All Tools View Categories About Contact Privacy

Nginx SSL/HTTPS Config Generator

Harden a 443 server block with modern protocols, ciphers and HSTS.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your SSL server block will appear here.
-
lines
-
blocks

About Nginx SSL/HTTPS Config Generator

Serving traffic over HTTPS is no longer optional, but the TLS server block is one of the most fiddly parts of nginx: protocol lists that accidentally re-enable insecure ciphers, copied cipher strings that negotiate weak suites, missing OCSP stapling, and an HSTS header that is easy to forget. The Nginx SSL/HTTPS Config Generator assembles a modern, auditable 443 server block from a handful of toggles and validates the result before you copy it.

At the heart of the configuration are a handful of directives. ssl_certificate points nginx at your public certificate chain (fullchain.pem) so it can present it during the TLS handshake. ssl_certificate_key holds the private key that proves ownership of the certificate; keep its permissions tight. ssl_protocols limits negotiated versions to TLSv1.2 and/or TLSv1.3, never older SSL protocols. ssl_ciphers selects the actual encryption suites using a Mozilla preset for balanced compatibility or maximum strength. ssl_stapling lets nginx attach a signed OCSP response so clients skip contacting the CA directly. add_header (Strict-Transport-Security) instructs browsers to enforce HTTPS for your domain and subdomains. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. Selecting both TLS 1.2 and 1.3 is safe, but enabling neither would leave the server unable to negotiate any connection, so the generator forbids that. Pointing ssl_certificate at a path that is not an absolute filename makes nginx fail to start, so the tool requires an absolute prefix. Forgetting OCSP stapling verification means clients cannot confirm revocation, so the generator adds the required resolver when stapling is on. Shipping HSTS without a working HTTPS redirect can lock users out, so enable it only once TLS is confirmed. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Performance and correctness both benefit from explicit configuration. Defaults baked into the generator reflect current best practice rather than decades-old forum snippets, so the block you ship today will not surprise you with deprecated directives or insecure fallbacks six months from now.

Features

  • ssl_certificate - points nginx at your public certificate chain (fullchain.pem) so it can present it during the TLS handshake.
  • ssl_certificate_key - holds the private key that proves ownership of the certificate; keep its permissions tight.
  • ssl_protocols - limits negotiated versions to TLSv1.2 and/or TLSv1.3, never older SSL protocols.
  • ssl_ciphers - selects the actual encryption suites using a Mozilla preset for balanced compatibility or maximum strength.
  • ssl_stapling - lets nginx attach a signed OCSP response so clients skip contacting the CA directly.
  • add_header (Strict-Transport-Security) - instructs browsers to enforce HTTPS for your domain and subdomains.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. Enter each domain on its own line.
  2. Set the certificate path prefix to the absolute directory holding fullchain.pem and privkey.pem.
  3. Choose which TLS versions to allow.
  4. Pick a cipher preset: Intermediate for broad compatibility or Modern for maximum strength.
  5. Toggle OCSP stapling and HSTS as needed.
  6. Click Generate (or Load sample) and review the block.
  7. Copy or download, then drop it into conf.d and run nginx -t.

Examples

Example 1 - Single domain one domain, Intermediate ciphers, stapling and HSTS on - a standard secure host.

Example 2 - Modern only cipher set to Modern for an internal app where every client is current.

Example 3 - No stapling stapling off when the host cannot resolve the CA OCSP endpoint.

Example 4 - Multiple domains several domains listed on server_name share one certificate.

Example 5 - Relative path rejected a certificate prefix without a leading slash is reported as an error.

Benefits

  • Safe protocol list that can never be empty.
  • Mozilla-aligned cipher presets instead of copy-pasted strings.
  • OCSP stapling with the resolver nginx needs, emitted automatically.
  • HSTS header only when you ask for it.
  • Self-checked output re-parsed before display.
  • Private: everything runs in your browser.

Frequently Asked Questions

Why two certificate files?
fullchain.pem contains your certificate plus the CA chain; privkey.pem is the private key. Both reference the same live directory.
Modern vs intermediate?
Modern drops older cipher families for maximum strength and is for current clients only; intermediate keeps broader compatibility including older Android devices.
What is OCSP stapling?
It lets nginx attach a signed revocation response so clients do not contact the CA directly, improving TLS handshake speed and privacy.
Do I need a resolver for stapling?
Yes - stapling verification resolves the CA OCSP endpoint, so the generator adds a resolver directive when stapling is enabled.
Is HTTP/2 enabled?
The block uses the modern http2 on; directive (nginx 1.25.1+). On older nginx swap it for listen 443 ssl http2;.
Where do certificates come from?
The paths are referenced only; obtain them with certbot or your CA. The tool does not create key material.
Is the output validated?
Yes - it is re-parsed with a built-in tokenizer before display.
Is anything uploaded?
No. Everything runs locally in your browser.