Compare commits

..

1 Commits

Author SHA1 Message Date
54fbb9f613 ssl 2023-09-18 16:10:18 -07:00
11 changed files with 149 additions and 88 deletions

3
.gitignore vendored
View File

@ -1 +1,2 @@
nginx-1.20.1
conf/includes/localhost.crt
conf/includes/localhost.key

View File

@ -1,11 +1,11 @@
location /
{
proxy_pass http://localhost:5555;
location / {
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection keep-alive;
proxy_set_header Host $http_host;
proxy_cache_bypass $http_upgrade;
proxy_pass http://localhost:5555;
proxy_set_header Host $http_host;
proxy_set_header Connection keep-alive;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header X-Forwarded-Proto https;
}
# sc create "Baget-5555" start= delayed-auto DisplayName="Baget-5555" binPath= "C:\Users\phares\AppData\Local\IFXApps\BaGet\src\BaGet\bin\Release\net6.0\win-x64\publish\BaGet.exe" obj= "infineon\phares" password= ""

8
conf/includes/Gogs.conf Normal file
View File

@ -0,0 +1,8 @@
location / {
proxy_hide_header Authorization;
if ($http_Authorization != "Basic asdf") {
return 401;
}
proxy_set_header Authorization "Basic asdf";
proxy_pass http://localhost:3000;
}

View File

@ -0,0 +1,25 @@
server {
server_name phares3757.ddns.net;
location / {
proxy_pass http://localhost:8007/;
proxy_set_header Host $host;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection upgrade;
proxy_set_header Accept-Encoding gzip;
}
listen [::]:443 ssl ipv6only=on; # managed by Certbot
listen 443 ssl; # managed by Certbot
ssl_certificate /etc/letsencrypt/live/phares3757.ddns.net/fullchain.pem; # managed by Certbot
ssl_certificate_key /etc/letsencrypt/live/phares3757.ddns.net/privkey.pem; # managed by Certbot
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
}
server {
if ($host = phares3757.ddns.net) {
return 301 https://$host$request_uri;
} # managed by Certbot
listen 80;
listen [::]:80;
server_name phares3757.ddns.net;
return 404; # managed by Certbot
}

View File

@ -0,0 +1,8 @@
server {
listen 8008 default_server;
listen [::]:8008 default_server;
## Trun on /cgi-bin/ support to run CGI apps ##
include /etc/nginx/fcgiwrap.conf;
root /var/www/html;
server_name _;
}

View File

@ -1,23 +0,0 @@
-----BEGIN CERTIFICATE-----
MIIDvTCCAqWgAwIBAgIUCy4C1wKPnhGgZoOX5Cmu1FT5jKMwDQYJKoZIhvcNAQEL
BQAwbjELMAkGA1UEBhMCVVMxEDAOBgNVBAgMB0FyaXpvbmExDzANBgNVBAcMBkFu
dGhlbTEPMA0GA1UECgwGUGhhcmVzMRQwEgYDVQQLDAtEZXZlbG9wbWVudDEVMBMG
A1UEAwwMbWlrZS5kZXNrdG9wMB4XDTI0MDEwMjAwMDM0OVoXDTI1MDEwMTAwMDM0
OVowbjELMAkGA1UEBhMCVVMxEDAOBgNVBAgMB0FyaXpvbmExDzANBgNVBAcMBkFu
dGhlbTEPMA0GA1UECgwGUGhhcmVzMRQwEgYDVQQLDAtEZXZlbG9wbWVudDEVMBMG
A1UEAwwMbWlrZS5kZXNrdG9wMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
AQEAkEP08Go4NBmHmKi9jS3JPPY3iA3apX0PXV37YmN1IMLW6BEX/X90o4FSadQK
iyuA0BMXQM/oiM0TfIOtR6ung1aSg/dTgAp6B2SfB6/J08ELb7Mt1tZ9r0L6289X
66pWIWBKCCN4jGP69KnF/k95wHoHE99YMgaMGtAQo8r+pSeJRNeIZQ8pS96Cg3k5
aynBIxkQAEIGI5DufrpZsRzJJK367KCpz/pyb0jC37iLaCCTVPDfKag9ZvgaZjzw
fTX6T17EVfvfLeal/7L7FlC4gRaw5qWAJB+h1DYPHuy4A0lCUhG3aR06RABQADeE
7oxWMEwQJeX9YgzGTIFkOC9nLwIDAQABo1MwUTAwBgNVHREEKTAngg9kZXNrdG9w
LWJtdjR2NjaCCWxvY2FsaG9zdIIJMTI3LjAuMC4xMB0GA1UdDgQWBBRYO/dy7DEp
xS5YJ/0zkF3MmZra8TANBgkqhkiG9w0BAQsFAAOCAQEAgNLGYSES1aQWaE6nKfol
ZY7vhTTHK3GI1RrnvzKsOpZiTHjz+mlYH4csrPTBYn++6kX4xDElqxyaWdVLOt/7
16KjoXTCJGUBK8kIkpmhGWk0AAPddW2tXCEq9BDHXuqsOUrsQVXJaXeKoJFsRD7F
apQAFHvurM+P6L9XdoOHJvlx0cWcAQscWw3tRBfmmBfaNceBoWdK5Aq9jAD48p94
tz8P+ALZSdtVAInfZ75KdmY77E4rXNmdasUfv4dO2mzyWUZPNVK1ZFo6jarFN4Tp
VcjYG8idl/Mq/nMFSAp2fNCah1LorfOBzVsGAA7o3SLHbwJ7u9Guq+kYY2CFvwWf
mA==
-----END CERTIFICATE-----

