在 Debian 上跑 Nginx + SSL,一般需要的依赖和组件如下(分场景):
apt update
apt install -y nginx
Nginx 默认已支持 SSL(编译时带 http_ssl_module),不需要额外装 OpenSSL 库来跑 HTTPS。
不需要额外依赖,用系统自带:
openssl req -x509 -nodes -days 365 -newkey rsa:2048 \
-keyout /etc/nginx/ssl/nginx.key \
-out /etc/nginx/ssl/nginx.crt
需要 certbot:
apt install -y certbot python3-certbot-nginx
申请并自动配置:
certbot --nginx -d example.com
✅ 会自动:
| 场景 | 依赖 |
|---|---|
| 编译 Nginx | build-essential, libpcre3-dev, zlib1g-dev, libssl-dev |
| HTTP/2 | Nginx ≥ 1.9.5(默认支持) |
| OCSP Stapling | 无需额外依赖 |
| 高并发 TLS | 内核 ≥ 3.10 即可 |
server {
listen 443 ssl;
server_name example.com;
ssl_certificate /etc/nginx/ssl/nginx.crt;
ssl_certificate_key /etc/nginx/ssl/nginx.key;
ssl_protocols TLSv1.2 TLSv1.3;
}
ufw allow 443
如果你说下:
我可以给你精确命令。