ssl加密
创建目录
[root@bbc ~]# mkdir /etc/ssl/private
给目录一个用户组的权限
[root@bbc ~]# chmod 700 /etc/ssl/private
生成密钥到文件中
[root@bbc ~]# openssl req -x509 -nodes -days 2 -newkey rsa:2048 -keyout /etc/ssl/private/nginx-selfsigned.key -out /etc/ssl/certs/nginx-selfsigned.crt
Generating a 2048 bit RSA private key
...................+++
...............................+++ #加载中...
**writing new private key to '/etc/ssl/private/nginx-selfsigned.key'
-----**
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
**If you enter '.', the field will be left blank.
-----**
Country Name (2 letter code) [XX]:CN #输入国家
State or Province Na