网站开启SSL (https)

虚拟空间域名配置*.conf如下:

server {  
  listen 80;
  listen 443 ssl http2;
  ssl_certificate /usr/local/nginx/conf/ssl/xxx.pem;
  ssl_certificate_key /usr/local/nginx/conf/ssl/xxx.key;
  ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  ssl_ciphers EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;
  ssl_prefer_server_ciphers on;
  ssl_session_timeout 10m;
  ssl_session_cache builtin:1000 shared:SSL:10m;
  ssl_buffer_size 1400;
  add_header Strict-Transport-Security max-age=15768000;
  ssl_stapling on;
  ssl_stapling_verify on;
  server_name www.xxx.com xxxx.com;
  access_log /data/wwwlogs/xxxx_nginx.log combined;
  index index.html index.htm index.php;
  root /data/wwwroot/www.xxx.com;
  if ($ssl_protocol = "") { return 301 https://$server_name$request_uri; }
  if ($host != www.xxx.com) {  return 301 $scheme://www.xxx.com$request_uri;  }
  include /usr/local/nginx/conf/rewrite/drupal.conf;
  #error_page 404 = /404.html;
  #error_page 502 = /502.html;

  location ~ [^/]\.php(/|$) {
    #fastcgi_pass remote_php_ip:9000;
    fastcgi_pass unix:/dev/shm/php-cgi.sock;
    fastcgi_index index.php;
    include fastcgi.conf;
  }
  location ~ .*\.(gif|jpg|jpeg|png|bmp|swf|flv|mp4|ico)$ {
    expires 30d;
    access_log off;
  }
  location ~ .*\.(js|css)?$ {
    expires 7d;
    access_log off;
  }
  location ~ /\.ht {
    deny all;
  }