建立ssl證書
$ mkdir -p /etc/nginx/ssl $ cd /etc/nginx/ssl $ openssl genrsa -idea -out server.key 1024 $ openssl req -new -key server.key -out server.csr $ openssl x509 -req -days 3650 -in server.csr -signkey server.key -out server.crt
注意要加過時時間,默認的有效期很短html
Nginx 配置
$ cd /etc/nginx/conf.d
$ vim https.conf
輸入如下內容nginx
server { listen 443 ssl http2 default_server; listen [::]:443 ssl http2 default_server; server_name _; root /usr/share/nginx/html; ssl_certificate "/etc/nginx/ssl/server.crt"; ssl_certificate_key "/etc/nginx/ssl/server.key"; ssl_session_cache shared:SSL:1m; ssl_session_timeout 10m; ssl_ciphers PROFILE=SYSTEM; ssl_prefer_server_ciphers on; location / { } error_page 404 /404.html; location = /40x.html { } error_page 500 502 503 504 /50x.html; location = /50x.html { } }
保存退出並重啓nginx
shell
由於咱們的證書沒有給相關機構認證,因此仍是提示不安全,可是不影響咱們測試使用vim