- Debian Jessie host
- Ansible
- "Internet"
- Brain
- Add your VHosts and Upstreams into the groupvars
- Change the inventory to match your hosts IP address
- ansible-playbook -K -i inventory nginx-offloading-letsencrypt.yml
- A+ rating on ssllabs.com (DNS record is mandatory: https://blog.qualys.com/ssllabs/2017/03/13/caa-mandated-by-cabrowser-forum )
- HTTP/2 support
- IPv6 support
- SNI -> SSL certificates without messy AltName attributes
- HSTS enabled by default
- optional websocket support