1. 阿里云数字证书管理服务 -》SSL 证书管理 -》个人测试证书(原免费证书)-》查找相应域名的证书/新建证书,申请 -》下载证书,如果是ngnix服务器,就下载pem/key格式
2.远程连接服务器
a.nginx -t :查看ngnix 配置文件在哪里
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: configuration file /etc/nginx/nginx.conf test is successful
b.cd /etc/nginx/nginx.conf,
server {
listen 443 ssl;
#ssl on;
server_name qbjandbj. luckprint.com;
ssl_certificate /etc/nginx/cert/qbjandbj. luckprint.com.pem;
ssl_certificate_key /etc/nginx/cert/qbjandbj . luckprint.com.key;
ssl_session_timeout 5m;
ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256: ECDHE: ECDH:AES:HIGH: !NULL: !aNULL: !MD5: !ADH: !RC4;
ssl_protocols TLSv1.2 TLSv1;
ssl_prefer_server_ciphers on;
location / {
proxy_pass http://127.0.0.1:6050;
proxy_buffer_size 2048k;
proxy_buffers 16 2048k;
proxy_busy_buffers_size 4096k;
proxy_temp_file_write_size 4096k;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
client_max_body_size 10000m;
proxy_read_timeout 3000; # 秒
}
}
c. 替换下载的 pem/key 到 /etc/nginx/cert/qbjandbj. luckprint.com.pem; /etc/nginx/cert/qbjandbj . luckprint.com.key;