Nginx·´ÏòÊðÀíHTTPSÉèÖ㬰ü¹ÜÍøÕ¾Êý¾Ý´«ÊäÇå¾²
nginx·´ÏòÊðÀíhttpsÉèÖ㬰ü¹ÜÍøÕ¾Êý¾Ý´«ÊäÇå¾²
Ëæ×Å»¥ÁªÍøµÄ¿ìËÙÉú³¤£¬ÍøÂçÇå¾²ÎÊÌâ±äµÃÔ½À´Ô½Ö÷Òª¡£ÔÚ´«ÊäÃô¸ÐÊý¾ÝµÄÍøÕ¾ÖУ¬Ê¹ÓÃHTTPSÐÒéÀ´¼ÓÃܺͱ£»¤Êý¾ÝµÄÇå¾²ÊDZز»¿ÉÉٵġ£Nginx×÷Ϊһ¿î¸ßÐÔÄܵÄWebЧÀÍÆ÷ºÍ·´ÏòÊðÀíЧÀÍÆ÷£¬¿ÉÒÔͨ¹ýÉèÖÃʵÏÖHTTPSµÄ·´ÏòÊðÀí£¬½øÒ»²½°ü¹ÜÍøÕ¾Êý¾Ý´«ÊäµÄÇå¾²¡£±¾ÎĽ«ÏÈÈÝÔõÑùÔÚNginxÖÐÉèÖÃHTTPS·´ÏòÊðÀí£¬²¢ÌṩÏà¹ØµÄ´úÂëʾÀý¡£
Ê×ÏÈ£¬ÐèҪȷ±£ÒѾ׼ȷװÖÃÁËNginx£¬²¢Í¨¹ýÔËÐÐnginx -vÏÂÁîÈ·ÈÏ°æ±¾ºÅ¡£½ÓÏÂÀ´£¬ÎÒÃǽ«ÉèÖÃNginxÖ§³ÖHTTPS·´ÏòÊðÀí¡£
ÌìÉúSSLÖ¤Êé
Ê×ÏÈ£¬ÎÒÃÇÐèÒªÌìÉúSSLÖ¤Ê飬ÒÔÈ·±£Êý¾ÝÔÚ´«ÊäÀú³ÌÖеÄÇå¾²ÐÔ¡£¿ÉÒÔʹÓÃÃâ·ÑµÄLet’s EncryptÖ¤Ê飬Ҳ¿ÉÒÔ¹ºÖÃÉÌÒµSSLÖ¤Êé¡£
¼ÙÉèÎÒÃÇÑ¡ÔñʹÓÃLet’s EncryptÖ¤Ê飬ÔÚЧÀÍÆ÷ÉÏ×°ÖÃcertbot¹¤¾ß£¬²¢ÔËÐÐÒÔÏÂÏÂÁîÒÔÌìÉúÖ¤Ê飺
sudo apt-get update sudo apt-get install certbot sudo certbot certonly --nginx
µÇ¼ºó¸´ÖÆ
ƾ֤ÌáÐÑÊäÈëÓòÃû£¬²¢Ñ¡Ôñ×Ô¶¯ÉèÖÃNginxÒÔʹÆäÖ§³ÖHTTPS¡£
ÉèÖÃNginx
ÌìÉúÖ¤Êéºó£¬ÎÒÃÇÐèÒªÉèÖÃNginxÒÔÖ§³ÖHTTPS·´ÏòÊðÀí¡£·¿ªNginxµÄÉèÖÃÎļþ/etc/nginx/nginx.conf£¬²¢Ìí¼ÓÒÔÏÂÄÚÈÝ£º
http { server { listen 80; server_name example.com; return 301 https://$host$request_uri; } server { listen 443 ssl; server_name example.com; ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem; location / { proxy_pass http://backend-server; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } } }
µÇ¼ºó¸´ÖÆ
ÔÚÉÏÊöÉèÖÃÖУ¬ÎÒÃÇÊ×ÏÈÉèÖÃÁ˼àÌý80¶Ë¿ÚµÄserver¿é£¬½«ËùÓÐHTTPÇëÇóÖض¨ÏòÖÁHTTPS¡£È»ºó£¬ÉèÖÃÁ˼àÌý443¶Ë¿ÚµÄserver¿é£¬Ö¸¶¨SSLÖ¤ÊéµÄ·¾¶£¬²¢ÉèÖÃÁË·´ÏòÊðÀíλÖÃ/£¬½«ÇëÇóת·¢ÖÁºó¶ËЧÀÍÆ÷backend-server¡£
ÐèҪעÖصÄÊÇ£¬example.comÓ¦¸ÃÌ滻ΪÏÖʵµÄÓòÃû£¬backend-serverÓ¦¸ÃÌ滻ΪÏÖʵµÄºó¶ËЧÀÍÆ÷µØµã¡£
ÖØÆôNginxЧÀÍ
Íê³ÉÉèÖúó£¬ÉúÑÄÎļþ²¢ÖØÆôNginxЧÀÍÒÔʹÉèÖÃÉúЧ¡£ÔËÐÐÒÔÏÂÏÂÁ
sudo service nginx restart
µÇ¼ºó¸´ÖÆ
ÑéÖ¤HTTPS·´ÏòÊðÀí
ÏÖÔÚ£¬ÎÒÃÇ¿ÉÒÔͨ¹ý»á¼ûhttps://example.comÀ´ÑéÖ¤HTTPS·´ÏòÊðÀíµÄÉèÖá£ÈôÊÇÒ»ÇÐ˳Ë죬Äú½«¿´µ½Í¨¹ý·´ÏòÊðÀíת·¢µÄÄÚÈÝ£¬²¢ÇÒä¯ÀÀÆ÷µÄµØµãÀ¸½«ÏÔʾÇå¾²ÅþÁ¬µÄ±êʶ¡£
×ܽá
ͨ¹ýNginx·´ÏòÊðÀíµÄÉèÖã¬ÎÒÃÇ¿ÉÒÔʵÏÖHTTPSÐÒéµÄÇå¾²Êý¾Ý´«Ê䣬½øÒ»²½°ü¹ÜÍøÕ¾Êý¾ÝµÄÇå¾²ÐÔ¡£ÔÚ±¾ÎÄÖУ¬ÎÒÃÇÏÈÈÝÁËÔõÑùÉèÖÃNginxÖ§³ÖHTTPS·´ÏòÊðÀí£¬²¢ÌṩÁËÏà¹ØµÄ´úÂëʾÀý¡£Í¨¹ýÕâÖÖ·½·¨£¬ÎÒÃÇ¿ÉÒÔÈ·±£ÍøÕ¾ÔÚÊý¾Ý´«ÊäÀú³ÌÖеÄÇå¾²ÐÔ£¬²¢±ÜÃâÃô¸ÐÊý¾Ý±»ÇÔÈ¡»ò¸Ä¶¯¡£
ÒÔÉϾÍÊÇNginx·´ÏòÊðÀíHTTPSÉèÖ㬰ü¹ÜÍøÕ¾Êý¾Ý´«ÊäÇå¾²µÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