CentOS7 配置Nginx域名HTTPS

Configuring Nginx with HTTPS on CentOS 7 involves similar steps to the ones for Ubuntu, but with some variations in package management and service control. Here's a step-by-step guide for CentOS 7:

Prerequisites

  1. Domain Name : "www.xxx.com"
  2. Nginx Installed: Ensure Nginx is installed.
  3. Domain DNS: Domain should point to your server's IP address.
  4. Root Privileges : You should have root or sudo privileges.

Step-by-Step Guide

1. Install Nginx

If Nginx is not already installed, you can install it using the following commands:

sh 复制代码
sudo yum install epel-release
sudo yum install nginx

Start and enable Nginx to start on boot:

sh 复制代码
sudo systemctl start nginx
sudo systemctl enable nginx
2. Configure Firewall

Allow HTTPS traffic through your firewall:

sh 复制代码
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
3. Obtain SSL Certificate

Install Certbot and the Nginx plugin:

sh 复制代码
sudo yum install certbot python2-certbot-nginx
4. Request SSL Certificate

Run Certbot to obtain and install the SSL certificate:

sh 复制代码
sudo certbot --nginx -d www.xxx.com

Follow the prompts to complete the process. Certbot will automatically configure Nginx to use the SSL certificate.

5. Verify Nginx Configuration

Open your Nginx configuration file to verify or manually configure the SSL settings:

sh 复制代码
sudo vim /etc/nginx/conf.d/www.xxx.com.conf

Ensure your server block looks like this:

nginx 复制代码
server {
    listen 80;
    listen [::]:80;
    server_name www.xxx.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl;
    listen [::]:443 ssl;
    server_name www.xxx.com;

    ssl_certificate /etc/letsencrypt/live/www.xxx.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/www.xxx.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;

    root /usr/share/nginx/html;
    index index.html index.htm;

    location / {
        try_files $uri $uri/ =404;
    }
}
6. Test Nginx Configuration

Test your configuration to ensure there are no syntax errors:

sh 复制代码
sudo nginx -t

If the test is successful, reload Nginx:

sh 复制代码
sudo systemctl reload nginx
7. Set Up Automatic Certificate Renewal

Let's Encrypt certificates are valid for 90 days. Certbot can handle renewal automatically. To set up a cron job for automatic renewal, open the crontab editor:

sh 复制代码
sudo crontab -e

Add the following line to the crontab file:

sh 复制代码
0 0,12 * * * /usr/bin/certbot renew --quiet

This runs the renewal command twice daily.

Access Your Site

Now, you should be able to access your site securely at https://www.xxx.com.

Troubleshooting

If you encounter any issues, check the Nginx and Certbot logs for more information:

sh 复制代码
sudo tail -f /var/log/nginx/error.log
sudo tail -f /var/log/letsencrypt/letsencrypt.log

This setup ensures that your website is served over HTTPS, providing security and trust to your visitors.

相关推荐
wdfk_prog8 分钟前
Wi-Fi Direct 源码分析(11):P2P-GROUP-STARTED 之后——Group Interface、IP 配置与真实数据通路
运维·服务器·网络协议·tcp/ip·asp.net·p2p·wifi-direct
MicrosoftCloud15 分钟前
用户权限 02|/etc/passwd、/etc/shadow、/etc/group:三个文件讲透 Linux 用户体系
linux·运维·ubuntu·用户管理·权限·useradd
天远API17 分钟前
零信任架构实战:基于天远人车核验加强版构建自动化商用车承保核验网关
运维·人工智能·架构·自动化
崽崽..20 分钟前
【Linux】ping命令刨析
linux·运维·服务器·网络
张小姐的猫41 分钟前
【Linux】网络编程 —— 五种IO模型
linux·运维·服务器·网络·c++·人工智能·php
程序员-Benothing42 分钟前
Shell脚本调试与最佳实践:set -eux、shellcheck实战
linux·运维·服务器
海宇AI1 小时前
零信任架构实战:基于海宇活体识别V步骤1构建自动化直播开播鉴权网关
运维·人工智能·架构·自动化
ZeroNews内网穿透1 小时前
企业内网穿透安全避坑:路由白名单,解决整站映射带来的接口泄露风险
运维·内网穿透·api安全·zeronews·企业网络安全·运维实践
Wang's Blog1 小时前
Java 项目实战: 外卖平台优化-Nginx常用命令与环境变量配置
java·网络·nginx
苦瓜不会码代码1 小时前
负载均衡会话保持-扩容后登录掉线踩坑
运维·负载均衡