Nginx·´ÏòÊðÀíHTTPSÉèÖ㬼ÓÃÜÍøÕ¾´«Êä
nginx·´ÏòÊðÀíhttpsÉèÖ㬼ÓÃÜÍøÕ¾´«Êä
Ëæ×Å»¥ÁªÍøµÄ¿ìËÙÉú³¤£¬Êý¾Ý´«ÊäÀú³ÌÖеÄÇå¾²ÐÔ±äµÃÔ½À´Ô½Ö÷Òª¡£ÎªÁ˱£»¤Óû§µÄÒþ˽ºÍÊý¾ÝÇå¾²£¬¶ÔÍøÕ¾µÄ´«Êä¾ÙÐмÓÃÜÒѳÉΪһ¸öÐëÒªµÄÊֶΡ£Ê¹ÓÃHTTPSÐÒéÄܹ»ÊµÏÖÊý¾Ý´«ÊäµÄ¼ÓÃÜ£¬°ü¹ÜÍøÕ¾µÄÇå¾²ÐÔ¡£¶øNginx×÷Ϊһ¸ö¸ßÐÔÄܵÄWebЧÀÍÆ÷£¬¿ÉÒÔͨ¹ý·´ÏòÊðÀíµÄ·½·¨À´ÊµÏÖ¶ÔHTTPSÍøÕ¾µÄÉèÖá£
ÏÂÃæÎÒÃÇÀ´ÏêϸÏÈÈÝÒ»ÏÂNginx·´ÏòÊðÀíHTTPSµÄÉèÖÃÒªÁì¼°´úÂëʾÀý¡£
°ì·¨Ò»£º×¼±¸SSLÖ¤Êé
ÔÚÉèÖÃHTTPSÇ°£¬ÎÒÃÇÐèÒªÏÈ×¼±¸Ò»¸öSSLÖ¤Êé¡£¿ÉÒÔͨ¹ý¹ºÖÃÉÌÒµÖ¤Ê飬»òÊÇʹÓÃÃâ·ÑµÄÖ¤Êé»ú¹¹ÈçLet’s EncryptÀ´»ñÈ¡Ò»¸öSSLÖ¤Êé¡£
°ì·¨¶þ£º×°ÖúÍÉèÖÃNginx
Ê×ÏÈ£¬È·±£ÒѾװÖÃÁËNginx¡£¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁîÀ´×°Öãº
# Ubuntu sudo apt-get install nginx # CentOS sudo yum install nginx
µÇ¼ºó¸´ÖÆ
×°ÖÃÍê³Éºó£¬ÎÒÃÇÐèÒª·¿ªNginxÉèÖÃÎļþ£¬Í¨³£Î»ÓÚ/etc/nginx/nginx.conf¡£ÔÚhttpÄ£¿éÏÂÌí¼ÓÒÔÏÂÄÚÈÝ£º
http { ... # ÊðÀíЧÀÍÆ÷µÄ×î´óÅþÁ¬Êý proxy_connect_timeout 600; # ·´ÏòÊðÀí»º´æµÄʱ¼ä proxy_cache_valid 200 302 1h; # ·´ÏòÊðÀí»º´æµÄ×î´ó×Ö½ÚÊý proxy_cache_max_size 5m; # ·´ÏòÊðÀí»º´æµÄ·¾¶ proxy_cache_path /var/cache/nginx levels=1:2 keys_zone=my_cache:10m max_size=10g inactive=60m use_temp_path=off; ... }
µÇ¼ºó¸´ÖÆ
°ì·¨Èý£ºÉèÖ÷´ÏòÊðÀí
ÔÚÉèÖÃÎļþÖУ¬ÎÒÃÇÐèҪΪ·´ÏòÊðÀíÉèÖÃÒ»¸ölocation¿é¡£ÔڸÿéÖУ¬ÎÒÃǽ«Ö¸¶¨ÊðÀíЧÀÍÆ÷µÄµØµã¡¢¶Ë¿ÚºÍSSLÖ¤ÊéµÄ·¾¶¡£
server { listen 80; server_name yourdomain.com; # Öض¨ÏòHTTPÇëÇóµ½HTTPS return 301 https://$server_name$request_uri; } # HTTPSÉèÖà server { listen 443 ssl; server_name yourdomain.com; # SSLÖ¤ÊéµÄ·¾¶ºÍÃÜÔ¿ ssl_certificate /path/to/ssl_certificate.crt; ssl_certificate_key /path/to/ssl_certificate.key; # ·´ÏòÊðÀíÉèÖà location / { proxy_pass https://backend_server; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } }
µÇ¼ºó¸´ÖÆ
°ì·¨ËÄ£ºÖØмÓÔØÉèÖÃÎļþ
Íê³ÉÒÔÉÏÉèÖúó£¬ÎÒÃÇÐèÒªÖØмÓÔØNginxµÄÉèÖÃÎļþ¡£
sudo nginx -s reload
µÇ¼ºó¸´ÖÆ
ÖÁ´Ë£¬Nginx·´ÏòÊðÀíHTTPSµÄÉèÖþÍÍê³ÉÁË¡£
×ܽá
ͨ¹ýNginx·´ÏòÊðÀíHTTPSµÄÉèÖã¬ÎÒÃÇ¿ÉÒÔʵÏÖÍøÕ¾´«ÊäµÄ¼ÓÃÜ£¬°ü¹ÜÊý¾ÝµÄÇå¾²ÐÔ¡£Í¬Ê±£¬NginxµÄ¸ßÐÔÄÜÌØÕ÷Ò²Äܹ»°ü¹ÜÍøÕ¾µÄ»á¼ûËÙÂÊ¡£
Ï£ÍûÒÔÉϵĴúÂëʾÀýºÍÉèÖÃ˵Ã÷Äܹ»¶ÔÄãÓÐËù×ÊÖú£¬ÈôÓÐÎÊÌ⣬ÇëËæʱÏòÎÒÃÇÌáÎÊ¡£×£ÄãÔÚNginx·´ÏòÊðÀíHTTPSµÄÉèÖÃÀú³ÌÖÐ˳Ëì¾ÙÐУ¡
ÒÔÉϾÍÊÇNginx·´ÏòÊðÀíHTTPSÉèÖ㬼ÓÃÜÍøÕ¾´«ÊäµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