add quic support

This commit is contained in:
2025-10-02 20:46:16 -07:00
parent e4ccf355a2
commit 3e1e21dfe1
12 changed files with 13 additions and 0 deletions

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic reuseport default_server;
listen 443 ssl default_server; listen 443 ssl default_server;
server_name *.tronnet.net; server_name *.tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic;
listen 443 ssl; listen 443 ssl;
server_name git.tronnet.net; server_name git.tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic;
listen 443 ssl; listen 443 ssl;
server_name tronnet.net; server_name tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic;
listen 443 ssl; listen 443 ssl;
server_name minecraft.tronnet.net; server_name minecraft.tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic;
listen 443 ssl; listen 443 ssl;
server_name office.tronnet.net; server_name office.tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic;
listen 443 ssl; listen 443 ssl;
server_name opns.tronnet.net; server_name opns.tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic;
listen 443 ssl; listen 443 ssl;
server_name paas.tronnet.net; server_name paas.tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic;
listen 443 ssl; listen 443 ssl;
server_name pve.tronnet.net; server_name pve.tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic;
listen 443 ssl; listen 443 ssl;
server_name root.tronnet.net; server_name root.tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic;
listen 443 ssl; listen 443 ssl;
server_name status.tronnet.net; server_name status.tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -1,4 +1,5 @@
server { server {
listen 443 quic;
listen 443 ssl; listen 443 ssl;
server_name wiki.tronnet.net; server_name wiki.tronnet.net;
include snippets/ssl-acme.conf; include snippets/ssl-acme.conf;

View File

@@ -10,6 +10,8 @@ ssl_stapling on;
ssl_stapling_verify on; ssl_stapling_verify on;
resolver 8.8.8.8 8.8.4.4 valid=300s; resolver 8.8.8.8 8.8.4.4 valid=300s;
resolver_timeout 5s; resolver_timeout 5s;
# quic alternate service advertisement
add_header Alt-Svc 'h3=":443"; ma=864000';
# ssl cert paths # ssl cert paths
ssl_dhparam /etc/ssl/certs/dhparam.pem; ssl_dhparam /etc/ssl/certs/dhparam.pem;
ssl_certificate /etc/letsencrypt/live/tronnet.net/fullchain.pem; ssl_certificate /etc/letsencrypt/live/tronnet.net/fullchain.pem;