schuerz.at/'; - #add_header 'Access-Control-Allow-Origin' *; - #add_header 'Access-Control-Allow-Origin' '*.schuerz.at'; add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"; add_header Referrer-Policy "same-origin" always; add_header Permissions-Policy "payment=()" always;