home · contact · privacy
Improve web server setup.
authorChristian Heller <c.heller@plomlompom.de>
Mon, 3 Dec 2018 23:14:57 +0000 (00:14 +0100)
committerChristian Heller <c.heller@plomlompom.de>
Mon, 3 Dec 2018 23:14:57 +0000 (00:14 +0100)
all_new_2018/linkable_etc_files/web/etc/nginx/nginx.conf
all_new_2018/setup_web.sh [new file with mode: 0644]

index 1072651ca39c1006eef72735c9a4784ee715f146..c5cbe48431f38f77ed05d353b05bd0197dcaea6b 100644 (file)
@@ -26,7 +26,7 @@ http {
        #access_log /var/log/nginx/access.log;
        #error_log /var/log/nginx/error.log;
 
        #access_log /var/log/nginx/access.log;
        #error_log /var/log/nginx/error.log;
 
-        # HTTP server: only enforce HTTPS 
+        # HTTP server: only enforce HTTPS
         server {
                 listen 80;
                 return 301 https://$host$request_uri;
         server {
                 listen 80;
                 return 301 https://$host$request_uri;
@@ -35,9 +35,9 @@ http {
        # HTTPS server
         server {
                 listen 443 ssl;
        # HTTPS server
         server {
                 listen 443 ssl;
-                server_name web20181130.plomlompom.com;
-                ssl_certificate /etc/letsencrypt/live/web20181130.plomlompom.com/fullchain.pem;
-                ssl_certificate_key /etc/letsencrypt/live/web20181130.plomlompom.com/privkey.pem;
+                server_name REPLACE_fqdn_ECALPER;
+                ssl_certificate /etc/letsencrypt/live/REPLACE_fqdn_ECALPER/fullchain.pem;
+                ssl_certificate_key /etc/letsencrypt/live/REPLACE_fqdn_ECALPER/privkey.pem;
                 root /var/www/html/;
                index index.html index.htm index.nginx-debian.html;
         }
                 root /var/www/html/;
                index index.html index.htm index.nginx-debian.html;
         }
diff --git a/all_new_2018/setup_web.sh b/all_new_2018/setup_web.sh
new file mode 100644 (file)
index 0000000..8aac7ef
--- /dev/null
@@ -0,0 +1,7 @@
+#!/bin/sh
+set -e
+
+./hardlink_etc.sh web
+sed -i "s/REPLACE_fqdn_ECALPER/$(hostname -f)/g" /etc/nginx/nginx.conf
+apt -y -o Dpkg::Options::=--force-confold install nginx
+iptables-restore /etc/iptables/rules.v4