View File

@ -1,28 +0,0 @@
-----BEGIN PRIVATE KEY-----
MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCQQ/Twajg0GYeY
qL2NLck89jeIDdqlfQ9dXftiY3UgwtboERf9f3SjgVJp1AqLK4DQExdAz+iIzRN8
g61Hq6eDVpKD91OACnoHZJ8Hr8nTwQtvsy3W1n2vQvrbz1frqlYhYEoII3iMY/r0
qcX+T3nAegcT31gyBowa0BCjyv6lJ4lE14hlDylL3oKDeTlrKcEjGRAAQgYjkO5+
ulmxHMkkrfrsoKnP+nJvSMLfuItoIJNU8N8pqD1m+BpmPPB9NfpPXsRV+98t5qX/
svsWULiBFrDmpYAkH6HUNg8e7LgDSUJSEbdpHTpEAFAAN4TujFYwTBAl5f1iDMZM
gWQ4L2cvAgMBAAECggEADLxLD7w4yPSmAUaIMUHk/YI45cRfVHOlWxc0XXutN96r
bSIxLXpGeDau6VPEOIP3I6dDyr9v5j/AZCIVtnmDWLdYSNkZIHkMS8HIvjt5BD4K
/enh9pDJ2KJ/lc8Ikm/fmaOv9Wb4OeCLo3SnW2t1spWzMUBqv0PPs4BBr8v4Tej9
IQoiNHMnUv724kHvSGH1yQ7Pdv2oX1eWjZEYjpyZrwN6pne4uizpB5tqYGiu95iE
QryRVtBCjmk6iHz3xwXGgTn9Ek8dwg2H1o1wKEv4u5/4Hxq4iI4IMEg+u3rlaVz6
3uBRDBFRZhpXoYKbzo7BNj0kCHwijc2UFDQHp2ovOQKBgQDI1720vsFoC4cqH9Dj
a0WaJtfgukn/hG6pgt2WmHlx791DgYGojMXWPPnnKGFfZVQExopOsojVybyz1uTZ
Dcn2hQabWo6JLnDh36dvaNBAxuyzmfmSXROD0uWeX9qJBPrjY8ao7AvSe7w0cWjY
DhgkFlifD3akRc5+EmhFnkCKeQKBgQC34owLJ96oIjef10PS1TPnIkgyciVGq+ES
6OUvm0wMHImrDabW4IDGYwGI3lfMAFgOiLM+Y7cd3czZHB7uyxpDr2tfdggR9VB4
KzpOmrZtb2Wrew0SBurPNOk1ONwHM9ReAgq4+7xFzYsHGXMWwZZ59hgRSLGhdZ6Y
JkUb4ekU5wKBgQCE+YpJ5E5rU86fDkegewKvSG6ABPc/bPBT3ShXMAagcD6gFlvB
O8s0yFRxPuQRZCZXrxgdeMluOs5sh6gnKaEBThwMuc1LeGsWsZzK/6t6Z/qKAzUh
OezUx8ptrGslcx2ldgcvCnHdXz1Bv6C6A8LqCb2NOpDDvNA12nwdM+TpiQKBgGkO
6xoYjlKbMhKFh392RfAhGwSPSJLG8pG+M+ruHBWzXEg5RX/wxkISILdU6O5pp+Wt
3lKf3+gVZ8sHEPk3Wuse1wa0RcoU0QPHFsoABIgjo//EDuSkxRTbUv4QXU1UJFoN
apjjYl6zH2JP/PwcYF+P5ZJCaRIpRBIDk2ppuKQzAoGBAKmlwZesnk6R4ZBSQkJ9
I+2515sv4iyllPkkw43U8IHUZD8iENCtmYpMqqIGf8RYnkxOUR3N56Zx/XEW4foG
5bz20mQUq8v4q9iqtNMGzJgMxC9VK3E4nGYdvkRa+Pizu8Lot54ZrzgaishnXFCE
pdwvuc9GTJ/bvyCK7jfLu64F
-----END PRIVATE KEY-----

