命令:vi /usr/local/nginx/conf/nginx.conf,编辑nginx.conf文件,添加以下代码:
server {
listen 443;
server_name www.xxx.com;
ssl on;
ssl_certificate ./cert/2573734_www.xxx.com.pem;
ssl_certificate_key ./cert/2573734_www.xxx.com.key;
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 5m;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
location / {
root html;
index index.html index.htm;
proxy_pass http://127.0.0.1:18080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
}
server{
listen 80;
server_name www.xxx.com;
rewrite ^(.*)$ https://$host$1 permanent;
}
其中,SSL证书放在conf文件夹下的cert文件夹里面