nginx https http2
生活随笔
收集整理的這篇文章主要介紹了
nginx https http2
小編覺得挺不錯的,現(xiàn)在分享給大家,幫大家做個參考.
前提條件
1.編譯openssl最新版本
2.生成證書 (本文采用的是let's encrypt的證書)
安裝nginx (本文不討論nginx的性能優(yōu)化)
./configure --prefix=/usr/local/nginx-1.12.0 --with-http_ssl_module --with-http_v2_module --with-openssl=/usr/local/src/openssl-1.1.0e
make -j4
sudo make install
配置文件
server {listen 80;server_name www.panchan.net.cn;return 301 https://$host$request_uri;} server {listen 443 ssl http2;server_name www.panchan.net.cn;ssl_certificate /etc/letsencrypt/live/panchan.net.cn/fullchain.pem;ssl_certificate_key /etc/letsencrypt/live/panchan.net.cn/privkey.pem;ssl_session_timeout 1d;ssl_session_cache shared:SSL:50m;ssl_session_tickets off;ssl_protocols TLSv1.2;ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256';ssl_prefer_server_ciphers on;add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload";ssl_stapling on;ssl_stapling_verify on;ssl_trusted_certificate /etc/letsencrypt/live/panchan.net.cn/chain.pem;resolver 100.100.2.138;location / {root html;index index.html index.htm;}}
測試評
測試報告參
參考資料
http://nginx.org/en/docs/http/ngx_http_ssl_module.html
http://nginx.org/en/docs/http/ngx_http_v2_module.html
http://nginx.org/en/docs/http/configuring_https_servers.html
下次寫一下如何使用let's ecnrypt的ecc證書.
總結(jié)
以上是生活随笔為你收集整理的nginx https http2的全部內(nèi)容,希望文章能夠幫你解決所遇到的問題。
- 上一篇: linux编译libevent
- 下一篇: Docker swarm mode