http { # SSL CONFIGURATION # Key locations ssl_certificate /etc/letsencrypt/live/karaoke.roosens.me/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/karaoke.roosens.me/privkey.pem; # Allowed protocols ssl_protocols TLSv1.2; # Allowed cyphers # ssl_ciphers EECDH+CHACHA20:EECDH+AES; # Cache settings ssl_session_cache shared:SSL:10m; ssl_session_timeout 10m; # Still gotta figure out what these do # ssl_session_tickets off; # ssl_prefer_server_ciphers on; # ssl_ecdh_curve X25519:prime256v1:secp521r1:secp384r1; # LOAD SITES include conf.d/sites_enabled/*.conf; }