Posted: Tue Jul 07, 2020 7:49 am
by donat

My websites are no longer available. I don't know, where the problem sucks.

In the forum I changed the cipher in the vesta.conf as mentioned earlier, but this didn't work anyway.

The Handshake ssl seems not to work.

I have debian 9.

Where should I look at it?

When I start nginx -t, then I have following warnings:
nginx: [warn] the "ssl" directive is deprecated, use the "listen ... ssl" directive instead in /home/user/conf/web/website.nginx.ssl.conf:4
nginx: [warn] conflicting server name "website" on ip:80, ignored

The ports are set correct. Therefore I don't know actually, what is wrong.

Here are my templates file:
nginx_proxy: default.tpl

server {
    listen      %ip%:%proxy_port%;
    server_name %domain_idn% %alias_idn%;
    error_log  /var/log/%web_system%/domains/%domain%.error.log error;

    location / {
        proxy_pass      http://%ip%:%web_port%;
        location ~* ^.+\.(%proxy_extentions%)$ {
            root           %docroot%;
            access_log     /var/log/%web_system%/domains/%domain%.log combined;
            access_log     /var/log/%web_system%/domains/%domain%.bytes bytes;
            expires        max;
            try_files      $uri @fallback;

    location /error/ {
        alias   %home%/%user%/web/%domain%/document_errors/;

    location @fallback {
        proxy_pass      http://%ip%:%web_port%;

    location ~ /\.ht    {return 404;}
    location ~ /\.svn/  {return 404;}
    location ~ /\.git/  {return 404;}
    location ~ /\.hg/   {return 404;}
    location ~ /\.bzr/  {return 404;}

    include %home%/%user%/conf/web/nginx.%domain%.conf*;

server {
    listen      %ip%:%proxy_ssl_port%;
    server_name %domain_idn% %alias_idn%;
    ssl         on;
    ssl_certificate      %ssl_pem%;
    ssl_certificate_key  %ssl_key%;
    error_log  /var/log/%web_system%/domains/%domain%.error.log error;

    location / {
        proxy_pass      https://%ip%:%web_ssl_port%;
        location ~* ^.+\.(%proxy_extentions%)$ {
            root           %sdocroot%;
            access_log     /var/log/%web_system%/domains/%domain%.log combined;
            access_log     /var/log/%web_system%/domains/%domain%.bytes bytes;
            expires        max;
            try_files      $uri @fallback;

    location /error/ {
        alias   %home%/%user%/web/%domain%/document_errors/;

    location @fallback {
        proxy_pass      https://%ip%:%web_ssl_port%;

    location ~ /\.ht    {return 404;}
    location ~ /\.svn/  {return 404;}
    location ~ /\.git/  {return 404;}
    location ~ /\.hg/   {return 404;}
    location ~ /\.bzr/  {return 404;}

    include %home%/%user%/conf/web/snginx.%domain%.conf*;
apache2: default:tpl

<VirtualHost %ip%:%web_port%>

    ServerName %domain_idn%
    ServerAdmin %email%
    DocumentRoot %docroot%
    ScriptAlias /cgi-bin/ %home%/%user%/web/%domain%/cgi-bin/
    Alias /vstats/ %home%/%user%/web/%domain%/stats/
    Alias /error/ %home%/%user%/web/%domain%/document_errors/
    #SuexecUserGroup %user% %group%
    CustomLog /var/log/%web_system%/domains/%domain%.bytes bytes
    CustomLog /var/log/%web_system%/domains/%domain%.log combined
    ErrorLog /var/log/%web_system%/domains/%domain%.error.log
    <Directory %docroot%>
        AllowOverride All
        Options +Includes -Indexes +ExecCGI
    <Directory %home%/%user%/web/%domain%/stats>
        AllowOverride All

    <IfModule mod_ruid2.c>
        RMode config
        RUidGid %user% %group%
        RGroups www-data
    <IfModule itk.c>
        AssignUserID %user% %group%

    IncludeOptional %home%/%user%/conf/web/%web_system%.%domain%.conf*


apache2: default.stpl

<VirtualHost %ip%:%web_ssl_port%>

    ServerName %domain_idn%
    ServerAdmin %email%
    DocumentRoot %sdocroot%
    ScriptAlias /cgi-bin/ %home%/%user%/web/%domain%/cgi-bin/
    Alias /vstats/ %home%/%user%/web/%domain%/stats/
    Alias /error/ %home%/%user%/web/%domain%/document_errors/
    #SuexecUserGroup %user% %group%
    CustomLog /var/log/%web_system%/domains/%domain%.bytes bytes
    CustomLog /var/log/%web_system%/domains/%domain%.log combined
    ErrorLog /var/log/%web_system%/domains/%domain%.error.log
    <Directory %sdocroot%>
        AllowOverride All
        Options +Includes -Indexes +ExecCGI
    <Directory %home%/%user%/web/%domain%/stats>
        AllowOverride All
    SSLEngine on
    SSLVerifyClient none
    SSLCertificateFile %ssl_crt%
    SSLCertificateKeyFile %ssl_key%
    %ssl_ca_str%SSLCertificateChainFile %ssl_ca%

    <IfModule mod_ruid2.c>
        RMode config
        RUidGid %user% %group%
        RGroups www-data
    <IfModule itk.c>
        AssignUserID %user% %group%

    IncludeOptional %home%/%user%/conf/web/s%web_system%.%domain%.conf*


Maybe it's completely another problem, because I don't have any idea, where the error is.

Any help is very appreciated.

Posted: Tue Jul 07, 2020 11:52 am
by donat
I found the failure:

In the config template nginx: default.stpl
there is no ssl on>;
but an ssl after listen:

server {
    listen      %ip%:%proxy_ssl_port% ssl;
    server_name %domain_idn% %alias_idn%;