官术网_书友最值得收藏!

  • NGINX Cookbook
  • Tim Butler
  • 119字
  • 2021-07-03 00:04:33

How to do it...

Now that we have a certificate and private key, we can update our NGINX configuration to serve SSL-based sites. Here's our NGINX server directive block:

server { 
    listen              443 ssl; 
    server_name         ssl.nginxcookbook.com; 
    ssl_certificate     /etc/ssl/public.pem; 
    ssl_certificate_key /etc/ssl/private.key; 
    ssl_protocols       TLSv1 TLSv1.1 TLSv1.2; 
    ssl_ciphers         HIGH:!aNULL:!MD5; 
 
    access_log  /var/log/nginx/ssl-access.log  combined; 
 
    location  /favicon.ico { access_log off; log_not_found off; } 
    root  /var/www; 
} 

If you have a basic index.html or similar in /var/www, you should see something like the following:

The error message will vary between browsers, but they're all simply letting you know that the certificate presented couldn't be validated and therefore can't be intrinsically trusted. For testing, add an exception here; you should see the SSL site served by NGINX:

主站蜘蛛池模板: 蒙城县| 渝中区| 绥江县| 信宜市| 漯河市| 开化县| 平遥县| 新闻| 筠连县| 固始县| 调兵山市| 和政县| 峨眉山市| 巫山县| 垦利县| 越西县| 海门市| 英德市| 木兰县| 孝感市| 离岛区| 成安县| 苍山县| 象州县| 大同县| 龙门县| 开鲁县| 太和县| 美姑县| 成安县| 广汉市| 广南县| 清涧县| 惠州市| 东源县| 福州市| 邹城市| 揭西县| 伊川县| 当阳市| 黑河市|