Centos Nginx SSL 配置

Nginx 配置 SSL

1.下载SSL证书

.crt 和 .key文件

2.创建和上传证书

bash 复制代码
mkdir -p /etc/nginx/cert
上传证书

3.nginx.conf配置

bash 复制代码
# For more information on configuration, see:
#   * Official English Documentation: http://nginx.org/en/docs/
#   * Official Russian Documentation: http://nginx.org/ru/docs/

user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log;
pid /run/nginx.pid;

# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic.
include /usr/share/nginx/modules/*.conf;

events {
    worker_connections 1024;
}

http {
    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';

    access_log  /var/log/nginx/access.log  main;

    sendfile            on;
    tcp_nopush          on;
    tcp_nodelay         on;
    keepalive_timeout   65;
    types_hash_max_size 4096;

    include             /etc/nginx/mime.types;
    default_type        application/octet-stream;
    
    include /etc/nginx/conf.d/*.conf;
    
    server {
	listen 80;
        server_name baiduX.com www.baiduX.com;
        return 301 https://$server_name$request_uri;  
    }

    server {

 	listen 443 ssl;
        server_name meteor;
        # 证书配置
        ssl_certificate /etc/nginx/cert/server.crt;
        ssl_certificate_key /etc/nginx/cert/server.key;
        ssl_session_cache shared:sslcache:20m;
        ssl_session_timeout 10m;

        error_page 497 301 =307 https://$host:$server_port$request_uri;

        location / {
            root /mnt/data/meteor/html;
            index index.html index.htm;
			try_files $uri $uri/ /index.html;
        }
	   location /Galaxys/ {

			proxy_pass http://127.0.0.1:6012/Galaxys/;
			proxy_set_header X-Forwarded-Proto $scheme;
			proxy_set_header X-Forwarded-Host  $host;
			proxy_set_header X-Forwarded-Port 6012;
			proxy_set_header Host $host:6012;
			proxy_set_header X-Real-IP $remote_addr;
			proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
			proxy_http_version 1.1;
			proxy_set_header Upgrade $http_upgrade;
			proxy_set_header Connection "Upgrade";
			access_log off;
			client_max_body_size 1024m;
        }
		
        error_page   500 502 503 504  /50x.html;
        location = /50x.html {
            root   html;
        }
    }

    server {
        listen 3461 ssl;
        server_name baudu;
        ssl_certificate /etc/nginx/cert/server.crt;
        ssl_certificate_key /etc/nginx/cert/server.key;
        ssl_session_cache shared:sslcache:20m;
        ssl_session_timeout 10m;

        location / {
            root   /mnt/data/comet/dist;
            index  index.html index.htm;
			try_files $uri $uri/ /index.html;
        }

        location /Galaxys/ {
			proxy_pass http://127.0.0.1:6905/Galaxys/;
               }
    }
    
    server {
        listen 4901 ssl;
        server_name dure;
        ssl_certificate /etc/nginx/cert/server.crt;
        ssl_certificate_key /etc/nginx/cert/server.key;
        ssl_session_cache shared:sslcache:20m;
        ssl_session_timeout 10m;

        location / {
            root   /mnt/data/stellar/dist;
            index  index.html index.htm;
            try_files $uri $uri/ /index.html;
        }

		location /Galaxys/ {
           proxy_pass https://www.uyi.com/Galaxys/;
		}
    } 

    server {
        listen 8901 ssl;
        server_name supplier;
        ssl_certificate /etc/nginx/cert/server.crt;
        ssl_certificate_key /etc/nginx/cert/server.key;
        ssl_session_cache shared:sslcache:20m;
        ssl_session_timeout 10m;

        location / {
            root   /mnt/data/supplier/dist-dev;
            index  index.html index.htm;
            try_files $uri $uri/ /index.html;
        }

		location /Galaxys/ {
           proxy_pass https://iop.com/Galaxys/;
		}
    }
    
    server {
        listen 8718 ssl;
        server_name byu;
        ssl_certificate /etc/nginx/cert/server.crt;
        ssl_certificate_key /etc/nginx/cert/server.key;
        ssl_session_cache shared:sslcache:20m;
        ssl_session_timeout 10m;

        client_max_body_size 1280m;
		proxy_read_timeout 600;

        error_page 497 301 =307 https://$host:$server_port$request_uri;

		location / {
			proxy_pass http://127.0.0.1:8010;
			proxy_set_header X-Forwarded-Proto $scheme;
			proxy_set_header X-Forwarded-Host  $host;
			proxy_set_header X-Forwarded-Port 8011;
			proxy_set_header Host $host:8011;
			proxy_set_header X-Real-IP $remote_addr;
			proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
			proxy_http_version 1.1;
			proxy_set_header Upgrade $http_upgrade;
			proxy_set_header Connection "Upgrade";
			access_log off;

		}
		# You may need this to prevent return 404 recursion.
		location = /404.html {
				internal;
		}
    }
}
bash 复制代码
cd /etc/nginx
service nginx restart
或
systemctl restart nginx.service
相关推荐
枕布响丸辣7 分钟前
万字详解 GlusterFS 分布式文件系统:原理 + 卷类型 + CentOS 7 集群部署
linux·运维·centos
拄杖忙学轻声码20 分钟前
Linux平台 CentOS、Ubuntu、Debian 系统安装 docker compose
ubuntu·docker·centos
书生执笔画浮沉13 小时前
rpmrebuild
linux·centos·rpm
七七powerful15 小时前
loki监控docker容器&系统&nginx日志的告警规则
nginx·docker·容器
云动课堂18 小时前
【运维实战】企业级VSFTPD 文件服务 · 一键自动化部署方案 (适配银河麒麟 V10 /openEuler /CentOS)
运维·centos·自动化
杨云龙UP18 小时前
2000—CentOS Linux 7上部署Oracle 19c(19.3) RAC(RedHat/CentOS 7/8)
linux·运维·服务器·数据库·oracle·centos
dovens18 小时前
httpslocalhostindex 配置的nginx,一刷新就报404了
运维·nginx
PinTrust SSL证书19 小时前
Sectigo(Comodo)企业型OV通配符SSL
网络·网络协议·网络安全·小程序·https·ssl
riNt PTIP20 小时前
Ubuntu 系统下安装 Nginx
数据库·nginx·ubuntu
oLLI PILO21 小时前
Ubuntu介绍、与centos的区别、基于VMware安装Ubuntu Server 22.04、配置远程连接、安装jdk+Tomcat
java·ubuntu·centos