|
|
|
|
2548
|
echo 'WARNING: No freeDNS subdomain code given for Red Matrix. It is assumed that you are using some other dynamic DNS provider.'
|
2548
|
echo 'WARNING: No freeDNS subdomain code given for Red Matrix. It is assumed that you are using some other dynamic DNS provider.'
|
2549
|
fi
|
2549
|
fi
|
2550
|
|
2550
|
|
|
|
2551
|
+ echo 'server {' > /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2552
|
+ echo ' listen 80;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2553
|
+ echo " server_name $REDMATRIX_DOMAIN_NAME;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2554
|
+ echo " root /var/www/$REDMATRIX_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2555
|
+ echo " error_log /var/www/$REDMATRIX_DOMAIN_NAME/error.log;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2556
|
+ echo ' index index.php;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2557
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2558
|
+ echo ' rewrite ^ https://$server_name$request_uri? permanent;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2559
|
+ echo '}' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2560
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2561
|
+ echo 'server {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2562
|
+ echo ' listen 443 ssl;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2563
|
+ echo " root /var/www/$REDMATRIX_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2564
|
+ echo " server_name $REDMATRIX_DOMAIN_NAME;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2565
|
+ echo " error_log /var/www/$REDMATRIX_DOMAIN_NAME/error_ssl.log;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2566
|
+ echo ' index index.php;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2567
|
+ echo ' charset utf-8;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2568
|
+ echo ' client_max_body_size 20m;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2569
|
+ echo ' client_body_buffer_size 128k;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2570
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2571
|
+ echo ' ssl on;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2572
|
+ echo " ssl_certificate /etc/ssl/certs/$REDMATRIX_DOMAIN_NAME.crt;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2573
|
+ echo " ssl_certificate_key /etc/ssl/private/$REDMATRIX_DOMAIN_NAME.key;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2574
|
+ echo " ssl_dhparam /etc/ssl/certs/$REDMATRIX_DOMAIN_NAME.dhparam;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2575
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2576
|
+ echo ' ssl_session_timeout 5m;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2577
|
+ echo ' ssl_prefer_server_ciphers on;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2578
|
+ echo ' ssl_session_cache builtin:1000 shared:SSL:10m;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2579
|
+ echo ' ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2580
|
+ echo " ssl_ciphers 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA';" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2581
|
+ echo ' add_header X-Frame-Options DENY;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2582
|
+ echo ' add_header X-Content-Type-Options nosniff;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2583
|
+ echo ' add_header Strict-Transport-Security max-age=15768000;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2584
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2585
|
+ echo ' # rewrite to front controller as default rule' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2586
|
+ echo ' location / {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2587
|
+ echo ' rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2588
|
+ echo ' }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2589
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2590
|
+ echo " # make sure webfinger and other well known services aren't blocked" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2591
|
+ echo ' # by denying dot files and rewrite request to the front controller' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2592
|
+ echo ' location ^~ /.well-known/ {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2593
|
+ echo ' allow all;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2594
|
+ echo ' rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2595
|
+ echo ' }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2596
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2597
|
+ echo ' # statically serve these file types when possible' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2598
|
+ echo ' # otherwise fall back to front controller' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2599
|
+ echo ' # allow browser to cache them' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2600
|
+ echo ' # added .htm for advanced source code editor library' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2601
|
+ echo ' location ~* \.(jpg|jpeg|gif|png|ico|css|js|htm|html|ttf|woff|svg)$ {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2602
|
+ echo ' expires 30d;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2603
|
+ echo ' try_files $uri /index.php?q=$uri&$args;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2604
|
+ echo ' }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2605
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2606
|
+ echo ' # block these file types' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2607
|
+ echo ' location ~* \.(tpl|md|tgz|log|out)$ {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2608
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2609
|
+ echo ' }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2610
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2611
|
+ echo ' # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2612
|
+ echo ' # or a unix socket' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2613
|
+ echo ' location ~* \.php$ {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2614
|
+ echo ' # Zero-day exploit defense.' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2615
|
+ echo ' # http://forum.nginx.org/read.php?2,88845,page=3' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2616
|
+ echo " # Won't work properly (404 error) if the file is not stored on this" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2617
|
+ echo " # server, which is entirely possible with php-fpm/php-fcgi." >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2618
|
+ echo " # Comment the 'try_files' line out if you set up php-fpm/php-fcgi on" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2619
|
+ echo " # another machine. And then cross your fingers that you won't get hacked." >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2620
|
+ echo ' try_files $uri $uri/ /index.php;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2621
|
+ echo ' # NOTE: You should have "cgi.fix_pathinfo = 0;" in php.ini' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2622
|
+ echo ' fastcgi_split_path_info ^(.+\.php)(/.+)$;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2623
|
+ echo ' # With php5-cgi alone:' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2624
|
+ echo ' # fastcgi_pass 127.0.0.1:9000;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2625
|
+ echo ' # With php5-fpm:' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2626
|
+ echo ' fastcgi_pass unix:/var/run/php5-fpm.sock;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2627
|
+ echo ' include fastcgi_params;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2628
|
+ echo ' fastcgi_index index.php;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2629
|
+ echo ' fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2630
|
+ echo ' }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2631
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2632
|
+ echo ' # deny access to all dot files' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2633
|
+ echo ' location ~ /\. {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2634
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2635
|
+ echo ' }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2636
|
+ echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2637
|
+ echo ' location ~ /\.ht {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2638
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2639
|
+ echo ' }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2640
|
+ echo '}' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
|
|
|
2641
|
+
|
|
|
2642
|
+ configure_php
|
|
|
2643
|
+
|
|
|
2644
|
+ if [ ! -f /etc/ssl/private/$REDMATRIX_DOMAIN_NAME.key ]; then
|
|
|
2645
|
+ makecert $REDMATRIX_DOMAIN_NAME
|
|
|
2646
|
+ fi
|
|
|
2647
|
+
|
|
|
2648
|
+ nginx_ensite $REDMATRIX_DOMAIN_NAME
|
|
|
2649
|
+ service php5-fpm restart
|
|
|
2650
|
+ service nginx restart
|
2551
|
service cron restart
|
2651
|
service cron restart
|
2552
|
|
2652
|
|
2553
|
echo 'install_redmatrix' >> $COMPLETION_FILE
|
2653
|
echo 'install_redmatrix' >> $COMPLETION_FILE
|