Let's Encrypt Demo: ssl-legacy
nginx ssl config
server {
    set $APP_BACKEND php70_backend;

    listen       80;
    server_name ssl-legacy.php79.net www.ssl-legacy.php79.net;
    include /etc/letsencrypt/php79/well-known.conf;
    root   ...

	...

    listen 443 ssl http2;
    ssl_certificate /etc/letsencrypt/live/ssl-legacy.php79.net/fullchain.pem;
    ssl_trusted_certificate /etc/letsencrypt/live/ssl-legacy.php79.net/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/ssl-legacy.php79.net/privkey.pem;
    include /etc/letsencrypt/php79/ssl-legacy.conf;

    # Force https
    if ($scheme != "https") {
        return 301 https://$host$request_uri;
    }
}
Oldest compatible clients: Windows XP IE6, Java 6