I followed your advice and added comments to almost all my configurations. I will add some test tools to allow easier test of the configurations, but I think it's a lot better now.
Besides that, I assume people will use nginx 1.3.7 or newer, so a few defaults are assumed as well.
We currently are setting Strict-Transport-Security with rails, but as I said in the comments of the blog, I think that setting this header inside nginx could be a better idea.
I agree that having a PPA isn't the best thing in the world, but this one is very stable(I'm using it for quite some time). Anyway, I will update the post to use the official repo, since it's really a better option. Thanks :)
Thanks for the heads up ck2. I've updated the config to add ocsp stapling. The certificate really has a extra(unnecessary) root certificate, I will solve this later today.
When I read this news I was expecting something like this http://www.ohloh.net/accounts/Stefan (show all repos that this person had done any commits/opened issues). Kinda sad.