nginx https http2

来源:互联网 发布:mac复制文件夹到u盘 编辑:程序博客网 时间:2024/06/06 17:31

前提条件

1.编译openssl最新版本

2.生成证书 (本文采用的是let's encrypt的证书)



安装nginx (本文不讨论nginx的性能优化)

./configure --prefix=/usr/local/nginx-1.12.0 --with-http_ssl_module --with-http_v2_module --with-openssl=/usr/local/src/openssl-1.1.0e

make -j4

sudo make install


配置文件

server {        listen       80;        server_name  www.panchan.net.cn;        return 301 https://$host$request_uri;}
server {        listen       443 ssl http2;        server_name  www.panchan.net.cn;        ssl_certificate      /etc/letsencrypt/live/panchan.net.cn/fullchain.pem;        ssl_certificate_key  /etc/letsencrypt/live/panchan.net.cn/privkey.pem;        ssl_session_timeout 1d;        ssl_session_cache shared:SSL:50m;        ssl_session_tickets off;        ssl_protocols TLSv1.2;        ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256';        ssl_prefer_server_ciphers  on;        add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload";        ssl_stapling on;        ssl_stapling_verify on;        ssl_trusted_certificate /etc/letsencrypt/live/panchan.net.cn/chain.pem;        resolver 100.100.2.138;        location / {            root   html;            index  index.html index.htm;        }    }


测试


测试报告


参考资料

http://nginx.org/en/docs/http/ngx_http_ssl_module.html

http://nginx.org/en/docs/http/ngx_http_v2_module.html

http://nginx.org/en/docs/http/configuring_https_servers.html


下次写一下如何使用let's ecnrypt的ecc证书.


0 0