user nginx; worker_processes auto; error_log /dev/null; # /var/log/nginx/error.log notice; pid /var/run/nginx.pid; events { worker_connections 1024; } http { include /etc/nginx/mime.types; default_type application/octet-stream; log_format main '$remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; access_log /dev/null main; server_tokens off; sendfile on; tcp_nopush on; quic_retry on; ssl_early_data on; quic_gso on; keepalive_timeout 65; gzip on; # modern configuration ssl_protocols TLSv1.3; ssl_ecdh_curve X25519:prime256v1:secp384r1; ssl_prefer_server_ciphers off; # OCSP stapling ssl_stapling on; ssl_stapling_verify on; # replace with the IP address of your resolver; # async 'resolver' is important for proper operation of OCSP stapling resolver 2001:4860:4860::8888 2001:4860:4860::8844; # If certificates are marked OCSP Must-Staple, consider managing the # OCSP stapling cache with an external script, e.g. certbot-ocsp-fetcher # HTTPS redirect server { listen 80 default_server; listen [::]:80 default_server; return 301 https://$host$request_uri; } # default HTTPS server server { listen 443 ssl default_server; listen 443 quic reuseport default_server; listen [::]:443 ssl default_server; return 200; } include /etc/nginx/conf.d/*.conf; }