SSL配置

1. 阿里云买证书

2. /etc/httpd/conf     httpd.conf

<VirtualHost *:80>
ServerAdmin denghuachengle@gmail.com
DocumentRoot "/var/www/xxx/xxx_crm/api"
ServerName crmapi.xxx.com
Redirect permanent / https://crmapi.xxx.com/
ErrorLog "logs/crmapi.xxx.com-error.log"
CustomLog "logs/crmapi.xxx.com-access.log" common
</VirtualHost>

3. /etc/httpd/conf.d    ssl.conf

<VirtualHost *:443>
ServerAdmin denghuachengle@gmail.com
DocumentRoot "/var/www/xxx/xxx_service/xxx_filer"
ServerName file.xxx.com

SSLEngine on
SSLCertificateFile /etc/pki/tls/certs/server.crt
SSLCertificateKeyFile /etc/pki/tls/private/xxx_com.key
SSLCertificateChainFile /etc/pki/tls/certs/intermediate.crt

ErrorLog "/var/www/xxx/logs/file.xxx.com.error.log"
CustomLog "/var/www/xxx/logs/file.xxx.com.access.log" combined
</VirtualHost>

 

 

============================这是分割线=====================================

Sathish分享的SSL相关网站

 

 

 

==========================SSL Nginx配置===================================

server {
    listen *:80;
    listen [::]:80;
    server_name crm.domain.com;
    return 301 https://crm.domain.com$request_uri;
}

server
{
	listen *:443 ssl;
	listen [::]:443 ssl;
	ssl_certificate /etc/nginx/ssl/domain/CER-CRT-Files/STAR_domain_com.pem;
	ssl_certificate_key /etc/nginx/ssl/domain/myserver.key;
	ssl_session_timeout 5m;
	ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;
	ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
	ssl_prefer_server_ciphers on;

	server_name crm.domain.com;
	index index.html index.htm index.php default.html;
	root  /var/www/et-prod/crm/et_crm_view;

	location ~ .*\.(gif|jpg|jpeg|png|bmp|swf)$
	{
		expires      30d;
	}

	location ~ .*\.(js|css)?$
	{
		expires      12h;
	}
	location @router {
		rewrite ^.*$ /index.html last;
	}

	error_log  /var/log/nginx/error.crm.domain.com.log;
	access_log /var/log/nginx/access.crm.domain.com.log;

}

  

  • openssl x509 -inform PEM -in ssl.crt > ssl.pem

 

posted @ 2019-02-18 19:06  大漠孤烟~  阅读(464)  评论(0编辑  收藏  举报