location / {
...
proxy_ssl_trusted_certificate /etc/nginx/trusted_ca_cert.crt;
proxy_ssl_verify off;
proxy_ssl_verify_depth 2;
...
}
add_header Front-End-Https on;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade"; <-- when using websockets