mirror of
https://codeberg.org/icewind/haze.git
synced 2026-10-01 08:44:09 +02:00
spelling fixes in changelog and book
This commit is contained in:
parent
08df5a11c0
commit
51d0279c41
14 changed files with 110 additions and 102 deletions
|
|
@ -1,10 +1,10 @@
|
|||
# HTTPS
|
||||
|
||||
The proxy can be setup to enable using https to access the running instances.
|
||||
Besides the warm and fuzy feeling of knowing that nobody can snoop on the trafic
|
||||
that is happening completely local inside your machine. Accessing the page over
|
||||
https is required for some javascript features (such as service workers), as
|
||||
they are only available in "secure contexts".
|
||||
The proxy can be setup to enable using HTTPS to access the running instances.
|
||||
Besides the warm and fuzzy feeling of knowing that nobody can snoop on the
|
||||
traffic that is happening completely local inside your machine. Accessing the
|
||||
page over HTTPS is required for some JavaScript features (such as service
|
||||
workers), as they are only available in "secure contexts".
|
||||
|
||||
## Getting a wildcard certificate
|
||||
|
||||
|
|
@ -26,18 +26,18 @@ lists some DNS providers and supported ACME clients.
|
|||
You can also create a self-signed wildcard certificate using a tool like
|
||||
`mkcert`. This certificate will not be trusted by your browser and tools like
|
||||
curl, but you can add manually add it to the trusted certificates on your
|
||||
system, or bypass the certficate warning in the browser/curl every time.
|
||||
system, or bypass the certificates warning in the browser/curl every time.
|
||||
|
||||
```bash
|
||||
# Generate local wildcard certificate
|
||||
mkcert -cert-file <path-to-your-certificats>haze.example.com.crt -key-file <path-to-your-certificats>haze.example.com.key '*.haze.example.com'
|
||||
mkcert -cert-file <path-to-your-certificates>haze.example.com.crt -key-file <path-to-your-certificates>haze.example.com.key '*.haze.example.com'
|
||||
```
|
||||
|
||||
## Using the certificate
|
||||
|
||||
### Without reverse proxy
|
||||
|
||||
The haze proxy can serve over https directly, to enable that add the following
|
||||
The haze proxy can serve over HTTPS directly, to enable that add the following
|
||||
to the `[proxy]` section of your `haze.toml`.
|
||||
|
||||
```toml
|
||||
|
|
@ -64,8 +64,8 @@ server {
|
|||
http2 on;
|
||||
server_name *.haze.example.com;
|
||||
|
||||
ssl_certificate <path-to-your-certificats>/haze.example.com.crt;
|
||||
ssl_certificate_key <path-to-your-certificats>/haze.example.com.key;
|
||||
ssl_certificate <path-to-your-certificates>/haze.example.com.crt;
|
||||
ssl_certificate_key <path-to-your-certificates>/haze.example.com.key;
|
||||
|
||||
location / {
|
||||
proxy_pass http://haze-handler;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue