版权声明:本文为博主原创文章,未经博主允许不得转载。 https://blog.csdn.net/dujianxiong/article/details/88251784
openssl genrsa -des3 -out vulcan.key 1024
最重要的是填common Name为域名
openssl req -new -key vulcan.key -out vulcan.csr
copy vulcan.key vulcan.key.org
openssl rsa -in vulcan.key.org -out vulcan.key
openssl x509 -req -days 36500 -in vulcan.csr -signkey vulcan.key -out vulcan.crt
Nginx配置
server {
listen 8098 ssl;
server_name xxxx.xxx.com;
ssl_certificate /usr/local/nginx/sslKey/vulcan/vulcan.crt;
ssl_certificate_key /usr/local/nginx/sslKey/vulcan/vulcan.key;
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 5m;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
location /info-api-m {
proxy_pass http://zkyjsm;
#Proxy Settings
proxy_redirect off;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
}