|  | 
 |  | 
 | 
												
													
														| 2548 |        echo 'WARNING: No freeDNS subdomain code given for Red Matrix. It is assumed that you are using some other dynamic DNS provider.'
 | 2548 |        echo 'WARNING: No freeDNS subdomain code given for Red Matrix. It is assumed that you are using some other dynamic DNS provider.'
 | 
												
													
														| 2549 |    fi
 | 2549 |    fi
 | 
												
													
														| 2550 |  
 | 2550 |  
 | 
												
													
														|  | 
 | 2551 | +  echo 'server {' > /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2552 | +  echo '    listen 80;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2553 | +  echo "    server_name $REDMATRIX_DOMAIN_NAME;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2554 | +  echo "    root /var/www/$REDMATRIX_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2555 | +  echo "    error_log /var/www/$REDMATRIX_DOMAIN_NAME/error.log;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2556 | +  echo '    index index.php;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2557 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2558 | +  echo '    rewrite ^ https://$server_name$request_uri? permanent;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2559 | +  echo '}' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2560 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2561 | +  echo 'server {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2562 | +  echo '    listen 443 ssl;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2563 | +  echo "    root /var/www/$REDMATRIX_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2564 | +  echo "    server_name $REDMATRIX_DOMAIN_NAME;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2565 | +  echo "    error_log /var/www/$REDMATRIX_DOMAIN_NAME/error_ssl.log;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2566 | +  echo '    index index.php;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2567 | +  echo '    charset utf-8;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2568 | +  echo '    client_max_body_size 20m;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2569 | +  echo '    client_body_buffer_size 128k;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2570 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2571 | +  echo '    ssl on;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2572 | +  echo "    ssl_certificate /etc/ssl/certs/$REDMATRIX_DOMAIN_NAME.crt;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2573 | +  echo "    ssl_certificate_key /etc/ssl/private/$REDMATRIX_DOMAIN_NAME.key;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2574 | +  echo "    ssl_dhparam /etc/ssl/certs/$REDMATRIX_DOMAIN_NAME.dhparam;" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2575 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2576 | +  echo '    ssl_session_timeout 5m;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2577 | +  echo '    ssl_prefer_server_ciphers on;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2578 | +  echo '    ssl_session_cache  builtin:1000  shared:SSL:10m;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2579 | +  echo '    ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2580 | +  echo "    ssl_ciphers 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA';" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2581 | +  echo '    add_header X-Frame-Options DENY;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2582 | +  echo '    add_header X-Content-Type-Options nosniff;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2583 | +  echo '    add_header Strict-Transport-Security max-age=15768000;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2584 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2585 | +  echo '    # rewrite to front controller as default rule' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2586 | +  echo '    location / {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2587 | +  echo '        rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2588 | +  echo '    }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2589 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2590 | +  echo "    # make sure webfinger and other well known services aren't blocked" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2591 | +  echo '    # by denying dot files and rewrite request to the front controller' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2592 | +  echo '    location ^~ /.well-known/ {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2593 | +  echo '        allow all;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2594 | +  echo '        rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2595 | +  echo '    }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2596 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2597 | +  echo '    # statically serve these file types when possible' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2598 | +  echo '    # otherwise fall back to front controller' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2599 | +  echo '    # allow browser to cache them' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2600 | +  echo '    # added .htm for advanced source code editor library' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2601 | +  echo '    location ~* \.(jpg|jpeg|gif|png|ico|css|js|htm|html|ttf|woff|svg)$ {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2602 | +  echo '        expires 30d;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2603 | +  echo '        try_files $uri /index.php?q=$uri&$args;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2604 | +  echo '    }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2605 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2606 | +  echo '    # block these file types' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2607 | +  echo '    location ~* \.(tpl|md|tgz|log|out)$ {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2608 | +  echo '        deny all;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2609 | +  echo '    }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2610 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2611 | +  echo '    # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2612 | +  echo '    # or a unix socket' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2613 | +  echo '    location ~* \.php$ {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2614 | +  echo '        # Zero-day exploit defense.' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2615 | +  echo '        # http://forum.nginx.org/read.php?2,88845,page=3' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2616 | +  echo "        # Won't work properly (404 error) if the file is not stored on this" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2617 | +  echo "        # server, which is entirely possible with php-fpm/php-fcgi." >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2618 | +  echo "        # Comment the 'try_files' line out if you set up php-fpm/php-fcgi on" >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2619 | +  echo "        # another machine. And then cross your fingers that you won't get hacked." >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2620 | +  echo '        try_files $uri $uri/ /index.php;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2621 | +  echo '        # NOTE: You should have "cgi.fix_pathinfo = 0;" in php.ini' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2622 | +  echo '        fastcgi_split_path_info ^(.+\.php)(/.+)$;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2623 | +  echo '        # With php5-cgi alone:' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2624 | +  echo '        # fastcgi_pass 127.0.0.1:9000;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2625 | +  echo '        # With php5-fpm:' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2626 | +  echo '        fastcgi_pass unix:/var/run/php5-fpm.sock;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2627 | +  echo '        include fastcgi_params;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2628 | +  echo '        fastcgi_index index.php;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2629 | +  echo '        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2630 | +  echo '    }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2631 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2632 | +  echo '    # deny access to all dot files' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2633 | +  echo '    location ~ /\. {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2634 | +  echo '        deny all;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2635 | +  echo '    }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2636 | +  echo '' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2637 | +  echo '    location ~ /\.ht {' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2638 | +  echo '      deny  all;' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2639 | +  echo '    }' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2640 | +  echo '}' >> /etc/nginx/sites-available/$REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2641 | +
 | 
												
													
														|  | 
 | 2642 | +  configure_php
 | 
												
													
														|  | 
 | 2643 | +
 | 
												
													
														|  | 
 | 2644 | +  if [ ! -f /etc/ssl/private/$REDMATRIX_DOMAIN_NAME.key ]; then
 | 
												
													
														|  | 
 | 2645 | +      makecert $REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2646 | +  fi
 | 
												
													
														|  | 
 | 2647 | +
 | 
												
													
														|  | 
 | 2648 | +  nginx_ensite $REDMATRIX_DOMAIN_NAME
 | 
												
													
														|  | 
 | 2649 | +  service php5-fpm restart
 | 
												
													
														|  | 
 | 2650 | +  service nginx restart
 | 
												
													
														| 2551 |    service cron restart
 | 2651 |    service cron restart
 | 
												
													
														| 2552 |  
 | 2652 |  
 | 
												
													
														| 2553 |    echo 'install_redmatrix' >> $COMPLETION_FILE
 | 2653 |    echo 'install_redmatrix' >> $COMPLETION_FILE
 |