Centos Nginx SSL 配置

Nginx 配置 SSL

1.下载SSL证书

.crt 和 .key文件

2.创建和上传证书

bash 复制代码
mkdir -p /etc/nginx/cert
上传证书

3.nginx.conf配置

bash 复制代码
# For more information on configuration, see:
#   * Official English Documentation: http://nginx.org/en/docs/
#   * Official Russian Documentation: http://nginx.org/ru/docs/

user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log;
pid /run/nginx.pid;

# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic.
include /usr/share/nginx/modules/*.conf;

events {
    worker_connections 1024;
}

http {
    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';

    access_log  /var/log/nginx/access.log  main;

    sendfile            on;
    tcp_nopush          on;
    tcp_nodelay         on;
    keepalive_timeout   65;
    types_hash_max_size 4096;

    include             /etc/nginx/mime.types;
    default_type        application/octet-stream;
    
    include /etc/nginx/conf.d/*.conf;
    
    server {
	listen 80;
        server_name baiduX.com www.baiduX.com;
        return 301 https://$server_name$request_uri;  
    }

    server {

 	listen 443 ssl;
        server_name meteor;
        # 证书配置
        ssl_certificate /etc/nginx/cert/server.crt;
        ssl_certificate_key /etc/nginx/cert/server.key;
        ssl_session_cache shared:sslcache:20m;
        ssl_session_timeout 10m;

        error_page 497 301 =307 https://$host:$server_port$request_uri;

        location / {
            root /mnt/data/meteor/html;
            index index.html index.htm;
			try_files $uri $uri/ /index.html;
        }
	   location /Galaxys/ {

			proxy_pass http://127.0.0.1:6012/Galaxys/;
			proxy_set_header X-Forwarded-Proto $scheme;
			proxy_set_header X-Forwarded-Host  $host;
			proxy_set_header X-Forwarded-Port 6012;
			proxy_set_header Host $host:6012;
			proxy_set_header X-Real-IP $remote_addr;
			proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
			proxy_http_version 1.1;
			proxy_set_header Upgrade $http_upgrade;
			proxy_set_header Connection "Upgrade";
			access_log off;
			client_max_body_size 1024m;
        }
		
        error_page   500 502 503 504  /50x.html;
        location = /50x.html {
            root   html;
        }
    }

    server {
        listen 3461 ssl;
        server_name baudu;
        ssl_certificate /etc/nginx/cert/server.crt;
        ssl_certificate_key /etc/nginx/cert/server.key;
        ssl_session_cache shared:sslcache:20m;
        ssl_session_timeout 10m;

        location / {
            root   /mnt/data/comet/dist;
            index  index.html index.htm;
			try_files $uri $uri/ /index.html;
        }

        location /Galaxys/ {
			proxy_pass http://127.0.0.1:6905/Galaxys/;
               }
    }
    
    server {
        listen 4901 ssl;
        server_name dure;
        ssl_certificate /etc/nginx/cert/server.crt;
        ssl_certificate_key /etc/nginx/cert/server.key;
        ssl_session_cache shared:sslcache:20m;
        ssl_session_timeout 10m;

        location / {
            root   /mnt/data/stellar/dist;
            index  index.html index.htm;
            try_files $uri $uri/ /index.html;
        }

		location /Galaxys/ {
           proxy_pass https://www.uyi.com/Galaxys/;
		}
    } 

    server {
        listen 8901 ssl;
        server_name supplier;
        ssl_certificate /etc/nginx/cert/server.crt;
        ssl_certificate_key /etc/nginx/cert/server.key;
        ssl_session_cache shared:sslcache:20m;
        ssl_session_timeout 10m;

        location / {
            root   /mnt/data/supplier/dist-dev;
            index  index.html index.htm;
            try_files $uri $uri/ /index.html;
        }

		location /Galaxys/ {
           proxy_pass https://iop.com/Galaxys/;
		}
    }
    
    server {
        listen 8718 ssl;
        server_name byu;
        ssl_certificate /etc/nginx/cert/server.crt;
        ssl_certificate_key /etc/nginx/cert/server.key;
        ssl_session_cache shared:sslcache:20m;
        ssl_session_timeout 10m;

        client_max_body_size 1280m;
		proxy_read_timeout 600;

        error_page 497 301 =307 https://$host:$server_port$request_uri;

		location / {
			proxy_pass http://127.0.0.1:8010;
			proxy_set_header X-Forwarded-Proto $scheme;
			proxy_set_header X-Forwarded-Host  $host;
			proxy_set_header X-Forwarded-Port 8011;
			proxy_set_header Host $host:8011;
			proxy_set_header X-Real-IP $remote_addr;
			proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
			proxy_http_version 1.1;
			proxy_set_header Upgrade $http_upgrade;
			proxy_set_header Connection "Upgrade";
			access_log off;

		}
		# You may need this to prevent return 404 recursion.
		location = /404.html {
				internal;
		}
    }
}
bash 复制代码
cd /etc/nginx
service nginx restart
或
systemctl restart nginx.service
相关推荐
IT曙光4 小时前
在华为TaiShan 200系列服务器基于CentOS 7.6/7.7创建虚拟机
运维·服务器·centos
代码一天不写我浑森蓝廋4 小时前
CentOS7 使用 centos-release-scl-rh yum库安装 devtoolset
linux·centos·gcc·devtoolset
摇滚侠8 小时前
Nginx 与 F5 负载均衡的区别
nginx·负载均衡
微小冷9 小时前
WireShark抓包http,解密https
http·https·edge·wireshark·ssl·解密
普普通通的南瓜10 小时前
《国家安全法》下的 SSL 证书定位:网络数据加密的 “法定基石”
网络·php·ssl
问道飞鱼10 小时前
【知识科普】完整的 SSL 证书文件体系
网络协议·https·证书·ssl
春生野草14 小时前
腾讯云部署gitlab
运维·centos·gitlab
huangql52015 小时前
Nginx 从零到精通 - 最详细的循序渐进教程
开发语言·网络·nginx
苦逼IT运维15 小时前
Kubernetes 双层 Nginx 容器环境下的 CORS 问题及解决方案(极端情况)
运维·nginx·容器·kubernetes·jenkins·运维开发·ci
cqwuliu15 小时前
通过nginx+openssl自签名证书部署https应用并解决不安全问题
nginx·安全·https