ÔõÑùʹÓÃNginxÉèÖÃSSL/TLS¼ÓÃÜͨѶ
ÔõÑùʹÓÃnginxÉèÖÃssl/tls¼ÓÃÜͨѶ
¸ÅÊö
ÔÚÄ¿½ñ»¥ÁªÍøµÄÇéÐÎÖУ¬Çå¾²ÐÔÒѾ³ÉΪ×îÖ÷ÒªµÄ¿¼Á¿Ö®Ò»¡£±£»¤Óû§µÄÒþ˽ºÍÊý¾ÝÇå¾²±äµÃºÜÊÇÖ÷Òª¡£ÆäÖÐÒ»ÖÖ³£¼ûµÄ·½·¨ÊÇʹÓÃSSL/TLS¼ÓÃÜͨѶÀ´È·±£Êý¾ÝÔÚ´«ÊäÀú³ÌÖеÄÇå¾²¡£
NginxÊÇÒ»¸ö¸ßÐÔÄܵÄWebЧÀÍÆ÷£¬Ò²±»ÆÕ±éÓ¦ÓÃÓÚ·´ÏòÊðÀíºÍ¸ºÔØƽºâ¡£±¾ÎĽ«ÏÈÈÝÔõÑùʹÓÃnginxÉèÖÃssl/tls¼ÓÃÜͨѶ£¬°ü¹ÜÄúµÄÍøÕ¾µÄÇå¾²ÐÔ¡£
°ì·¨Ò»£º»ñÈ¡SSLÖ¤Êé
ҪʹÓÃSSL/TLS¼ÓÃÜͨѶ£¬Ê×ÏÈÐèÒª»ñÈ¡¿ÉÐŵÄSSLÖ¤Ê顣ͨ³££¬Äú¿ÉÒÔ´ÓÖ¤Êé½ÒÏþ»ú¹¹£¨CA£©¹ºÖÃÖ¤Ê飬»òÕßʹÓÃÃâ·ÑµÄLet’s EncryptЧÀÍ¡£
°ì·¨¶þ£º×°ÖÃNginx
ÔÚ×îÏÈÉèÖÃSSL/TLS֮ǰ£¬ÐèҪȷ±£ÒѾ׼ȷװÖúÍÉèÖÃÁËNginx¡£¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁî¼ì²éNginxÊÇ·ñÒѾװÖãº
nginx -v
µÇ¼ºó¸´ÖÆ
ÈôÊÇûÓÐ×°Öã¬ÔòÐèҪƾ֤NginxµÄÎĵµ¾ÙÐÐ×°Öá£
°ì·¨Èý£ºÉèÖÃNginx
·¿ªNginxµÄÉèÖÃÎļþ£¬Í¨³£ÔÚ/etc/nginx/nginx.conf»ò/etc/nginx/conf.d/default.conf·¾¶Ï¡£ÔÚÉèÖÃÖÐÕÒµ½server¿é£¬Ìí¼ÓÒÔÏ´úÂ룺
server { listen 80; server_name example.com; return 301 https://$host$request_uri; } server { listen 443 ssl; server_name example.com; ssl_certificate /path/to/ssl_certificate.crt; ssl_certificate_key /path/to/ssl_certificate.key; location / { ... } }
µÇ¼ºó¸´ÖÆ
ÔÚÉÏÃæµÄ´úÂëÖУ¬listen 443 ssl;½ç˵Á˼àÌýµÄ¶Ë¿ÚΪ443£¬²¢ÆôÓÃÁËSSL¡£server_nameÖ¸¶¨ÁËÄúµÄÓòÃû¡£ssl_certificateºÍssl_certificate_keyÖ¸¶¨ÁËSSLÖ¤ÊéºÍ˽ԿµÄ·¾¶¡£
°ì·¨ËÄ£º²âÊÔÉèÖÃ
ÉúÑIJ¢¹Ø±ÕÉèÖÃÎļþºó£¬Ê¹ÓÃÒÔÏÂÏÂÁî²âÊÔÉèÖÃÊÇ·ñ׼ȷ£º
nginx -t
µÇ¼ºó¸´ÖÆ
ÈôÊÇûÓйýʧ£¬½«ÏÔʾnginx: configuration file /etc/nginx/nginx.conf test is successful¡£
È»ºó£¬ÖØмÓÔØNginxÒÔʹÉèÖÃÉúЧ£º
sudo nginx -s reload
µÇ¼ºó¸´ÖÆ
°ì·¨Î壺ÑéÖ¤SSL¼ÓÃÜ
ʹÓÃä¯ÀÀÆ÷»á¼ûÄúµÄÍøÕ¾£¬ÔÚURLÇ°ÃæÌí¼Óhttps://£¬²¢Éó²éÊÇ·ñÀֳɽ¨ÉèÁËÇå¾²ÅþÁ¬¡£ÔÚä¯ÀÀÆ÷ÖлáÏÔʾһ¸öËøÐÎ×´µÄͼ±ê£¬ÌåÏÖÍøÕ¾ÒÑͨ¹ýSSL/TLS¼ÓÃÜͨѶ¡£
¸½¼ÓÉèÖãºHTTPµ½HTTPSµÄÖض¨Ïò
ΪÁËÔöÇ¿Çå¾²ÐÔ£¬Í¨³£ÐèÒª½«HTTPÇëÇóÖض¨Ïòµ½HTTPS¡£¿ÉÒÔʹÓÃÒÔÏ´úÂëÔÚNginxÉèÖÃÎļþÖÐÌí¼ÓHTTPµ½HTTPSµÄÖض¨Ïò£º
server { listen 80; server_name example.com; return 301 https://$host$request_uri; }
µÇ¼ºó¸´ÖÆ
ÔÚÉÏÃæµÄ´úÂëÖУ¬listen 80ÊÇΪHTTPÇëÇó¶øÉèÖõļàÌý¶Ë¿Ú¡£
×ܽá
ÉèÖÃSSL/TLS¼ÓÃÜͨѶ¿ÉÒÔΪÄúµÄÍøÕ¾Ìṩ¸ü¸ßµÄÇå¾²ÐÔ£¬È·±£Óû§ºÍÊý¾ÝµÄÇå¾²¡£Í¨¹ý±¾ÎÄÌṩµÄ°ì·¨£¬Äú¿ÉÒÔÇáËɵØÉèÖÃNginxÒÔͨ¹ýSSL/TLS¼ÓÃÜͨѶ±£»¤ÄúµÄÍøÕ¾¡£
ÎÄÕµ½´Ë¿¢Ê¡£Ï£ÍûÄܶÔÄúÓÐËù×ÊÖú£¡
ÒÔÉϾÍÊÇÔõÑùʹÓÃNginxÉèÖÃSSL/TLS¼ÓÃÜͨѶµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