在 Linux 上使用 Nginx 开启 HTTPS,通常步骤如下(以自签证书或Let’s Encrypt 免费证书为例):
nginx -v
CentOS / Rocky / Alma
yum install epel-release -y
yum install certbot python3-certbot-nginx -y
Ubuntu / Debian
apt update
apt install certbot python3-certbot-nginx -y
certbot --nginx -d www.example.com -d example.com
按提示操作,certbot 会:
certbot renew --dry-run
mkdir -p /etc/nginx/ssl
cd /etc/nginx/ssl
openssl genrsa -out server.key 2048
openssl req -new -x509 -days 365 -key server.key -out server.crt
编辑站点配置:
vim /etc/nginx/conf.d/https.conf
示例:
server {
listen 443 ssl;
server_name localhost;
ssl_certificate /etc/nginx/ssl/server.crt;
ssl_certificate_key /etc/nginx/ssl/server.key;
location / {
root /usr/share/nginx/html;
index index.html;
}
}
server {
listen 80;
server_name localhost;
return 301 https://$host$request_uri;
}
nginx -t
systemctl reload nginx
# firewalld
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
# 或 iptables
iptables -I INPUT -p tcp --dport 443 -j ACCEPT
浏览器访问:
https://你的域名
如果你告诉我:
我可以给你更精确的配置。