listen 443; server_name test.com; ssl on; ssl_certificate server.crt; //server端公鑰 ssl_certificate_key server.key; //server端私鑰 ssl_client_certificate client.crt; //client端公鑰 ssl_session_timeout 5m; ssl_verify_client on; //開啓client驗證
相關參考
http://wiki.nginx.org/HttpSslModule#sslnginx