nginx https http2
来源:互联网 发布:mac复制文件夹到u盘 编辑:程序博客网 时间:2024/06/06 17:31
前提条件
1.编译openssl最新版本
2.生成证书 (本文采用的是let's encrypt的证书)
安装nginx (本文不讨论nginx的性能优化)
./configure --prefix=/usr/local/nginx-1.12.0 --with-http_ssl_module --with-http_v2_module --with-openssl=/usr/local/src/openssl-1.1.0e
make -j4
sudo make install
配置文件
server { listen 80; server_name www.panchan.net.cn; return 301 https://$host$request_uri;}
server { listen 443 ssl http2; server_name www.panchan.net.cn; ssl_certificate /etc/letsencrypt/live/panchan.net.cn/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/panchan.net.cn/privkey.pem; ssl_session_timeout 1d; ssl_session_cache shared:SSL:50m; ssl_session_tickets off; ssl_protocols TLSv1.2; ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256'; ssl_prefer_server_ciphers on; add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload"; ssl_stapling on; ssl_stapling_verify on; ssl_trusted_certificate /etc/letsencrypt/live/panchan.net.cn/chain.pem; resolver 100.100.2.138; location / { root html; index index.html index.htm; } }
测试评
测试报告参
参考资料
http://nginx.org/en/docs/http/ngx_http_ssl_module.html
http://nginx.org/en/docs/http/ngx_http_v2_module.html
http://nginx.org/en/docs/http/configuring_https_servers.html
下次写一下如何使用let's ecnrypt的ecc证书.
0 0
- nginx+http2+https
- nginx https http2
- Nginx上部署HTTPS + HTTP2
- HTTP2.0 HTTPS学习
- Http2.2实现https
- nginx http2配置
- Nginx 上配置 HTTP2
- nginx 配置http2.0
- nginx http2 源码分析
- nginx的http2.0性能太逆天了,HTTPS网站性能优化
- HTTPS 与 HTTP2 协议分析
- HTTPS 与 HTTP2 协议分析
- HTTPS 与 HTTP2 协议分析
- springboot+undertow+http+https+http2
- HTTP、HTTPS、SPDY、HTTP2.0
- nginx 1.9 支持http2 协议
- nginx配置http2无效不起作用
- HTTP,HTTP2.0,SPDY,HTTPS看这篇就够了
- 【最简单】Electron 怎么将网页打包成桌面应用(web前端页面怎么生成exe可执行文件)
- 统计学习方法第四章朴素贝叶斯法-李航
- 第五次实验
- 浏览器插件之ActiveX开发(五)
- 预习指针
- nginx https http2
- 开发中遇到的问题汇总
- RxJava操作符(三) __过滤操作
- poj 1686
- excel分列功能
- Yougth的最大化(二分法加贪心)
- nodejs博客系统(express+mongodb)2——划分模块+连接数据库
- 在不关站的情况下对网站备案的方法
- 高效工作的六个方法