安装gcc、g++,用来编译源码
$ yum install -y gcc gcc-c++
安装PCRE,Perl正则表达式
$ yum install pcre pcre-devel
安装zlib,gzip压缩命令
$ yum install zlib zlib-devel
安装OpenSSL,SSL协议
$ yum install openssl openssl-devel
下载源码、解压源码、进入源码目录
$ wget http://nginx.org/download/nginx-1.13.0.tar.gz
$ tar xvf nginx-1.13.0.tar.gz
$ cd nginx-1.13.0
配置
$ ./configure --prefix=/usr/local/nginx --with-http_stub_status_module --with-http_ssl_module
编译、安装
$ make
$ make install
复制编译好的nginx启动文件到新目录
$ cp nginx-1.13.0/objs/nginx /usr/local/nginx/sbin/
指定配置文件位置
$ /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf
配置http与https共存
server {
listen 80 default backlog=2048;
listen 443 ssl;
server_name localhost;
root html;
ssl_certificate cert/servername.com.crt;
ssl_certificate_key cert/servername.com.key;
}
配置SSL安全证书后重启避免输入密码
$ openssl rsa -in servername.key -out servername.key.unsecure
# 生成一个解密的key,替换掉ssl_certificate_key的值为servername.key.unsecure
SSL性能调优
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4:HIGH:!MD5:!aNULL:!eNULL:!NULL:!DH:!EDH:!AESGCM;
ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;