官术网_书友最值得收藏!

Setting HTTPs on Nginx

In this recipe, we will learn how to enable HTTPs communication on the Nginx server.

Getting ready

You will need access to a root account or an account with sudo privileges.

How to do it…

Follow these steps to set HTTPs on Nginx:

  1. Obtain a certificate and the related keys from a certification authority or create a self-signed certificate. To create a self-signed certificate, refer to the Securing web traffic with HTTPS recipe in this chapter.
  2. Create a directory to hold all certificate and keys:
    $ sudo mkdir -p /etc/nginx/ssl/example.com
    
  3. Move the certificate and keys to the preceding directory. Choose any secure method, such as SCP, SFTP, or any other.
  4. Create a virtual host entry or edit it if you already have one:
    $ sudo nano /etc/nginx/sites-available/example.com
    
  5. Match your virtual host configuration with the following:
    server {
     listen 80;
     server_name example.com www.example.com;
     return 301 https://$host$request_uri;
    }
    server {
     listen 443 ssl;
     server_name example.com www.example.com;
    
     
    root /var/www/example.com/public_html;
     index index.php index.html index.htm;
    
     ssl on;
     ssl_certificate /etc/nginx/ssl/example.com/server.crt;
     ssl_certificate_key /etc/nginx/ssl/example.com/server.key;
     # if you have received ca-certs.pem from Certification Authority
     #ssl_trusted_certificate /etc/nginx/ssl/example.com/ca-certs.pem;
    
     ssl_session_cache shared:SSL:10m;
     ssl_session_timeout 5m;
     keepalive_timeout 70;
    
     
    ssl_ciphers "HIGH:!aNULL:!MD5 or HIGH:!aNULL:!MD5:!3DES";
     ssl_prefer_server_ciphers on;
     ssl_protocols TLSv1.2 TLSv1.1 TLSv1;
     add_header Strict-Transport-Security "max-age=31536000";
    
     location / {
     try_files $uri $uri/ /index.php;
     }
    
     location ~ \.php$ {
     include fastcgi_params;
     fastcgi_pass unix:/var/run/php/php7.0-fpm.sock;
     
    }
    }
    
  6. Enable this configuration by creating a symbolic link to it under sites-enabled:
    $ sudo ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/example.com
    
  7. Check the configuration for syntax errors:
    $ sudo nginx -t
    
  8. Reload Nginx for the changes to take effect:
    $ sudo service nginx reload
    
  9. Open your browser and access the site with domain or IP with HTTPS.

How it works…

When you know some basic configuration parameters, Nginx is quite simple to set up. Here, we have taken a few SSL settings from the default configuration file and added a simple redirection rule to redirect non-HTTPs traffic on port 80 to port 443. The first server block takes care of the redirection.

In addition to specifying the server certificate and keys, we have enabled session resumption by setting the cache to be shared across the Nginx process. We also have a timeout value of 5 minutes.

All other settings are common to the Nginx setup. We have allowed the virtual host to match with example.com, as well as www.example.com. We have set the index to search index.php, followed by index.html and others. With location directives, we have set Nginx to search for files and directories before forwarding the request to a PHP processor. Note that if you create a self-signed certificate, you will notice your browser complaining about invalid certification authority.

See also

主站蜘蛛池模板: 霍山县| 迭部县| 芒康县| 乌审旗| 博罗县| 安化县| 曲松县| 河东区| 肃南| 宜兰市| 社会| 霍州市| 登封市| 磐石市| 娄烦县| 潮州市| 栾川县| 灵石县| 建瓯市| 崇文区| 茌平县| 龙门县| 封开县| 塔城市| 明星| 连山| 微博| 三都| 柏乡县| 肥乡县| 安国市| 合江县| 东乡县| 高邮市| 土默特右旗| 武汉市| 扎囊县| 阿拉善左旗| 吉安市| 和龙市| 易门县|