本地https ssl key生成 及Nginx配置

版权声明:本文为博主原创文章,未经博主允许不得转载。 https://blog.csdn.net/dujianxiong/article/details/88251784
openssl genrsa -des3 -out vulcan.key 1024 

最重要的是填common Name为域名

openssl req -new -key vulcan.key -out vulcan.csr  


copy vulcan.key vulcan.key.org

openssl rsa -in vulcan.key.org -out vulcan.key  

openssl x509 -req -days 36500 -in vulcan.csr -signkey vulcan.key -out vulcan.crt 

Nginx配置

server {
        listen       8098 ssl;
        server_name    xxxx.xxx.com;
    
        ssl_certificate      /usr/local/nginx/sslKey/vulcan/vulcan.crt;
        ssl_certificate_key  /usr/local/nginx/sslKey/vulcan/vulcan.key;
    
        ssl_session_cache    shared:SSL:1m;
        ssl_session_timeout  5m;
    
        ssl_ciphers  HIGH:!aNULL:!MD5;
        ssl_prefer_server_ciphers  on;
    
        
        location /info-api-m {
               proxy_pass  http://zkyjsm;
 
				#Proxy Settings
				proxy_redirect     off;
				proxy_set_header   Host             $host;
				proxy_set_header   X-Real-IP        $remote_addr;
				proxy_set_header   X-Forwarded-For  $proxy_add_x_forwarded_for;               
        }
    }
	

猜你喜欢

转载自blog.csdn.net/dujianxiong/article/details/88251784
今日推荐