Use this generator as your base (update nginx/SSL versions appropriately if you run into issues) and add in your custom well-known block in the first server block and your proxy_pass location block in the SSL server block:

https://ssl-config.mozilla.org/#server=nginx&version=1.17.7&config=intermediate&openssl=1.1.1k&ocsp=false&guideline=5.6

Reply to this note

Please Login to reply.

Discussion

These are industry-standard defaults and should form the base of any nginx config.

Feel free to select "modern" TLS settings, should work fine for your use cases but may cause issues for the occasional person.

Thank you