You've already forked nginx-proxy-manager
							
							
				mirror of
				https://github.com/NginxProxyManager/nginx-proxy-manager.git
				synced 2025-11-02 16:53:15 +03:00 
			
		
		
		
	Add SSL certificate to TCP streams if certificate in database
This commit is contained in:
		@@ -2,6 +2,7 @@
 | 
			
		||||
{% if certificate.provider == "letsencrypt" %}
 | 
			
		||||
  # Let's Encrypt SSL
 | 
			
		||||
  include conf.d/include/letsencrypt-acme-challenge.conf;
 | 
			
		||||
  include conf.d/include/ssl-cache.conf;
 | 
			
		||||
  include conf.d/include/ssl-ciphers.conf;
 | 
			
		||||
  ssl_certificate /etc/letsencrypt/live/npm-{{ certificate_id }}/fullchain.pem;
 | 
			
		||||
  ssl_certificate_key /etc/letsencrypt/live/npm-{{ certificate_id }}/privkey.pem;
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										13
									
								
								backend/templates/_certificates_stream.conf
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										13
									
								
								backend/templates/_certificates_stream.conf
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,13 @@
 | 
			
		||||
{% if certificate and certificate_id > 0 -%}
 | 
			
		||||
{% if certificate.provider == "letsencrypt" %}
 | 
			
		||||
  # Let's Encrypt SSL
 | 
			
		||||
  include conf.d/include/ssl-cache-stream.conf;
 | 
			
		||||
  include conf.d/include/ssl-ciphers.conf;
 | 
			
		||||
  ssl_certificate /etc/letsencrypt/live/npm-{{ certificate_id }}/fullchain.pem;
 | 
			
		||||
  ssl_certificate_key /etc/letsencrypt/live/npm-{{ certificate_id }}/privkey.pem;
 | 
			
		||||
{% else %}
 | 
			
		||||
  # Custom SSL
 | 
			
		||||
  ssl_certificate /data/custom_ssl/npm-{{ certificate_id }}/fullchain.pem;
 | 
			
		||||
  ssl_certificate_key /data/custom_ssl/npm-{{ certificate_id }}/privkey.pem;
 | 
			
		||||
{% endif %}
 | 
			
		||||
{% endif %}
 | 
			
		||||
@@ -5,13 +5,15 @@
 | 
			
		||||
{% if enabled %}
 | 
			
		||||
{% if tcp_forwarding == 1 or tcp_forwarding == true -%}
 | 
			
		||||
server {
 | 
			
		||||
  listen {{ incoming_port }};
 | 
			
		||||
  listen {{ incoming_port }}{% if certificate %} ssl{% endif %};
 | 
			
		||||
{% if ipv6 -%}
 | 
			
		||||
  listen [::]:{{ incoming_port }};
 | 
			
		||||
  listen [::]:{{ incoming_port }}{% if certificate %} ssl{% endif %};
 | 
			
		||||
{% else -%}
 | 
			
		||||
  #listen [::]:{{ incoming_port }};
 | 
			
		||||
  #listen [::]:{{ incoming_port }}{% if certificate %} ssl{% endif %};
 | 
			
		||||
{% endif %}
 | 
			
		||||
 | 
			
		||||
{% include "_certificates_stream.conf" %}
 | 
			
		||||
 | 
			
		||||
  proxy_pass {{ forwarding_host }}:{{ forwarding_port }};
 | 
			
		||||
 | 
			
		||||
  # Custom
 | 
			
		||||
 
 | 
			
		||||
@@ -0,0 +1,2 @@
 | 
			
		||||
ssl_session_timeout 5m;
 | 
			
		||||
ssl_session_cache shared:SSL_stream:50m;
 | 
			
		||||
							
								
								
									
										2
									
								
								docker/rootfs/etc/nginx/conf.d/include/ssl-cache.conf
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										2
									
								
								docker/rootfs/etc/nginx/conf.d/include/ssl-cache.conf
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,2 @@
 | 
			
		||||
ssl_session_timeout 5m;
 | 
			
		||||
ssl_session_cache shared:SSL:50m;
 | 
			
		||||
@@ -1,6 +1,3 @@
 | 
			
		||||
ssl_session_timeout 5m;
 | 
			
		||||
ssl_session_cache shared:SSL:50m;
 | 
			
		||||
 | 
			
		||||
# intermediate configuration. tweak to your needs.
 | 
			
		||||
ssl_protocols TLSv1.2 TLSv1.3;
 | 
			
		||||
ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384';
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user