陈程的技术博客

  • 关于作者
全栈软件工程师
一个专注于技术研究创新的程序员
  1. 首页
  2. linux
  3. 正文

nginx部署SSL证书和二级域名

2019年11月1日 648点热度 0人点赞 0条评论

# For more information on configuration, see:
#   * Official English Documentation: http://nginx.org/en/docs/
#   * Official Russian Documentation: http://nginx.org/ru/docs/

user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log;
pid /run/nginx.pid;

# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic.
include /usr/share/nginx/modules/*.conf;

events {
    worker_connections 1024;
}

http {
    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';

    access_log  /var/log/nginx/access.log  main;

    sendfile            on;
    tcp_nopush          on;
    tcp_nodelay         on;
    keepalive_timeout   65;
    types_hash_max_size 2048;

    include             /etc/nginx/mime.types;
    default_type        application/octet-stream;

    # Load modular configuration files from the /etc/nginx/conf.d directory.
    # See http://nginx.org/en/docs/ngx_core_module.html#include
    # for more information.
    include /etc/nginx/conf.d/*.conf;
server {
    listen        80;
    listen 443 ssl;
    server_name   pusuaninfo.com;
    ssl_certificate ssl.conf/1_www.pusuaninfo.com_bundle.crt; 
    ssl_certificate_key ssl.conf/2_www.pusuaninfo.com.key; 
    ssl_session_timeout 5m;
    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
    ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE;
    ssl_prefer_server_ciphers on;

    location / {
        proxy_pass         http://localhost:5000;
        proxy_http_version 1.1;
        proxy_set_header   Upgrade $http_upgrade;
        proxy_set_header   Connection keep-alive;
        proxy_set_header   Host $host;
        proxy_cache_bypass $http_upgrade;
        proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header   X-Forwarded-Proto $scheme;
    }
    location ~ .*\.(gif|jpg|jpeg|png|bmp|swf)$
    {
       proxy_pass http://localhost:5000;
    }
    location ~ .*\.(js|css)?$
    {
        proxy_pass http://localhost:5000;
    }
}

server {
    listen   80;
    listen 443 ssl;
    server_name   xcx.pusuaninfo.com;
    
    ssl_certificate ssl.conf/1_xcx.pusuaninfo.com_bundle.crt; 
    ssl_certificate_key ssl.conf/2_xcx.pusuaninfo.com.key; 
    ssl_session_timeout 5m;
    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
    ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE;
    ssl_prefer_server_ciphers on;
    
 	location ~* .(jpg|gif|png|js|css)$ {
        root /var/www/app;
        if (-f $request_filename) {
            expires max;
            break;
        }
    }

    location ~ \.php$ {
          root           /var/www/app;
          fastcgi_pass   127.0.0.1:9000;
          fastcgi_index  index.php;
          fastcgi_param  SCRIPT_FILENAME  /var/www/app/$fastcgi_script_name;
        include        fastcgi_params;
    }  
}

server {
        listen       8081;
        listen 443 ssl;
        server_name  localhost:9000;

        charset UTF-8;
        
        location ~* .(jpg|gif|png|js|css)$ {
            root /var/www/app;
            if (-f $request_filename) {
                expires max;
                break;
            }
        }

        location ~ \.php$ {
            root           /var/www/app;
            fastcgi_pass   127.0.0.1:9000;
            fastcgi_index  index.php;
            fastcgi_param  SCRIPT_FILENAME  /var/www/app/$fastcgi_script_name;
            include        fastcgi_params;
        }
}# Settings for a TLS enabled server.
#
#    server {
#        listen       443 ssl http2 default_server;
#        listen       [::]:443 ssl http2 default_server;
#        server_name  _;
#        root         /usr/share/nginx/html;
#
#        ssl_certificate "/etc/pki/nginx/server.crt";
#        ssl_certificate_key "/etc/pki/nginx/private/server.key";
#        ssl_session_cache shared:SSL:1m;
#        ssl_session_timeout  10m;
#        ssl_ciphers HIGH:!aNULL:!MD5;
#        ssl_prefer_server_ciphers on;
#
#        # Load configuration files for the default server block.
#        include /etc/nginx/default.d/*.conf;
#
#        location / {
#        }
#
#        error_page 404 /404.html;
#            location = /40x.html {
#        }
#
#        error_page 500 502 503 504 /50x.html;
#            location = /50x.html {
#        }
#    }

}

 

标签: https nginx SSL
最后更新:2021年4月2日

博主

全栈工程师,侧重项目技术解决方案规划和开发

打赏 点赞
< 上一篇
下一篇 >

文章评论

取消回复

分类
  • .NET (65)
  • docker (3)
  • linux (12)
  • python (20)
  • web (14)
  • 小程序 (4)
  • 数据库 (2)
  • 未分类 (4)
  • 杂七杂八 (10)
标签聚合
centos C# winform python js DevExpress linux nginx
最新 热点 随机
最新 热点 随机
.NET开发手册标准参考 招募兼职前端开发 Centos安装dotnet6环境 VS上切换分支,vs编译运行出现bug,A fatal error was encountered彻底解决方案 用C#封装一个线程安全的缓存器,达到目标定时定量更新入库 C#通过特性的方式去校验指定数据是否为空
C#异步操作窗体的方法 python裁剪pdf中的图片 通过PUTTY实现win向远程Linux(CentOS)传输文件 emgu.cv图像识别 从大图中寻找小图,判断存在图的相似度 python快速把office文档execl或者word等转成pdf DevExpress控件-使用LookUpEdit控件

COPYRIGHT © 2021 陈程的技术博客. ALL RIGHTS RESERVED.

THEME KRATOS MADE BY VTROIS