2018-04-26 14:02:02 +08:00
回复了 Quaintjade 创建的主题 SSL Comodo PositiveSSL 已经支持 ECC 证书了
ecc 证书作为 ocserv 的 server cert,服务器测试 ip 是正常,但是 iOS 版 Anyconnect 连接不上去
2018-04-26 14:01:13 +08:00
回复了 Quaintjade 创建的主题 SSL Comodo PositiveSSL 已经支持 ECC 证书了
@Quaintjade 好像到现在为止,anyconnect 还不支持 ecc 证书登陆
2018-04-26 13:09:41 +08:00
回复了 halczy 创建的主题 分享创造 尝试优化了一下 AnyConnect(ocserv)的配置, 欢迎大家测试.
厉害,不过确实 anyconnenct 部署要比其他的复杂多了,学习一下
2018-04-26 10:30:53 +08:00
回复了 moack 创建的主题 分享发现 cloudflare 公共 dns
@elvisyao 其实就 119 这个不错,另外 114 其实也可以,其他阿里百度都不行
2018-04-26 10:24:16 +08:00
回复了 chenhui7373 创建的主题 分享发现 号外号外以后,装 Linux 系统的 PC 机将大量上架
神舟一直是这样呀,也挺好的。装个 msdn 原版最好
2018-04-25 13:20:50 +08:00
回复了 whx20202 创建的主题 NGINX 这个 proxy_redirect 是做什么的?
@Tink 这么弱,害得我测试了很久。
2018-04-23 17:01:26 +08:00
回复了 liuyinltemp 创建的主题 NGINX nginx 反向代理可以实现升级 https 功能吗
@my101du 谢谢,确实不复杂,小白不懂。
@Love4Taylor 图床不是固定的,看用户用那个?怎么处理。我想将<img src=对应的图片缓存下来变成现在网站的相对地址,然后替换,不知道可不可行?
关闭 gzip,问题怎么写代码?谢谢!小白,虽然学过计算机,现已转行。
图床<img src="http://***.jpg" ,这个图床的地址不是固定的,看发帖人选择,有通用的吗?
user www-data;
worker_processes auto;
pid /run/nginx.pid;
include /etc/nginx/modules-enabled/*.conf;

events {
worker_connections 128;
multi_accept on;
use epoll;

http {

# Basic Settings

sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 60;
types_hash_max_size 2048;
# server_tokens off;

# server_names_hash_bucket_size 64;
# server_name_in_redirect off;

include /etc/nginx/mime.types;
default_type application/octet-stream;

# Logging Settings

access_log /var/log/nginx/access.log;
error_log /var/log/nginx/error.log;

proxy_connect_timeout 600;
proxy_read_timeout 600;
proxy_send_timeout 600;
proxy_buffer_size 64k;
proxy_buffers 4 64k;
proxy_busy_buffers_size 128k;
proxy_temp_file_write_size 128k;
proxy_temp_path /etc/nginx/cache/temp;
proxy_cache_path /etc/nginx/cache/path levels=1:2 keys_zone=cache_one:32m inactive=1d max_size=1g;

# Gzip Settings

gzip on;
gzip_disable "msie6";

gzip_vary on;
gzip_proxied any;
gzip_comp_level 5;
gzip_buffers 16 8k;
gzip_http_version 1.1;
gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript;

# nginx-naxsi config
# Uncomment it if you installed nginx-naxsi

#include /etc/nginx/naxsi_core.rules;

# Virtual Host Configs

include /etc/nginx/conf.d/*.conf;
include /etc/nginx/sites-enabled/*;

server {
listen 80;
server_name bbb.com;
return 301 https://$host$request_uri;

server {
listen 443 ssl;
server_name bbb.com;
ssl on;
ssl_certificate cert/shss.crt;
ssl_certificate_key cert/shss.key;
ssl_session_timeout 8m;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_prefer_server_ciphers on;

location / {
sub_filter aaa.com bbb.com;
proxy_pass http://aaa.com;
proxy_http_version 1.1;
proxy_redirect off;
proxy_cache_key "$scheme://$host$request_uri";
proxy_cache cache_one;
proxy_cache_valid 200 304 10m;
proxy_cache_valid 301 1h;
proxy_cache_valid any 10s;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Referer http://aaa.com;
proxy_set_header Host $proxy_host;
proxy_set_header Accept-Encoding "";


