最近网站更新为https,于是做个笔记
将域名 www.domain.com 的证书文件1_www.domain.com\_bundle.crt 、
私钥文件2_www.domain.com.key保存到同一个目录,
例如/usr/local/nginx/conf目录下。
更新Nginx根目录下 conf/nginx.conf 文件如下:
1#user nobody; 2worker_processes 1; 3 4#error_log logs/error.log; 5#error_log logs/error.log notice; 6#error_log logs/error.log info; 7 8#pid logs/nginx.pid; 9 10 11events { 12 worker_connections 1024; 13} 14 15 16http { 17 include mime.types; 18 default_type application/octet-stream; 19 20 #log_format main '$remote_addr - $remote_user [$time_local] "$request" ' 21 # '$status $body_bytes_sent "$http_referer" ' 22 # '"$http_user_agent" "$http_x_forwarded_for"'; 23 24 #access_log logs/access.log main; 25 26 sendfile on; 27 #tcp_nopush on; 28 29 #keepalive_timeout 0; 30 keepalive_timeout 65; 31 32 #gzip on; 33 34 server { 35 listen 80; 36 37 server_name domain.com; 38 39 rewrite ^(.*) https://$host$1 permanent; 40 41 #charset koi8-r; 42 43 #access_log logs/host.access.log main; 44 45 #location / { 46 # root html; 47 # index index.html index.htm; 48 #} 49 50 #error_page 404 /404.html; 51 52 # redirect server error pages to the static page /50x.html 53 # 54 error_page 500 502 503 504 /50x.html; 55 location = /50x.html { 56 root html; 57 } 58 59 # proxy the PHP scripts to Apache listening on 127.0.0.1:80 60 # 61 #location ~ \.php$ { 62 # proxy_pass http://127.0.0.1; 63 #} 64 65 # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000 66 # 67 #location ~ \.php$ { 68 # root html; 69 # fastcgi_pass 127.0.0.1:9000; 70 # fastcgi_index index.php; 71 # fastcgi_param SCRIPT_FILENAME /scripts$fastcgi_script_name; 72 # include fastcgi_params; 73 #} 74 75 # deny access to .htaccess files, if Apache's document root 76 # concurs with nginx's one 77 # 78 #location ~ /\.ht { 79 # deny all; 80 #} 81 } 82 83 84 # another virtual host using mix of IP-, name-, and port-based configuration 85 # 86 #server { 87 # listen 8000; 88 # listen somename:8080; 89 # server_name somename alias another.alias; 90 91 # location / { 92 # root html; 93 # index index.html index.htm; 94 # } 95 #} 96 97 98 # HTTPS server 99 # 100 server { 101 listen 443 ssl; 102 server_name domain.com; 103 104 ssl_certificate 1_www.domain.com_bundle.crt; 105 ssl_certificate_key 2_www.domain.com.key; 106 107 ssl_session_cache shared:SSL:1m; 108 ssl_session_timeout 5m; 109 110 ssl_ciphers HIGH:!aNULL:!MD5; 111 ssl_prefer_server_ciphers on; 112 113 location / { 114 proxy_pass http://127.0.0.1:8080; 115 proxy_set_header X-real-ip $remote_addr; 116 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; 117 proxy_set_header Cookie $http_cookie; 118 } 119 } 120 121}
rewrite ^(.*) https://$host$1 permanent;
这句是将80端口的请求(http)重写为443端口的请求(https)
ssl_certificate 1_www.domain.com\_bundle.crt;
ssl_certificate_key 2_www.domain.com.key;
这两句是指定证书位置,这里是相对路径
location / {
proxy_pass http://127.0.0.1:8080;
proxy_set_header X-real-ip $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Cookie $http_cookie;
}
这里的反向代理到8080端口,是我的应用开启的端口