«

Nginx HTTPS 配置详解

时间:2026-10-8 07:15     作者:emer     分类: 无


Nginx HTTPS 配置详解

现在网站都要上 HTTPS,Nginx 配置 SSL 很简单。

1. 准备证书

免费证书可以用:

下载后有两个文件:

2. 基础配置

server {
    listen 443 ssl;
    server_name www.example.com;

    ssl_certificate /etc/nginx/ssl/xxx.pem;
    ssl_certificate_key /etc/nginx/ssl/xxx.key;

    location / {
        root /www/wwwroot/html;
        index index.html;
    }
}

3. HTTP 跳转 HTTPS

# HTTP 重定向到 HTTPS
server {
    listen 80;
    server_name www.example.com;
    return 301 https://$server_name$request_uri;
}

4. 优化配置

server {
    listen 443 ssl http2;
    server_name www.example.com;

    ssl_certificate /etc/nginx/ssl/xxx.pem;
    ssl_certificate_key /etc/nginx/ssl/xxx.key;

    # SSL 优化
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;
    ssl_session_cache shared:SSL:10m;
    ssl_session_timeout 10m;

    location / {
        root /www/wwwroot/html;
        index index.html;
    }
}

5. 验证配置

# 检查配置是否正确
nginx -t

# 重载配置
nginx -s reload

6. 常见问题

1)证书不生效:

2)浏览器提示不安全:

3)HTTP 打不开:

7. Let's Encrypt 免费证书

用 certbot 自动申请:

# 安装
yum install certbot python3-certbot-nginx

# 自动申请并配置
certbot --nginx -d www.example.com

# 自动续期
certbot renew

总结

Nginx HTTPS 配置要点:

现在做网站,HTTPS 是标配。

标签: Nginx HTTPS SSL 证书 安全