zarev sur certain endroit sur Sur https://www.whatsmydns.net/ je suis pas ok mais d'autre oui !!
server {
listen 80;
server_name @DOMAIN@;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
server_name @DOMAIN@;
index index.php;
ssl on;
ssl_certificate /etc/nginx/ssl/server.crt;
ssl_certificate_key /etc/nginx/ssl/server.key;
add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload;";
include /etc/nginx/conf.d/ciphers.conf;
ssl_session_cache shared:SSL:10m; (limite la session ssl à 10mn, à activer ou non si vous le souhaitez.
#LOGS
access_log /var/log/nginx/nextcloud-access.log combined;
error_log /var/log/nginx/nextcloud-error.log error;
root doit pointer vers le chemin d'installation de Nextcloud. Typiquement /var/www/nextcloud.
root /var/www/nextcloud;
client_max_body_size 10G; # set max upload size
fastcgi_buffers 64 4K;
#rewrite url pour la synchronisation caldav/webdav.
rewrite /caldav(.)$ /remote.php/caldav$1 redirect;
rewrite /carddav(.)$ /remote.php/carddav$1 redirect;
rewrite /webdav(.*)$ /remote.php/webdav$1 redirect;
error_page 403 /core/templates/403.php;
error_page 404 /core/templates/404.php;
#eviter le référencement de votre cloud par google.
location = /robots.txt {
allow all;
log_not_found off;
access_log off;
}
#interdire l'accès aux sous dossiers de nextcloud.
location ~ /(data|config|.ht|db_structure.xml|README) {
deny all;
}
location / {
# The following 2 rules are only needed with webfinger
rewrite ^/.well-known/host-meta /public.php?service=host-meta last;
rewrite ^/.well-known/host-meta.json /public.php?service=host-meta-json last;
rewrite ^/.well-known/carddav /remote.php/carddav/ redirect;
rewrite ^/.well-known/caldav /remote.php/caldav/ redirect;
rewrite ^(/core/doc/[^\/]+/)$ $1/index.html;
try_files $uri $uri/ index.php;
}
#config php
location ~ (.+?.php)(/.*)?$ {
try_files $1 = 404;
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$1;
fastcgi_param PATH_INFO $2;
fastcgi_pass unix:/var/run/php5-fpm.sock;
}
Mise en cache des images
location ~* .+.(jpg|jpeg|gif|bmp|ico|png|css|js|swf)$ {
expires 30d;
Optional: Don’t log access to assets
access_log off;
}
}