1.安裝git和bc
nginx
yum -y install git bc
2.安裝Nginx
1.準備:
c++
yum install -y gcc-c++ pcre pcre-devel zlib zlib-devel openssl openssl-devel
2.下載:
git
wget https://nginx.org/download/nginx-1.11.6.tar.gz
3.解壓:
github
tar zxvf nginx-1.11.6.tar.gz
4.編譯安裝:
bash
cd nginx-1.11.6 ./configure --with-ipv6 --with-http_ssl_module make make install
3.申請SSL證書
1.下載Let’s Encrypt
code
git clone https://github.com/wjg1101766085/certbot.git
2.運行Let’s Encrypt
server
cd certbot ./letsencrypt-auto
生成文件: crontab
cert.pem: 域名證書
chain.pem: The Let’s Encrypt 證書
fullchain.pem: 上面二者合體
privkey.pem: 證書密鑰ip
4.配置Nginx
1.修改nginx.conf文件
ssl
nano /usr/local/nginx/conf/nginx.conf 添加: ssl_certificate /etc/letsencrypt/live/域名/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/域名/privkey.pem; 修改: server_name 域名;
5.自動續簽證書
建立定時任務執行 letsencrypt路徑/letsencrypt-auto renew
例如:
crontab -e 新增一行 30 2 * * 1 letsencrypt路徑/letsencrypt-auto renew