29
conf/includes/dex.conf Normal file
View File

@ -0,0 +1,29 @@
location ~* .(3gp|apng|avi|avif|bmp|css|cur|flv|gif|htm|html|ico|jfif|jpeg|jpg|js|mid|mov|mp3|mp4|mpeg|mpg|ogg|pdf|php|pjp|pjpeg|png|svg|tif|tiff|txt|wav|webp|wmf|wml|wmv|xml|xml)$ {
expires 1d;
index index.html index.htm;
# ln -s /etc/nginx/sites-available/json /etc/nginx/sites-enabled/
# ln -s /srv/samba/share/637998119172547651 /var/www/html/637998119172547651
# ln -s /var/www/html/NGINdeX.io /var/www/html/637998119172547651/NGINdeX.io
# ln -s /srv/git /var/www/html/637998119172547651/git
# root /var/www/html/637998119172547651;
# mklink /J "D:\Tmp\Phares\www\pictures" "D:\Documents\Pictures"
# mklink /J "D:\Tmp\Phares\www\NGINdeX.io" "L:\GitHub\NGINdeX.io"
root "D://Tmp//phares//www";
}
location / {
index index.html index.htm;
# root /var/www/html/637998119172547651;
# mklink /J "D:\Tmp\Phares\www\pictures" "D:\Documents\Pictures"
# mklink /J "D:\Tmp\Phares\www\NGINdeX.io" "L:\GitHub\NGINdeX.io"
root "D://Tmp//phares//www";
# First attempt to serve request as file, then
autoindex on;
# Send the data in JSON
autoindex_format json;
addition_types application/json;
# Calling from SERVERNAME/autoindex/*
add_before_body /NGINdeX.io/header.html;
add_after_body /NGINdeX.io/footer.html;
# Need to tell that we are sending HTML
add_header Content-Type text/html;
}

View File

@ -1,24 +1,29 @@
# location ~ /admin(.*)/$ {
location ~* .(3gp|apng|avi|avif|bmp|css|cur|flv|gif|htm|html|ico|jfif|jpeg|jpg|js|mid|mov|mp3|mp4|mpeg|mpg|ogg|pdf|php|pjp|pjpeg|png|svg|tif|tiff|txt|wav|webp|wmf|wml|wmv|xml|xml)$ {
expires 1d;
index index.html index.htm;
# ln -s /etc/nginx/sites-available/json /etc/nginx/sites-enabled/
# ln -s /srv/samba/share/637998119172547651 /var/www/html/637998119172547651
# ln -s /var/www/html/NGINdeX.io /var/www/html/637998119172547651/NGINdeX.io
# ln -s /srv/git /var/www/html/637998119172547651/git
# root /var/www/html/637998119172547651;
# mklink /J "D:\Tmp\Phares\www\pictures" "D:\Documents\Pictures"
# mklink /J "D:\Tmp\Phares\www\NGINdeX.io" "L:\GitHub\NGINdeX.io"
root "D://Tmp//phares//www";
}
location / {
index index.html index.htm;
# root /var/www/html/637998119172547651;
# mklink /J "D:\Tmp\Phares\www\pictures" "D:\Documents\Pictures"
# mklink /J "D:\Tmp\Phares\www\NGINdeX.io" "L:\GitHub\NGINdeX.io"
root "D://Tmp//phares//www";
root "C://4p_W7a";
# First attempt to serve request as file, then
autoindex on;
# Send the data in JSON
autoindex_format json;
addition_types application/json;
# addition_types application/json;
# Calling from SERVERNAME/autoindex/*
add_before_body /NGINdeX.io/header.html;
add_after_body /NGINdeX.io/footer.html;
# add_before_body /NGINdeX.io/header.html;
# add_after_body /NGINdeX.io/footer.html;
# Need to tell that we are sending HTML
add_header Content-Type text/html;
# add_header Content-Type text/html;
}

