我的代码是这样,你可以参考下
server {
listen 80;
server_name *.com www.*.com ;
rewrite ^(.*) https://www.*.com$1 permanent;
add_header Strict-Transport-Security "max-age=31536000;includeSubDomains";
}
server {
listen 443 ssl spdy;
server_name *.com www.*.com ;
ssl on;
ssl_certificate /cert/sever.crt ;
ssl_certificate_key /cert/sever.key ;
ssl_protocols TLSv1.2 TLSv1.1 TLSv1;
ssl_ciphers FIPS@STRENGTH:!aNULL:!eNULL;
ssl_prefer_server_ciphers on;
ssl_stapling on;
ssl_stapling_verify on;
add_header Strict-Transport-Security "max-age=31536000;includeSubDomains";
location / {
proxy_redirect
https://www.google.com/ /;
proxy_pass http://173.194.120.67;
proxy_cookie_domain
google.com *.com;
proxy_set_header Accept-Language "zh-CN";
proxy_set_header Accept-Encoding "";
proxy_set_header User-Agent $http_user_agent;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_cache one;
proxy_cache_valid 200 304 3h;
proxy_cache_valid 301 3d;
proxy_cache_valid any 1m;
proxy_cache_use_stale invalid_header error timeout http_502;
sub_filter
google.com *.com;
sub_filter_once off;
}
}