server {
listen [::]:80;
listen 80;
server_name api.example.com;
return 301 https://$host$request_uri;
}
server {
listen [::]:443 ssl;
listen 443 ssl;
http2 on;
server_name api.example.com;
ssl_certificate путь_к_серту_для_api.example.com;
ssl_certificate_key путь_к_ключу_для_api.example.com;
location / {
proxy_pass 127.0.0.1:порт_вашего_приложения;
........
........
}
}
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030) ECDH secp256r1 (eq. 3072 bits RSA) FS 256
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f) ECDH secp256r1 (eq. 3072 bits RSA) FS 128
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xcca8) ECDH secp256r1 (eq. 3072 bits RSA) FS 256