Nginx设置默认首页,index.html配置
前言
访问网站根目录,Nginx 不知道默认打开哪个文件,就返回 403 或者 404。这是因为没配置默认首页。本文讲一下 Nginx 怎么设置默认首页。
什么是默认首页
用户访问 www.example.com/,Nginx 自动找目录下的 index.html 打开,不用手动输入文件名。
配置方法
用 index 指令设置:
server {
listen 80;
server_name www.example.com;
root /var/www/html;
index index.html;
}
多个默认首页
Nginx 会按顺序找,找到第一个存在的就用:
index index.html index.htm index.php;
意思是:先找 index.html,没有就找 index.htm,再没有就找 index.php。
完整站点配置
server {
listen 80;
server_name www.example.com;
root /var/www/html;
index index.php index.html index.htm;
location / {
try_files $uri $uri/ =404;
}
location ~ \.php$ {
fastcgi_pass unix:/run/php-fpm/www.sock;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
include fastcgi_params;
}
}
自定义默认首页
不想用 index.html,想用别的文件名?
index default.html;
这样访问根目录就打开 default.html。
常见坑
坑1:访问根目录 403 Forbidden
配置了 root,也放了 index.html,但访问还是 403。
原因1: 文件名写错了,比如是 Index.html(大写 I)。
解决: Linux 区分大小写,文件名必须和 index 配置一致。
原因2: 文件权限不对。
解决: 确保文件权限是 644,目录是 755。
坑2:默认首页不生效
改了 index 配置,但还是打开旧的首页。
原因: 没重载 Nginx。
解决:
nginx -s reload
坑3:PHP 首页不解析
默认首页设成 index.php,但访问直接下载 PHP 文件。
原因: PHP 解析配置没写对。
解决: 确保有 PHP 的 location 配置:
location ~ \.php$ {
fastcgi_pass unix:/run/php-fpm/www.sock;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
include fastcgi_params;
}
坑4:静态首页和 PHP 首页顺序
index 里先写 index.html 还是 index.php?
建议: 把常用的放前面。如果主要是 PHP 程序,就把 index.php 放前面。
总结
一行配置搞定:
index index.php index.html index.htm;
记住: index 后面跟多个文件名,Nginx 按顺序找,找到第一个存在的就用。
遇到问题加QQ23979811 协助处理
Nginx 配置 HTTPS 详解
Nginx 配置 HTTPS 详解
现在网站都要求上 HTTPS,Nginx 配置 HTTPS 是运维必备技能。
1. 申请 SSL 证书
免费证书推荐:
- Let's Encrypt(免费 90 天)
- 阿里云/腾讯云免费 DV 证书
用 acme.sh 申请 Let's Encrypt:
# 安装 acme.sh
curl https://get.acme.sh | sh
# 申请证书
~/.acme.sh/acme.sh --issue -d www.example.com --webroot /www/wwwroot/example.com/
# 安装证书
~/.acme.sh/acme.sh --install-cert -d www.example.com \
--key-file /www/server/ssl/private.key \
--fullchain-file /www/server/ssl/cert.crt
2. Nginx 基础 HTTPS 配置
server {
listen 443 ssl;
server_name www.example.com;
# 证书文件
ssl_certificate /www/server/ssl/cert.crt;
ssl_certificate_key /www/server/ssl/private.key;
# SSL 优化
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;
root /www/wwwroot/example.com;
index index.html index.php;
location / {
try_files $uri $uri/ /index.php?$query_string;
}
location ~ \.php$ {
fastcgi_pass 127.0.0.1:9000;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
include fastcgi_params;
}
}
3. HTTP 自动跳转 HTTPS
server {
listen 80;
server_name www.example.com;
return 301 https://$server_name$request_uri;
}
4. 优化 HTTPS 性能
开启 HTTP/2:
listen 443 ssl http2;
HSTS 强制 HTTPS:
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
开启 OCSP Stapling:
ssl_stapling on;
ssl_stapling_verify on;
resolver 8.8.8.8 114.114.114.114 valid=300s;
5. 常见问题
1)证书不生效:
- 检查证书路径对不对
- 证书文件格式是否正确
- Nginx 配置重载了吗
2)混合内容问题:
- 页面里有 http:// 的资源,浏览器会拦截
- 全部改成 https:// 或 // 协议相对路径
3)证书过期:
- 免费证书 90 天过期
- 用 acme.sh 自动续期
# acme.sh 自动安装了定时任务
crontab -l | grep acme
6. 检查配置
# 检查 Nginx 配置
nginx -t
# 重载配置
nginx -s reload
# 测试证书
curl -I https://www.example.com
总结
Nginx 配置 HTTPS 要点:
- 申请 SSL 证书
- 配置 443 端口和证书路径
- HTTP 跳转 HTTPS
- 开启 HTTP/2 和 SSL 优化
- 设置自动续期
现在没有 HTTPS 的网站浏览器都标"不安全",赶紧给网站配上。