View File

@ -1,6 +1,6 @@
[req]
default_bits = 2048
default_keyfile = desktop-bmv4v66.key
default_keyfile = localhost.key
distinguished_name = req_distinguished_name
req_extensions = req_ext
x509_extensions = v3_ca
@ -11,13 +11,13 @@ countryName_default = US
stateOrProvinceName = State or Province Name (full name)
stateOrProvinceName_default = Arizona
localityName = Locality Name (eg, city)
localityName_default = Anthem
localityName_default = Mesa
organizationName = Organization Name (eg, company)
organizationName_default = Phares
organizationName_default = Infineon Technologies Americas Corp.
organizationalUnitName = organizationalunit
organizationalUnitName_default = Development
commonName = Common Name (e.g. server FQDN or YOUR name)
commonName_default = mike.desktop
commonName_default = example.com
commonName_max = 64
[req_ext]
@ -27,11 +27,11 @@ subjectAltName = @alt_names
subjectAltName = @alt_names
[alt_names]
DNS.1 = mike.desktop
DNS.1 = desktop-bmv4v66
DNS.1 = example.com
DNS.2 = localhost
DNS.3 = 127.0.0.1
# https://webscoot.io/blog/create-self-signed-certificate-ubuntu-windows-nginx/
# cd "C:\Program Files\Git\usr\bin"
# openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout L:\Git\NGINX-Conf\conf\includes\desktop-bmv4v66.key -out L:\Git\NGINX-Conf\conf\includes\desktop-bmv4v66.crt -config L:\Git\NGINX-Conf\conf\includes\desktop-bmv4v66.conf
# openssl
# req -x509 -nodes -days 365 -newkey rsa:2048 -keyout L:\Git\NGINX-Conf\conf\includes\localhost.key -out L:\Git\NGINX-Conf\conf\includes\localhost.crt -config L:\Git\NGINX-Conf\conf\includes\localhost.conf

View File

@ -3,20 +3,56 @@ events {
worker_connections 1024;
}
http {
include "includes/mime.types";
default_type application/octet-stream;
sendfile on;
keepalive_timeout 65;
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name localhost;
ssl_certificate "includes/desktop-bmv4v66.crt";
ssl_certificate_key "includes/desktop-bmv4v66.key";
ssl_protocols TLSv1.2 TLSv1.1 TLSv1;
# include "includes/html.conf";
location / { proxy_pass http://localhost:8384; }
error_page 500 502 503 504 /50x.html;
include "includes/html-error.conf";
}
include "includes/mime.types";
default_type application/octet-stream;
sendfile on;
keepalive_timeout 65;
server {
listen 5051;
server_name localhost;
include "includes/www.conf";
}
server {
listen 5052;
server_name localhost;
include "includes/dex.conf";
}
server {
listen 5053;
server_name localhost;
include "includes/ProgramData.conf";
}
server {
listen 80;
server_name localhost;
include "includes/json.conf";
}
server {
listen 8011;
server_name localhost;
include "includes/Gogs.conf";
}
server {
listen 8080;
server_name ~(oi-metrology-viewer-archive).mes.infineon.com;
location / {
include "includes/Archive.conf";
}
}
server {
listen 8080;
server_name ~(oi-metrology-viewer-prod).mes.infineon.com;
location / {
include "includes/Viewer.conf";
}
}
server {
listen 8088;
server_name *.mes.infineon.com;
include "includes/EAF-Viewer.Server.conf";
}
}
# mklink /J "C:\Users\mikep\AppData\Local\PharesApps\nginx-1.20.1\conf" "L:\Git\NGINX-Conf\conf"
# cd "C:\Users\ECMESEAF\AppData\Local\IFXApps\nginx-1.20.1"
# .\nginx -t
# .\nginx -s reload