从http到https(Part-02)
1、下载文件,上传服务器
2、修改配置,增加后台访问路径
SSL证书完毕,点击下载,得到两个文件
将这两个文件上传到服务器任一文件夹,记住路径
找到服务器的nginx配置,使用 nginx -t 命令,下载nginx.conf文件,对其进行编辑,在server里配置
server {
listen 443 ;
server_name 填写你申请证书时的域名;
#charset koi8-r;
ssl on;
#这里写上传的以pem结尾的文件路径,如/etc/nginx/mySSL/xxx.pem
ssl_certificate /etc/nginx/mySSL/xxx.pem;
#这里写上传的以key结尾的文件路径;
ssl_certificate_key /etc/nginx/mySSL/xxx.key;
ssl_session_timeout 5m;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
#access_log logs/host.access.log main;
location /api/ { #后台访问地址
proxy_pass http://127.0.0.1:8764/api/;
proxy_redirect off;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Cookie $http_cookie;
chunked_transfer_encoding off;
client_max_body_size 2000m;
client_body_buffer_size 256k;
proxy_connect_timeout 60;
proxy_buffering on;
proxy_send_timeout 60;
proxy_read_timeout 60;
proxy_buffer_size 256k;
proxy_buffers 100 256k;
proxy_busy_buffers_size 256k;
proxy_temp_file_write_size 256k;
proxy_next_upstream error timeout invalid_header http_500 http_503 http_404;
proxy_max_temp_file_size 128m;
}
}
修改完上传服务器,使用 nginx -s reload 重新加载