CentOS8_SSL_HTTPS自签名证书配置

本机环境

CentOS_8.4.2105

MariaDB 10.3.28

nginx/1.14.1

检查环境

nginx -V

需安装with-http_ssl_module

生成CA证书

1.进入nginx服务目录,创建certs目录并生成CA证书

cd /usr/share/nginx/
mkdir certs && cd certs
openssl req -newkey rsa:4096 -nodes -sha256 -keyout ca.key -x509 -days 3650 -out ca.crt
​
参考项:Common Name (eg, your name or your server's hostname) []:test.com
其他随意填写

2.生成证书请求文件

openssl req -newkey rsa:4096 -nodes -sha256 -keyout www.test.com.key -out www.test.com.csr
​
参考项:Common Name (eg, your name or your server's hostname) []:www.yinzhengjie.org.cn
其他随意填写

3.签发证书

openssl x509 -req -days 36500 -in www.test.com.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out www.test.com.crt

4.验证证书内容

openssl x509 -in www.test.com.crt -noout -text
 

配置nginx

# For more information on configuration, see:
#   * Official English Documentation: http://nginx.org/en/docs/
#   * Official Russian Documentation: http://nginx.org/ru/docs/
​
user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log;
pid /run/nginx.pid;
​
# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic.
include /usr/share/nginx/modules/*.conf;
​
events {
    worker_connections 1024;
}
​
http {
    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';
​
    access_log  /var/log/nginx/access.log  main;
​
    sendfile            on;
    tcp_nopush          on;
    tcp_nodelay         on;
    keepalive_timeout   65;
    types_hash_max_size 2048; 
          
    include             /etc/nginx/mime.types;
    default_type        application/octet-stream;
         
    # Load modular configuration files from the /etc/nginx/conf.d directory.
    # See http://nginx.org/en/docs/ngx_core_module.html#include
    # for more information. 
    include /etc/nginx/conf.d/*.conf;
​
​
#        listen       80 default_server;
#        listen       [::]:80 default_server;
#        server_name  www.test.com;
#       return 301 https://$server_name$request_url;
#        root         /usr/share/nginx/html;
#   
#        # Load configuration files for the default server block.
#        include /etc/nginx/default.d/*.conf;
#
#        location / {
#        }
#
#        error_page 404 /404.html;
#            location = /40x.html {
#        }
#
#        error_page 500 502 503 504 /50x.html;
#            location = /50x.html {
#        }
#    }
#
​
# Settings for a TLS enabled server.
​
    server {
        listen       443 ssl http2 default_server;
        listen       [::]:443 ssl http2 default_server;
        server_name  www.test.com;
        root         /usr/share/nginx/html;
​
        ssl_certificate "/usr/share/nginx/certs/www.test.com.crt";
        ssl_certificate_key "/usr/share/nginx/certs/www.test.com.key";
        ssl_session_cache shared:SSL:20m;
        ssl_session_timeout  10m;
        ssl_ciphers PROFILE=SYSTEM;
        ssl_prefer_server_ciphers on;
​
        # Load configuration files for the default server block.
        #include /etc/nginx/conf.d/*.conf;
​
        location / {
        }
​
        error_page 404 /404.html;
            location = /40x.html {
        }
​
        error_page 500 502 503 504 /50x.html;
            location = /50x.html {
        }
    }
    #include /etc/nginx/conf.d/*.conf;
​
}
​
nginx -t

完成!

最后检查重启nginx服务,开启防火墙443端口,刷新浏览器缓存等。

 

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值