From dc56175d4316090fef79447ddf2f680d346568b8 Mon Sep 17 00:00:00 2001 From: "a.bouhuolia" Date: Tue, 21 Sep 2021 13:33:24 +0200 Subject: [PATCH] feat: add nginx ssl certicate. --- client/Dockerfile | 1 + client/nginx/certs/bigcapital.ly/cert.pem | 30 ++++++ client/nginx/certs/bigcapital.ly/chain.pem | 62 +++++++++++++ .../nginx/certs/bigcapital.ly/fullchain.pem | 92 +++++++++++++++++++ .../bigcapital.ly/options-ssl-nginx.conf | 14 +++ client/nginx/certs/bigcapital.ly/privkey.pem | 28 ++++++ .../certs/bigcapital.ly/ssl-dhparams.pem | 8 ++ client/nginx/sites/node-https.template | 8 +- 8 files changed, 240 insertions(+), 3 deletions(-) create mode 100644 client/nginx/certs/bigcapital.ly/cert.pem create mode 100644 client/nginx/certs/bigcapital.ly/chain.pem create mode 100644 client/nginx/certs/bigcapital.ly/fullchain.pem create mode 100644 client/nginx/certs/bigcapital.ly/options-ssl-nginx.conf create mode 100644 client/nginx/certs/bigcapital.ly/privkey.pem create mode 100644 client/nginx/certs/bigcapital.ly/ssl-dhparams.pem diff --git a/client/Dockerfile b/client/Dockerfile index b619f9a01..4b092a9bc 100644 --- a/client/Dockerfile +++ b/client/Dockerfile @@ -28,6 +28,7 @@ FROM nginx COPY nginx/sites /etc/nginx/templates COPY ./nginx/scripts /root/scripts/ +COPY nginx/certs /etc/ssl/ # COPY ./nginx/nginx.conf /etc/nginx/conf.d/default.conf RUN /bin/bash /root/scripts/nginx-build.sh diff --git a/client/nginx/certs/bigcapital.ly/cert.pem b/client/nginx/certs/bigcapital.ly/cert.pem new file mode 100644 index 000000000..53676c6d6 --- /dev/null +++ b/client/nginx/certs/bigcapital.ly/cert.pem @@ -0,0 +1,30 @@ +-----BEGIN CERTIFICATE----- +MIIFITCCBAmgAwIBAgISBCEYRF6ZI4rvByqWHFTIVE7uMA0GCSqGSIb3DQEBCwUA +MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD +EwJSMzAeFw0yMTA5MTgxNjMxMjZaFw0yMTEyMTcxNjMxMjVaMBgxFjAUBgNVBAMT +DWJpZ2NhcGl0YWwubHkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCW +b5Hq9KmqAjkqg2Z80RFst3fYOgwd4lm7HiLkBbMFLySUOfMwMO7ShNKA3Wt+T0jY +YH2CrK75jqY6tnI0Lj9mxiNESBeNrqpRjH9a3Fy1SGO/EvR99DJ5umntCu0IOkjU +aOXmMzSJNVSim65Qaty/XCgaKZ7+mxnmo2O2Lrr8bPcxLD5KvFuOu0yTIj41tCJy +PEeRg1s3DhBqohE+zEeV5l/F64358igoqBo6GBTRv2GCI+alPwYqvFwW6ptdaUvz +YMWV8Bzh0wkjYlacMAns4sxQ4GTzHbfG4vs/TjaDLEiPW9EYbgmrQa5kxdIanATc +V62Tygrd44d2nQmf0V/XAgMBAAGjggJJMIICRTAOBgNVHQ8BAf8EBAMCBaAwHQYD +VR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYDVR0O +BBYEFJmagLvYa9FJMa9dLOCgQ8jc9QPDMB8GA1UdIwQYMBaAFBQusxe3WFbLrlAJ +QOYfr52LFMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYVaHR0cDovL3Iz +Lm8ubGVuY3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5sZW5jci5vcmcv +MBgGA1UdEQQRMA+CDWJpZ2NhcGl0YWwubHkwTAYDVR0gBEUwQzAIBgZngQwBAgEw +NwYLKwYBBAGC3xMBAQEwKDAmBggrBgEFBQcCARYaaHR0cDovL2Nwcy5sZXRzZW5j +cnlwdC5vcmcwggEFBgorBgEEAdZ5AgQCBIH2BIHzAPEAdgCUILwejtWNbIhzH4KL +IiwN0dpNXmxPlD1h204vWE2iwgAAAXv59n8zAAAEAwBHMEUCIQDwvd9fCsEGsfa+ +MhW1ICBMHLoiZZ1ZWFyONLJFQVUG9AIgOr58xaJryfblhiv59nkrS2FKN5247qYE +IfgRm205XI4AdwB9PvL4j/+IVWgkwsDKnlKJeSvFDngJfy5ql2iZfiLw1wAAAXv5 +9n9YAAAEAwBIMEYCIQC1mHqIipsv2NhYvVeXNt3rJKfjO4OSfWU1b4KhUTaRXgIh +ALvCoONxOFGUaFWLkY6HM10cvBsIFmFcng1QnYFU3pYXMA0GCSqGSIb3DQEBCwUA +A4IBAQAsS+g4xVp9E1vHZc0JQxKWTFap/3rzBq1yPyNd5VGYO3F8L/kNc08bup24 +F4GID8DpLLFX/7bApvfQqp5/Yps+YyfXiXNJ3jO4uH8ww24rKBEAzDOliSrqI2Cn +gg457v3oMbkhahcOY9Prz+LqxCkRsi81cqTtrbkiw0I2q1QXAUqwlUZPXmoep7FJ +dsOFTtOYe6dP80Y+htuva9C6qfSmamZIsH8eJsmxrJzRiv1bU0tP9i6ZmCNABXwE +q0s8ixrbL5RdeV5/6X5PR06nG9VR9jlzTA2JyosM6Ptc6Rrx2Xt9vw4dig3JkUV5 +lwuRGoo7SGYRoHDZ+zV4OqJhDa6g +-----END CERTIFICATE----- diff --git a/client/nginx/certs/bigcapital.ly/chain.pem b/client/nginx/certs/bigcapital.ly/chain.pem new file mode 100644 index 000000000..f8a9f198f --- /dev/null +++ b/client/nginx/certs/bigcapital.ly/chain.pem @@ -0,0 +1,62 @@ +-----BEGIN CERTIFICATE----- +MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw +TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh +cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw +WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg +RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK +AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP +R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx +sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm +NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg +Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG +/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC +AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB +Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA +FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw +AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw +Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB +gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W +PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl +ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz +CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm +lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4 +avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2 +yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O +yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids +hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+ +HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv +MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX +nLRbwHOoq7hHwg== +-----END CERTIFICATE----- + +-----BEGIN CERTIFICATE----- +MIIFYDCCBEigAwIBAgIQQAF3ITfU6UK47naqPGQKtzANBgkqhkiG9w0BAQsFADA/ +MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT +DkRTVCBSb290IENBIFgzMB4XDTIxMDEyMDE5MTQwM1oXDTI0MDkzMDE4MTQwM1ow +TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh +cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwggIiMA0GCSqGSIb3DQEB +AQUAA4ICDwAwggIKAoICAQCt6CRz9BQ385ueK1coHIe+3LffOJCMbjzmV6B493XC +ov71am72AE8o295ohmxEk7axY/0UEmu/H9LqMZshftEzPLpI9d1537O4/xLxIZpL +wYqGcWlKZmZsj348cL+tKSIG8+TA5oCu4kuPt5l+lAOf00eXfJlII1PoOK5PCm+D +LtFJV4yAdLbaL9A4jXsDcCEbdfIwPPqPrt3aY6vrFk/CjhFLfs8L6P+1dy70sntK +4EwSJQxwjQMpoOFTJOwT2e4ZvxCzSow/iaNhUd6shweU9GNx7C7ib1uYgeGJXDR5 +bHbvO5BieebbpJovJsXQEOEO3tkQjhb7t/eo98flAgeYjzYIlefiN5YNNnWe+w5y +sR2bvAP5SQXYgd0FtCrWQemsAXaVCg/Y39W9Eh81LygXbNKYwagJZHduRze6zqxZ +Xmidf3LWicUGQSk+WT7dJvUkyRGnWqNMQB9GoZm1pzpRboY7nn1ypxIFeFntPlF4 +FQsDj43QLwWyPntKHEtzBRL8xurgUBN8Q5N0s8p0544fAQjQMNRbcTa0B7rBMDBc +SLeCO5imfWCKoqMpgsy6vYMEG6KDA0Gh1gXxG8K28Kh8hjtGqEgqiNx2mna/H2ql +PRmP6zjzZN7IKw0KKP/32+IVQtQi0Cdd4Xn+GOdwiK1O5tmLOsbdJ1Fu/7xk9TND +TwIDAQABo4IBRjCCAUIwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYw +SwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5pZGVudHJ1 +c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTEp7Gkeyxx ++tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEEAYLfEwEB +ATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2VuY3J5cHQu +b3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0LmNvbS9E +U1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFHm0WeZ7tuXkAXOACIjIGlj26Ztu +MA0GCSqGSIb3DQEBCwUAA4IBAQAKcwBslm7/DlLQrt2M51oGrS+o44+/yQoDFVDC +5WxCu2+b9LRPwkSICHXM6webFGJueN7sJ7o5XPWioW5WlHAQU7G75K/QosMrAdSW +9MUgNTP52GE24HGNtLi1qoJFlcDyqSMo59ahy2cI2qBDLKobkx/J3vWraV0T9VuG +WCLKTVXkcGdtwlfFRjlBz4pYg1htmf5X6DYO8A4jqv2Il9DjXA6USbW1FzXSLr9O +he8Y4IWS6wY7bCkjCWDcRQJMEhg76fsO3txE+FiYruq9RUWhiF1myv4Q6W+CyBFC +Dfvp7OOGAN6dEOM4+qR9sdjoSYKEBpsr6GtPAQw4dy753ec5 +-----END CERTIFICATE----- diff --git a/client/nginx/certs/bigcapital.ly/fullchain.pem b/client/nginx/certs/bigcapital.ly/fullchain.pem new file mode 100644 index 000000000..fe0d6f40e --- /dev/null +++ b/client/nginx/certs/bigcapital.ly/fullchain.pem @@ -0,0 +1,92 @@ +-----BEGIN CERTIFICATE----- +MIIFITCCBAmgAwIBAgISBCEYRF6ZI4rvByqWHFTIVE7uMA0GCSqGSIb3DQEBCwUA +MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD +EwJSMzAeFw0yMTA5MTgxNjMxMjZaFw0yMTEyMTcxNjMxMjVaMBgxFjAUBgNVBAMT +DWJpZ2NhcGl0YWwubHkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCW +b5Hq9KmqAjkqg2Z80RFst3fYOgwd4lm7HiLkBbMFLySUOfMwMO7ShNKA3Wt+T0jY +YH2CrK75jqY6tnI0Lj9mxiNESBeNrqpRjH9a3Fy1SGO/EvR99DJ5umntCu0IOkjU +aOXmMzSJNVSim65Qaty/XCgaKZ7+mxnmo2O2Lrr8bPcxLD5KvFuOu0yTIj41tCJy +PEeRg1s3DhBqohE+zEeV5l/F64358igoqBo6GBTRv2GCI+alPwYqvFwW6ptdaUvz +YMWV8Bzh0wkjYlacMAns4sxQ4GTzHbfG4vs/TjaDLEiPW9EYbgmrQa5kxdIanATc +V62Tygrd44d2nQmf0V/XAgMBAAGjggJJMIICRTAOBgNVHQ8BAf8EBAMCBaAwHQYD +VR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHQYDVR0O +BBYEFJmagLvYa9FJMa9dLOCgQ8jc9QPDMB8GA1UdIwQYMBaAFBQusxe3WFbLrlAJ +QOYfr52LFMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYVaHR0cDovL3Iz +Lm8ubGVuY3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5sZW5jci5vcmcv +MBgGA1UdEQQRMA+CDWJpZ2NhcGl0YWwubHkwTAYDVR0gBEUwQzAIBgZngQwBAgEw +NwYLKwYBBAGC3xMBAQEwKDAmBggrBgEFBQcCARYaaHR0cDovL2Nwcy5sZXRzZW5j +cnlwdC5vcmcwggEFBgorBgEEAdZ5AgQCBIH2BIHzAPEAdgCUILwejtWNbIhzH4KL +IiwN0dpNXmxPlD1h204vWE2iwgAAAXv59n8zAAAEAwBHMEUCIQDwvd9fCsEGsfa+ +MhW1ICBMHLoiZZ1ZWFyONLJFQVUG9AIgOr58xaJryfblhiv59nkrS2FKN5247qYE +IfgRm205XI4AdwB9PvL4j/+IVWgkwsDKnlKJeSvFDngJfy5ql2iZfiLw1wAAAXv5 +9n9YAAAEAwBIMEYCIQC1mHqIipsv2NhYvVeXNt3rJKfjO4OSfWU1b4KhUTaRXgIh +ALvCoONxOFGUaFWLkY6HM10cvBsIFmFcng1QnYFU3pYXMA0GCSqGSIb3DQEBCwUA +A4IBAQAsS+g4xVp9E1vHZc0JQxKWTFap/3rzBq1yPyNd5VGYO3F8L/kNc08bup24 +F4GID8DpLLFX/7bApvfQqp5/Yps+YyfXiXNJ3jO4uH8ww24rKBEAzDOliSrqI2Cn +gg457v3oMbkhahcOY9Prz+LqxCkRsi81cqTtrbkiw0I2q1QXAUqwlUZPXmoep7FJ +dsOFTtOYe6dP80Y+htuva9C6qfSmamZIsH8eJsmxrJzRiv1bU0tP9i6ZmCNABXwE +q0s8ixrbL5RdeV5/6X5PR06nG9VR9jlzTA2JyosM6Ptc6Rrx2Xt9vw4dig3JkUV5 +lwuRGoo7SGYRoHDZ+zV4OqJhDa6g +-----END CERTIFICATE----- +-----BEGIN CERTIFICATE----- +MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw +TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh +cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw +WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg +RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK +AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP +R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx +sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm +NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg +Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG +/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC +AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB +Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA +FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw +AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw +Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB +gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W +PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl +ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz +CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm +lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4 +avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2 +yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O +yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids +hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+ +HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv +MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX +nLRbwHOoq7hHwg== +-----END CERTIFICATE----- + +-----BEGIN CERTIFICATE----- +MIIFYDCCBEigAwIBAgIQQAF3ITfU6UK47naqPGQKtzANBgkqhkiG9w0BAQsFADA/ +MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT +DkRTVCBSb290IENBIFgzMB4XDTIxMDEyMDE5MTQwM1oXDTI0MDkzMDE4MTQwM1ow +TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh +cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwggIiMA0GCSqGSIb3DQEB +AQUAA4ICDwAwggIKAoICAQCt6CRz9BQ385ueK1coHIe+3LffOJCMbjzmV6B493XC +ov71am72AE8o295ohmxEk7axY/0UEmu/H9LqMZshftEzPLpI9d1537O4/xLxIZpL +wYqGcWlKZmZsj348cL+tKSIG8+TA5oCu4kuPt5l+lAOf00eXfJlII1PoOK5PCm+D +LtFJV4yAdLbaL9A4jXsDcCEbdfIwPPqPrt3aY6vrFk/CjhFLfs8L6P+1dy70sntK +4EwSJQxwjQMpoOFTJOwT2e4ZvxCzSow/iaNhUd6shweU9GNx7C7ib1uYgeGJXDR5 +bHbvO5BieebbpJovJsXQEOEO3tkQjhb7t/eo98flAgeYjzYIlefiN5YNNnWe+w5y +sR2bvAP5SQXYgd0FtCrWQemsAXaVCg/Y39W9Eh81LygXbNKYwagJZHduRze6zqxZ +Xmidf3LWicUGQSk+WT7dJvUkyRGnWqNMQB9GoZm1pzpRboY7nn1ypxIFeFntPlF4 +FQsDj43QLwWyPntKHEtzBRL8xurgUBN8Q5N0s8p0544fAQjQMNRbcTa0B7rBMDBc +SLeCO5imfWCKoqMpgsy6vYMEG6KDA0Gh1gXxG8K28Kh8hjtGqEgqiNx2mna/H2ql +PRmP6zjzZN7IKw0KKP/32+IVQtQi0Cdd4Xn+GOdwiK1O5tmLOsbdJ1Fu/7xk9TND +TwIDAQABo4IBRjCCAUIwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYw +SwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5pZGVudHJ1 +c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTEp7Gkeyxx ++tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEEAYLfEwEB +ATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2VuY3J5cHQu +b3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0LmNvbS9E +U1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFHm0WeZ7tuXkAXOACIjIGlj26Ztu +MA0GCSqGSIb3DQEBCwUAA4IBAQAKcwBslm7/DlLQrt2M51oGrS+o44+/yQoDFVDC +5WxCu2+b9LRPwkSICHXM6webFGJueN7sJ7o5XPWioW5WlHAQU7G75K/QosMrAdSW +9MUgNTP52GE24HGNtLi1qoJFlcDyqSMo59ahy2cI2qBDLKobkx/J3vWraV0T9VuG +WCLKTVXkcGdtwlfFRjlBz4pYg1htmf5X6DYO8A4jqv2Il9DjXA6USbW1FzXSLr9O +he8Y4IWS6wY7bCkjCWDcRQJMEhg76fsO3txE+FiYruq9RUWhiF1myv4Q6W+CyBFC +Dfvp7OOGAN6dEOM4+qR9sdjoSYKEBpsr6GtPAQw4dy753ec5 +-----END CERTIFICATE----- diff --git a/client/nginx/certs/bigcapital.ly/options-ssl-nginx.conf b/client/nginx/certs/bigcapital.ly/options-ssl-nginx.conf new file mode 100644 index 000000000..50cc690b5 --- /dev/null +++ b/client/nginx/certs/bigcapital.ly/options-ssl-nginx.conf @@ -0,0 +1,14 @@ +# This file contains important security parameters. If you modify this file +# manually, Certbot will be unable to automatically provide future security +# updates. Instead, Certbot will print and log an error message with a path to +# the up-to-date file that you will need to refer to when manually updating +# this file. + +ssl_session_cache shared:le_nginx_SSL:10m; +ssl_session_timeout 1440m; +ssl_session_tickets off; + +ssl_protocols TLSv1.2 TLSv1.3; +ssl_prefer_server_ciphers off; + +ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-SHA"; \ No newline at end of file diff --git a/client/nginx/certs/bigcapital.ly/privkey.pem b/client/nginx/certs/bigcapital.ly/privkey.pem new file mode 100644 index 000000000..3761e7d5b --- /dev/null +++ b/client/nginx/certs/bigcapital.ly/privkey.pem @@ -0,0 +1,28 @@ +-----BEGIN PRIVATE KEY----- +MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCWb5Hq9KmqAjkq +g2Z80RFst3fYOgwd4lm7HiLkBbMFLySUOfMwMO7ShNKA3Wt+T0jYYH2CrK75jqY6 +tnI0Lj9mxiNESBeNrqpRjH9a3Fy1SGO/EvR99DJ5umntCu0IOkjUaOXmMzSJNVSi +m65Qaty/XCgaKZ7+mxnmo2O2Lrr8bPcxLD5KvFuOu0yTIj41tCJyPEeRg1s3DhBq +ohE+zEeV5l/F64358igoqBo6GBTRv2GCI+alPwYqvFwW6ptdaUvzYMWV8Bzh0wkj +YlacMAns4sxQ4GTzHbfG4vs/TjaDLEiPW9EYbgmrQa5kxdIanATcV62Tygrd44d2 +nQmf0V/XAgMBAAECggEBAIh78vQrQ5814y2aB6rod5meHwIzL/kQ+n4Uymz8ar4i +VlqQ9P1c9+BRlzZJLRRs1FdTu6uKBjnuXQxZqOWErAsPasGxcoUd2fKguI7z7Lyg +T7b0eJOpsP3VzfK8/e6ACsGD5kjjXh+6He5ltlHJkjufXdbWuiSfDXG9/WI1pXoL +8mRk3L8hkVQWE9dduhcptlvDsf3loHd3ANBowAaJw8LH3KGJ0WpqW+t9V+mctA6o +RA4Opwchd3FAr7Re1inaqbyBSWar5rZGXTb1p8R4OHu9iZgqnlRLsBAxvaPAnXA6 +DVtgBg7miFl/Pp5U1e6szE8OKSXIfJ4TpRUcXi6EYOkCgYEAxTp9UXK1Jfb6tHua +3I6HTIgaIf7bkNljYjQ2yXM9p9EP5zfDRcruqYMxOL6MwIek0PTasO0IU3fhLFW/ +i9I2eaYseqXr8RNnaS7IN2WWHBsrz5v0yWVrBLE9Z67ztAFWlreREdaFID+O6dlC +P2CO5RGn3ymxsr9ERxdc9ASRwL0CgYEAw0OEl899MM57YAYgvsoxSQUOLLaPf1M8 +n1gNFUcRzoUUVa71fGvO4Dsa0sv48JXyplPh1a/F1N5DeWiGRSpmI+7S1YgJlw9A +isD9CHeD4pUAxezKr4xuoe6XsSLa9GAFigCeiVcU53l4EPTPsoVFfeA6uNTNywAi +P+HeR5kTfiMCgYAB+J6uBLZ4xaolyaJ3l9kUU7vnIRPys6mBnsH5a3RvS/Cbv/vs +o6WU/iGszoK7nd9w0zGoWQYfR3Bxr/21GQnAV3/UTfo4s5fx/iy0GQjSCRd8ALQG +m0PhjR/u/FmlL+o8oWMKyZkVBG2aOrilx4JGGdISsej7v1ugVkRwj+chBQKBgFhE +21mtKFC55rffzUmyKVly+Zdo57GNNShrK27k873CFxEsyDh4m8ptrZCBOIW5ozlh +TgPFM88osqPdhmUZ55ZyzchNeNhawrh2yWvcazgwV2shwfZdq110eApRUV2LUrWx +1fkL7p09IfO4V3PCH0np5WHMgUM1SkZKmqsPHeq1AoGBAKug7eMr9iiobJN5g5wr +QnqbjHiwe1ykYoO23+zy4BOjRnqOyUgjfG/awiNXSR1T53l52nxPaXglVZoEax7b +twgrgEOl1zuzO4gezVjlNjMiOGM2wsCrji79ZagjdGvrma+tVBek3bSvg2gARgvc +MkPHRsp2xSNBsmib2TVSOC02 +-----END PRIVATE KEY----- diff --git a/client/nginx/certs/bigcapital.ly/ssl-dhparams.pem b/client/nginx/certs/bigcapital.ly/ssl-dhparams.pem new file mode 100644 index 000000000..088f9673d --- /dev/null +++ b/client/nginx/certs/bigcapital.ly/ssl-dhparams.pem @@ -0,0 +1,8 @@ +-----BEGIN DH PARAMETERS----- +MIIBCAKCAQEA//////////+t+FRYortKmq/cViAnPTzx2LnFg84tNpWp4TZBFGQz ++8yTnc4kmz75fS/jY2MMddj2gbICrsRhetPfHtXV/WVhJDP1H18GbtCFY2VVPe0a +87VXE15/V8k1mE8McODmi3fipona8+/och3xWKE2rec1MKzKT0g6eXq8CrGCsyT7 +YdEIqUuyyOP7uWrat2DX9GgdT0Kj3jlN9K5W7edjcrsZCwenyO4KbXCeAvzhzffi +7MA0BM0oNC9hkXL+nOmFg/+OTxIy7vKBg8P+OxtMb61zO7X8vC7CIAXFjvGDfRaD +ssbzSibBsu/6iGtCOGEoXJf//////////wIBAg== +-----END DH PARAMETERS----- \ No newline at end of file diff --git a/client/nginx/sites/node-https.template b/client/nginx/sites/node-https.template index 65cc5c7fe..8b7a2d355 100644 --- a/client/nginx/sites/node-https.template +++ b/client/nginx/sites/node-https.template @@ -4,10 +4,12 @@ server { listen 443 default_server http2; ssl on; - ssl_certificate /etc/ssl/cert1.pem; - ssl_certificate_key /etc/ssl/privkey1.pem; + ssl_certificate /etc/ssl/bigcapital.ly/fullchain.pem; + ssl_certificate_key /etc/ssl/bigcapital.ly/privkey.pem; + include /etc/ssl/bigcapital.ly/options-ssl-nginx.conf; + ssl_dhparam /etc/ssl/bigcapital.ly/ssl-dhparams.pem; location / { - proxy_pass http://node:${WEB_REVERSE_PROXY_PORT}; + proxy_pass http://127.0.0.1:${WEB_REVERSE_PROXY_PORT}; } } \ No newline at end of file