==== fiat.conf ==== server { listen 80; server_name fiat.website; return 301 https://fiat.website$request_uri; # enforce https } server { listen 443 ssl; server_name fiat.website; root /usr/local/www/html/doku; index index.php; charset utf-8; ## SSL settings ssl_certificate /usr/local/etc/letsencrypt/live/fiat.website/cert.pem; ssl_certificate_key /usr/local/etc/letsencrypt/live/fiat.website/privkey.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_ciphers "ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!3DES:!MD5:!PSK"; ssl_prefer_server_ciphers on; ssl_session_cache shared:SSL:10m; ssl_session_timeout 10m; ssl_ecdh_curve secp384r1; add_header Strict-Transport-Security max-age=31536000; access_log /var/log/nginx/fiat.access.log; error_log /var/log/nginx/fiat.error.log; location / { proxy_pass http://192.168.50.4:8080/; } location /poweradmin/ { proxy_pass http://192.168.50.4:8080/poweradmin/; } location /nextcloud/ { proxy_pass http://192.168.50.4:8080/nextcloud/; } location /betamail/ { proxy_pass https://betamail.unizar.es/; } location /betamail-a/ { proxy_pass https://betamail-unizar-00.alnuvol.com/; } location /betamail-o/ { proxy_pass https://130.61.39.175/; } }