前提:需要有这个编译模块 ./configure --prefix=/usr/local/nginx/ --with-http_ssl_module --with-file-aio
cd /etc/pki/tls/certs/
make cert.pem # 制作证书
cp cert.pem /usr/local/nginx/conf/ # 证书在 /usr/local/nginx/conf/才会生效
cd /usr/local/nginx/conf/
vim nginx.conf
server {
listen 443 ssl; # 监听端口为443
server_name www.westos.org;
ssl_certificate cert.pem; # 证书位置
ssl_certificate_key cert.pem; # 私钥位置
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 5m;
ssl_ciphers HIGH:!aNULL:!MD5; # 密码加密方式
ssl_prefer_server_ciphers on;
location / {
root /web; # 根目录位置
index index.html index.htm;
}
}
/usr/local/nginx/sbin/nginx -t # 检测语法
/usr/local/nginx/sbin/nginx -s reload
mkdir /web建立目录
vim /web/index.html
写入https:server1.westos.org
vim /etc/hosts # 在客户端写解析
172.25.254.10 www.westos.org
测试: