Author by Leojavascript
須要確保Nginx安裝了SSL的插件,不然須要重裝Nginx.css
server { listen 443 ssl; server_name xxxx; ssl on; ssl_certificate /home/security/wildcard/983e792300b2056e.crt(公鑰); ssl_certificate_key /home/security/wildcard/seoclarity_net.key(私鑰); ssl_protocols TLSv1 TLSv1.1 TLSv1.2(支持的SSL協議版本); ssl_ciphers ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5(支持的密鑰加密算法); ssl_prefer_server_ciphers on; ssl_session_cache shared:SSL:10m;(SSL認證緩存,提升效率) ssl_session_timeout 30m; ssl_buffer_size 1400;(緩存區) .....
./sbin/nginx -t ./sbin/nginx -s reload or ./sbin/nginx
<Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol" SSLEnabled="true" maxThreads="200" scheme="https" secure="true" clientAuth="false" sslProtocol="TLS" ciphers="TLS_RSA_WITH_AES_128_CBC_SHA,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,SSL_RSA_WITH_3DES_EDE_CBC_SHA,TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA" keystoreType="PKCS12" keystoreFile="/home/ec2-user/ssl-Tomcat/tomcat.p12(上面生成的p12)" keystorePass="xxxx" truststoreType="PKCS12" truststoreFile="/home/ec2-user/ssl-Tomcat/tomcat.p12(上面生成的p12)" truststorePass="xxxx" compression="on" URIEncoding="UTF-8" compressionMinSize="2048" maxPostSize="0" noCompressionUserAgents="gozilla, traviata" compressableMimeType="text/html,text/xml,text/javascript,text/css,application/json" />