lemp --------2ssl加密 模拟自签发

 openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout ssl.pem -out ssl.pem

vi /etc/nginx/nginx.conf

server {
listen 443 ssl;
server_name localhost;

ssl_certificate /usr/local/nginx/ssl.pem;
ssl_certificate_key /usr/local/nginx/ssl.pem;

ssl_session_cache shared:SSL:1m;
ssl_session_timeout 5m;

ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;

location / {
root /web2;
index index.html index.htm;
}
}

 

 

 

chmod +x ssl.pem 

systemctl restart nginx.service

 

测试

posted @ 2017-02-08 17:50  *奥特*  阅读(163)  评论(0编辑  收藏  举报