--- --- ssl on; ssl_certificate {{ site.cert-path }}/wildcard-rsa3072.pem; ssl_certificate_key /etc/keys/leaf-rsa3072.key;