Nginx 的 HTTPS 配置

备份,参考。

先上一份完整的配置文件:

/etc/nginx/conf.d/http.conf

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
server {
    listen          80 default_server;
    listen          443 ssl default_server;
    server_name     _;
    # server_tokens   off;

    include /etc/nginx/ssl/ssl.conf;

    return 404;
}

server {
    listen          80;
    listen          [::]:80;
    server_name     example.com;
    server_tokens   off;

    if ($request_method !~ ^(GET|HEAD|POST)$ ) {
        return 444;
    }

    location / {
        return 301 https://$host$request_uri;
    }
}

server {
    listen          443 ssl http2;
    listen          [::]:443 ssl http2;
    server_name     example.com;

    include /etc/nginx/ssl/ssl.conf;

    location / {
        proxy_pass_header Server;
        proxy_set_header Host $http_host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Scheme $scheme;
        proxy_pass  http://127.0.0.1:8086/;
    }
}

/etc/nginx/ssl/ssl.conf

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
server_tokens               off;

ssl_certificate             /opt/ssl_certificate/example.com/fullchain.pem;
ssl_certificate_key         /opt/ssl_certificate/example.com/key.pem;

ssl_dhparam                 /etc/nginx/ssl/dhparam.pem;

ssl_ciphers                 ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:DHE-RSA-AES256-GCM-SHA384;
ssl_ecdh_curve              prime256v1;
ssl_protocols               TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers   on;

ssl_session_cache           shared:SSL:10m;
ssl_session_timeout         10m;
ssl_session_tickets         off;

ssl_stapling                on;
ssl_stapling_verify         on;

resolver                    8.8.8.8 valid=300s;
resolver_timeout            5s;

add_header                  Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
add_header                  X-Frame-Options DENY;
add_header                  X-Content-Type-Options nosniff;
# add_header                  X-XSS-Protection "1; mode=block";
add_header                  Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data:; connect-src 'self'";

然后大概说说这都是什么东西,以及为什么要这样做。

TODO


发布于

2019-12-29

更新于

2020-05-12

许可协议

CC BY-NC 4.0

评论