目标:
1. 对域名tpl01.liang.com的站点进行SSL加密
步骤一: 修改配置文件(tpl01)
vim /usr/local/nginx/conf/nginx.conf
......
server {
listen 443 ssl;
server_name tpl01.liang.com;
ssl on;
ssl_certificate cert.pem;
ssl_certificate_key cert.key;
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 5m;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
location / {
root www;
index index.html index.htm;
}
}
2. 生成私钥与证书
openssl genrsa -out cert.key 2048
openssl req -new -x509 -key cert.key -out cert.pem
cp {cert.key,cert.pem} /usr/local/nginx/conf
3. 创建网站根目录机对应首页文件
mkdir /usr/local/nginx/{www,bbs}
echo "www" > /usr/local/nginx/www/index.html
4. 重启nginx服务
/usr/local/nginx/sbin/nginx -s stop
/usr/local/nginx/sbin/nginx
步骤二: 客户端测试(work)
1.修改/etc/hosts文件
192.168.29.150 tpl01.liang.com
2.
浏览器输入 https://tpl01.liang.com