2 listen 0.0.0.0:443 ssl;
3 server_name api.<%=$systemDomain%>;
4 server_name secure.<%=$systemDomain%>;
5 ssl_certificate /etc/ssl/private/gigi.crt;
6 ssl_certificate_key /etc/ssl/private/gigi.key;
8 ssl_client_certificate /etc/ssl/root.crt;
13 proxy_pass http://<%=$gigi_ip%>;
14 proxy_set_header Host $host;
15 proxy_set_header X-Real-IP $remote_addr;
16 proxy_set_header X-Real-Proto https;
17 proxy_set_header X-Client-Cert $ssl_client_cert;
22 listen 0.0.0.0:443 ssl;
23 server_name *.<%=$systemDomain%>;
24 server_name <%=$systemDomain%>;
25 ssl_certificate /etc/ssl/private/gigi.crt;
26 ssl_certificate_key /etc/ssl/private/gigi.key;
29 proxy_pass http://<%=$gigi_ip%>;
30 proxy_set_header Host $host;
31 proxy_set_header X-Real-IP $remote_addr;
32 proxy_set_header X-Real-Proto https;
33 proxy_set_header X-Client-Cert $ssl_client_cert;
34 <% if($protected != 'no') { %>
35 auth_basic "closed site";
36 auth_basic_user_file /etc/nginx/access.txt;
39 location ~* /cacert-.* {
46 server_name *.<%=$systemDomain%>;
47 server_name <%=$systemDomain%>;
50 proxy_pass http://<%=$gigi_ip%>;
51 proxy_set_header Host $host;
52 proxy_set_header X-Real-IP $remote_addr;
53 proxy_set_header X-Real-Proto http;
54 proxy_set_header X-Client-Cert "";
55 <% if($protected != 'no') { %>
56 auth_basic "closed site";
57 auth_basic_user_file /etc/nginx/access.txt;
60 location ~* /cacert-.* {