ÔõÑùʵÏÖNginxµÄSSLÖ¤ÊéÉèÖÃ
ÓÉÓÚÊÇһƪ¹ØÓÚNginx SSLÖ¤ÊéÉèÖõÄÎÄÕ£¬ÎÒ½¨ÒéÎÊÌâΪ¡¶Nginx SSLÖ¤ÊéÉèÖÃÏê½â¡·¡£
ÎÄÕÂÄÚÈÝÈçÏ£º
´«Êä²ãÇå¾²ÐÒ飨TLS£©ºÍÇå¾²Ì×½Ó×ֲ㣨SSL£©ÊÇÓÃÓÚÔÚÍøÂçÉÏÇå¾²´«ÊäÊý¾ÝµÄÐÒé¡£ÔÚÏÖ´úÍøÂçÖУ¬±£»¤ÍøÕ¾Êý¾Ý´«ÊäµÄÇå¾²ÐÔÖÁ¹ØÖ÷Òª¡£ÎªÁ˱£»¤ÍøÕ¾ºÍÓû§µÄÊý¾Ý£¬ÍøÕ¾ÖÎÀíÔ±ÐèÒªÉèÖÃTLS/SSLÖ¤Êé¡£±¾ÎĽ«ÏêϸÏÈÈÝÔõÑùÔÚNginxÖÐʵÏÖSSLÖ¤ÊéÉèÖ㬲¢ÌṩÏìÓ¦µÄ´úÂëʾÀý¡£
ÌìÉúSSLÖ¤ÊéºÍ˽Կ
ÔÚÉèÖÃNginx SSL֮ǰ£¬Ê×ÏÈÐèÒªÌìÉúSSLÖ¤ÊéºÍ˽Կ¡£¿ÉÒÔͨ¹ýÖÖÖÖÖ¤Êé½ÒÏþ»ú¹¹£¨CA£©»ñµÃSSLÖ¤Ê飬»òÕß×ÔÐÐÌìÉú×ÔÊðÃûÖ¤Êé¡£ÏÂÃæÊÇÒ»¸ö×ÔÊðÃûÖ¤ÊéµÄʾÀý£º
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout your_domain.key -out your_domain.crt
µÇ¼ºó¸´ÖÆ
ÔÚÖ´ÐÐÉÏÊöÏÂÁîʱ£¬ÐèÒªÌæ»»your_domain.keyºÍyour_domain.crtΪÏÖʵµÄÖ¤ÊéºÍ˽ԿÎļþÃû£¬²¢Æ¾Ö¤ÌáÐÑÊäÈëÏìÓ¦µÄÐÅÏ¢¡£
ÉèÖÃNginx
½ÓÏÂÀ´£¬ÐèÒªÔÚNginxÉèÖÃÎļþÖÐÌí¼ÓSSLÉèÖÃÏ²¢Ö¸¶¨ÌìÉúµÄSSLÖ¤ÊéºÍ˽ԿÎļþ·¾¶¡£ÒÔÏÂÊÇÒ»¸öNginxÉèÖÃÎļþʾÀý£º
server { listen 443 ssl; server_name your_domain.com; ssl_certificate /path/to/your_domain.crt; ssl_certificate_key /path/to/your_domain.key; ssl_protocols TLSv1.2 TLSv1.3; ssl_prefer_server_ciphers on; ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512; # ÆäËûSSLÑ¡ÏÈçSSL»á»°»º´æµÈ }
µÇ¼ºó¸´ÖÆ
ÔÚÉÏÊöÉèÖÃÖУ¬ÐèÒª½«your_domain.comÌ滻ΪÏÖʵµÄÓòÃû£¬½«/path/to/your_domain.crtºÍ/path/to/your_domain.keyÌ滻ΪÏÖʵµÄÖ¤ÊéºÍ˽ԿÎļþ·¾¶¡£ÁíÍ⣬Ҳ¿ÉÒÔƾ֤ÐèÒªÉèÖÃÆäËûSSLÑ¡ÏÈçSSLÐÒé°æ±¾¡¢ÃÜÂëÌ×¼þµÈ¡£
ÖØÆôNginx
ÔÚÍê³ÉSSLÖ¤ÊéºÍNginxÉèÖÃÎļþµÄÐ޸ĺó£¬ÐèÒªÖØÆôNginxЧÀÍÆ÷ÒÔʹ¸ü¸ÄÉúЧ¡£¿ÉÒÔʹÓÃÒÔÏÂÏÂÁîÖØÆôNginx£º
sudo systemctl restart nginx
µÇ¼ºó¸´ÖÆ
È·±£NginxÒѾÖØмÓÔØÁËеÄÉèÖá£
ÑéÖ¤SSLÉèÖÃ
×îºó£¬¿ÉÒÔʹÓÃÖÖÖÖÔÚÏßSSL¼ì²â¹¤¾ß»òä¯ÀÀÆ÷»á¼ûÍøÕ¾£¬ÑéÖ¤SSLÖ¤ÊéÊÇ·ñÀÖ³ÉÉèÖá£ÔÚä¯ÀÀÆ÷ÖÐÊäÈëhttps://your_domain.com£¬ÈôÊÇ¿´µ½ÒÑÀÖ³ÉʹÓÃSSLÖ¤Êé¼ÓÃܵÄÍøÕ¾£¬Ôò֤ʵSSLÖ¤ÊéÒÑÀÖ³ÉÉèÖá£
×ܽá
ͨ¹ýÉÏÊö°ì·¨£¬ÎÒÃÇÏêϸÏÈÈÝÁËÔõÑùÔÚNginxÖÐʵÏÖSSLÖ¤ÊéÉèÖá£Ê×ÏÈÌìÉúSSLÖ¤ÊéºÍ˽Կ£¬È»ºóÔÚNginxÉèÖÃÎļþÖÐÌí¼ÓSSLÉèÖÃÏ²¢×îºóÑéÖ¤SSLÉèÖÃÊÇ·ñÉúЧ¡£Ï£Íû¶ÁÕßÄܹ»Í¨¹ý±¾ÎÄÇáËÉÃ÷È·ºÍʵ¼ùNginx SSLÖ¤ÊéÉèÖ㬲¢ÎªÍøÕ¾µÄÇå¾²ÐÔ×ö³öТ˳¡£
£¨×¢£ºÒÔÉÏʾÀýÖеÄÎļþ·¾¶¡¢ÓòÃûµÈ½öΪÊ÷Ä££¬¶ÁÕßÐèҪƾ֤ÏÖÕæÏàÐξÙÐÐÌæ»»¡££©
ÒÔÉϾÍÊÇÔõÑùʵÏÖNginxµÄSSLÖ¤ÊéÉèÖõÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