SSL的那些事——三
为IIS和Nginx配置证书
IIS:
1. 服务器证书
2. 导入证书:pfx,需要密码
3. 目标站点,编辑绑定
4. 多证书绑定SNI
Nginx
1. 准备crt,key文件,放置到server的某个文件夹中
2. NGINX 配置文件
server {
listen 443;
server_name sample.com;
ssl on;
ssl_certificate /etc/nginx/ssl/sample.com.crt;
ssl_certificate_key /etc/nginx/ssl/sample.com.key;
}
证书转换:
openssl pkcs12 -in [yourfile.pfx] -nocerts -out [keyfile-encrypted.key]
- need to type in the importpassword of the .pfx file.
- need to type a new password will protect your .key file
openssl pkcs12 -in [yourfile.pfx] -clcerts -nokeys -out [certificate.crt]
openssl rsa -in [keyfile-encrypted.key] -out [keyfile-decrypted.key]
crt, key -> pfx
openssl pkcs12 -export -out domain.name.pfx -inkey domain.name.key -in domain.name.crt
openssl pkcs12 -export -out domain.name.pfx -inkey domain.name.key -in domain.name.crt -in intermediate.crt -in rootca.crt
pfx -> crt, key
Convert the .pfx file using OpenSSL
After you have exported the certificate from the Windows server you will need to extract all the individual certificates and private key from the .pfx file using OpenSSL (instead of using OpenSSL, you can use the SSL Converter to convert the .pfx file to a .pem file and then follow step 3).
Copy the .pfx file to the server or another computer that has OpenSSL installed.
Run this OpenSSL command to create a text file with the contents of the .pfx file:
openssl pkcs12 -in mydomain.pfx -out mydomain.txt -nodes
Open the mydomain.txt file that the command created in a text editor. Copy each certificate/private key to its own text file including the "
-----BEGIN RSA PRIVATE KEY-----"
and "
-----BEGIN CERTIFICATE-----
" headers. Save them with names such as mydomain.key, mydomain.crt, intermediateCA.crt, etc.
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· go语言实现终端里的倒计时
· 如何编写易于单元测试的代码
· 10年+ .NET Coder 心语,封装的思维:从隐藏、稳定开始理解其本质意义
· .NET Core 中如何实现缓存的预热?
· 从 HTTP 原因短语缺失研究 HTTP/2 和 HTTP/3 的设计差异
· 周边上新:园子的第一款马克杯温暖上架
· 分享 3 个 .NET 开源的文件压缩处理库,助力快速实现文件压缩解压功能!
· Ollama——大语言模型本地部署的极速利器
· DeepSeek如何颠覆传统软件测试?测试工程师会被淘汰吗?
· 使用C#创建一个MCP客户端