server {
listen 10.0.0.221:80;
server_name xxx.xxx.xxx;
return 301 https:
}
server{
listen 10.0.0.221:443 http2 ssl;
server_name xxx.xxx.xxx;
ssl_certificate /etc/letsencrypt/live/vnc.lstu.top/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/vnc.lstu.top/privkey.pem;
ssl_protocols TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:E256-GCM-SHA384;
ssl_prefer_server_ciphers off;
location / {
root /usr/share/novnc/;
index vnc.html;
try_files $uri $uri/ /vnc.html;
}
location /novnc {
proxy_pass http:
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "Upgrade";
proxy_set_header Host $host;
}
location /websockify {
proxy_pass http:
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "Upgrade";
proxy_set_header Host $host;
}
}