Nginx环境ssl配置+手动生成证书

1.配置https访问:

yum install nginx httpd-tools
vim /etc/nginx/conf.d/docker-registry.conf

upstream docker-registry {
 server localhost:5000;
}
server {
 listen 8080;
 server_name registry.wmj.com;
 ssl on;
 ssl_certificate /etc/ssl/nginx.crt;
 ssl_certificate_key /etc/ssl/nginx.key;
 proxy_set_header Host       $http_host;   # required for Docker client sake
 proxy_set_header X-Real-IP  $remote_addr; # pass on real client IP
 client_max_body_size 0; # disable any limits to avoid HTTP 413 for large image uploads
 chunked_transfer_encoding on;
 location / {
     # let Nginx know about our auth file
     auth_basic              "Docker";
     auth_basic_user_file    docker-registry.htpasswd;
     proxy_pass http://docker-registry;
 }
 location /_ping {
     auth_basic off;
     proxy_pass http://docker-registry;
 }
 location /v1/_ping {
     auth_basic off;
     proxy_pass http://docker-registry;
 }
}

# htpasswd -c docker-registry.htpassw wmj #生成http密码

2.手动生成证书:

生成根证书
# cd /etc/pki/CA/
# touch ./{serial,index.txt}
# echo "00" > serial
为CA生成一个私钥
# openssl genrsa -out private/cakey.pem 2048
签发CA证书
# openssl req -new -x509 -key private/cakey.pem -days 3650 cacert.pem

    Country Name (2 letter code) [XX]:CN
    State or Province Name (full name) []:Changsha
    Locality Name (eg, city) [Default City]:Changsha
    Organization Name (eg, company) [Default Company Ltd]:wmj
    Organizational Unit Name (eg, section) []:docker
    Common Name (eg, your name or your server's hostname) []:docker.wmj.com
    Email Address []:admin@wmj.com

生成nginx的key:
# cd /etc/ssl/
# openssl genrsa -out nginx.key 2048
# openssl req -new -key nginx.key -out nginx.csr

    Country Name (2 letter code) [XX]:CN
    State or Province Name (full name) []:Changsha
    Locality Name (eg, city) [Default City]:Changsha
    Organization Name (eg, company) [Default Company Ltd]:wmj
    Organizational Unit Name (eg, section) []:docker
    Common Name (eg, your name or your server's hostname) []:registry.wmj.com
    Email Address []:admin@wmj.com

    Please enter the following 'extra' attributes
    to be sent with your certificate request
    A challenge password []:
    An optional company name []:

签发nginx证书:
# openssl ca -in nginx.csr -days 3650 -out nginx.crt     #按两个Y

让系统接受自签发的证书:
# cat /etc/pki/CA/cacert.pem >> /etc/pki/tls/certs/ca-bundle.crt
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值