nginx 配置https

公司需要配置https站点

yum install openssl openssl-devel

[root@hadoop conf]# openssl genrsa -des3 -out 33iq.key 1024

Generating RSA private key, 1024 bit long modulus
...++++++
..............++++++
e is 65537 (0x10001)
Enter pass phrase for 33iq.key:
Verifying - Enter pass phrase for 33iq.key:
[root@hadoop conf]# openssl req -new -key 33iq.key -out 33iq.csr
Enter pass phrase for 33iq.key:
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [XX]:CN
State or Province Name (full name) []:Shanghai
Locality Name (eg, city) [Default City]:Shanghai
Organization Name (eg, company) [Default Company Ltd]:Shanghai Chuangji Information Technology Ltd
Organizational Unit Name (eg, section) []:33IQ
Common Name (eg, your name or your server's hostname) []:*.33iq.com
Email Address []:admin@33iq.com


Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
[root@hadoop conf]# rsa -in 33iq.key -out 33iq_nopass.key
-bash: rsa: command not found
[root@hadoop conf]# openssl rsa -in 33iq.key -out 33iq_nopass.key
Enter pass phrase for 33iq.key:
writing RSA key
[root@hadoop conf]# openssl x509 -req -days 365 -in 33iq.csr -signkey 33iq.key -out 33iq.crt
Signature ok
subject=/C=CN/ST=Shanghai/L=Shanghai/O=Shanghai Chuangji Information Technology Ltd/OU=33IQ/CN=*.33iq.com/emailAddress=admin@33iq.com
Getting Private key
Enter pass phrase for 33iq.key:

[root@hadoop conf]# vi servers/ssl.market.gsie.cn

server
{
    server_name ssl.test.cn;
        listen 443;
        ssl on;
    index index.html index.htm index.php;
    root  /data_disk1/webdata/ssl;


ssl_certificate  /data_disk1/webserver/nginx/conf/33iq.crt;
    ssl_certificate_key  /data_disk1/webserver/nginx/conf/33iq_nopass.key;
}

重启Nginx后即可通过https访问网站了。

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值