2018-04-19 18:49:30 +08:00
回复了 liuyinltemp 创建的主题 NGINX nginx 反向代理能否增加实现图片自适应屏幕功能?
2018-04-16 09:41:24 +08:00
回复了 UnPace 创建的主题 iPhone 现在买 iPhone 的最佳姿势是?
Godaddy 注册商域名如何使用 cloudflare.com 开启 DNSsec,Godaddy 选项不知道啥意思
2018-03-01 15:18:00 +08:00
回复了 liuyinltemp 创建的主题 NGINX nginx 反向代理可以实现升级 https 功能吗
user www-data;
worker_processes auto;
pid /run/nginx.pid;
include /etc/nginx/modules-enabled/*.conf;

events {
use epoll;
worker_connections 2048;
# multi_accept on;

http {

# Basic Settings

sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 60;
types_hash_max_size 2048;
# server_tokens off;

# server_names_hash_bucket_size 64;
# server_name_in_redirect off;

include /etc/nginx/mime.types;
default_type application/octet-stream;

# SSL Settings

ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # Dropping SSLv3, ref: POODLE
ssl_prefer_server_ciphers on;

# Logging Settings

access_log /var/log/nginx/access.log;
error_log /var/log/nginx/error.log;

proxy_connect_timeout 5;
proxy_read_timeout 60;
proxy_send_timeout 5;
proxy_buffer_size 16k;
proxy_buffers 4 64k;
proxy_busy_buffers_size 128k;
proxy_temp_file_write_size 128k;
proxy_temp_path /home/cache/temp;
proxy_cache_path /home/cache/path levels=1:2 keys_zone=cache_one:32m inactive=1h max_size=128m;

# Gzip Settings

gzip on;
gzip_disable "msie6";

# gzip_vary on;
# gzip_proxied any;
# gzip_comp_level 6;
# gzip_buffers 16 8k;
# gzip_http_version 1.1;
# gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript;

# nginx-naxsi config
# Uncomment it if you installed nginx-naxsi

#include /etc/nginx/naxsi_core.rules;

# Virtual Host Configs

include /etc/nginx/conf.d/*.conf;
include /etc/nginx/sites-enabled/*;

server {
listen 80;
server_name bbb.com;
large_client_header_buffers 4 16k;
client_max_body_size 300m;
client_body_buffer_size 128k;
proxy_connect_timeout 600;
proxy_read_timeout 600;
proxy_send_timeout 600;
proxy_buffer_size 64k;
proxy_buffers 4 32k;
proxy_busy_buffers_size 64k;
proxy_temp_file_write_size 64k;
access_log off;
if ($http_user_agent ~* (baiduspider|360spider|haosouspider|googlebot|soso|bing|sogou|yahoo|sohu-search|yodao|YoudaoBot|robozilla|msnbot|MJ12bot|NHN|Twiceler)) {
return 403;

location / {
sub_filter aaa.com bbb.com;
sub_filter 'include/javascript/common.js' '';
sub_filter '<div id="menu2">' '<div id="menu2" style="display:none;">';
sub_filter '<div id="header">' '<div id="header" style="display:none;">';
sub_filter '<div id="announcement"' '<id="announcement" style="display:none;"';
sub_filter '<div id="footercontainer">' '<div id="footercontainer" style="display:none;">';
sub_filter 'id="forumlinks" cellpadding="0" cellspacing="0" style="">' 'id="forumlinks" style="display:none;">';
sub_filter '<div class="maintable" style="color: #333; clear: both;">' '<div class="maintable" style="display:none;">';
sub_filter '<div class="legend">' '<div class="legend" style="display:none;">';
sub_filter_once off;
subs_filter '<div id="menu">' '<div id="menu" style="display:none;">' o;
proxy_pass http://aaa.com;
proxy_cache_key "$scheme://$host$request_uri";
proxy_cache cache_one;
proxy_cache_valid 200 304 10m;
proxy_cache_valid 301 1h;
proxy_cache_valid any 1m;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Referer http://aaa.com;
proxy_set_header Host $host;
proxy_set_header Accept-Encoding "";


#mail {
# # See sample authentication script at:
# # http://wiki.nginx.org/ImapAuthenticateWithApachePhpScript
# # auth_http localhost/auth.php;
# # pop3_capabilities "TOP" "USER";
# # imap_capabilities "IMAP4rev1" "UIDPLUS";
# server {
# listen localhost:110;
# protocol pop3;
# proxy on;
# }
# server {
# listen localhost:143;
# protocol imap;
# proxy on;
# }
2018-03-01 15:12:53 +08:00
回复了 liuyinltemp 创建的主题 NGINX nginx 反向代理可以实现升级 https 功能吗
请问怎么操作,最好是强制打开 https,谢谢
2018-02-09 10:17:45 +08:00
回复了 237176253 创建的主题 宽带症候群 四川移动的宽带和电视怎么样
四川建议用电信,四川是电信强势省份,itv 搞得还是不错的。
