美文网首页
2019-07-06

2019-07-06

作者: 大海244 | 来源:发表于2019-07-06 15:25 被阅读0次

    certbot官网(构建https)

    1.获取certbot-auto

    ####  下载

    wget https://dl.eff.org/certbot-auto

    ####  给予权限

    chmod a+x ./certbot-auto

    2.使用

    #### 请改为自己的域名

    ./certbot-auto --server https://acme-v02.api.letsencrypt.org/directory -d "*.xxx.com" -d "xxx.com" --manual --preferred-challenges dns-01 certonly

    ####  出现如下 输入邮箱

    Enter email address (used for urgent renewal and security notices) (Enter 'c' to

    cancel):

    ####  输入A同意

    Please read the Terms of Service at

    https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must

    agree in order to register with the ACME server at

    https://acme-v02.api.letsencrypt.org/directory

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    (A)gree/(C)ancel:

    ####  输入Y同意

    Would you be willing to share your email address with the Electronic Frontier

    Foundation, a founding partner of the Let's Encrypt project and the non-profit

    organization that develops Certbot? We'd like to send you email about our work

    encrypting the web, EFF news, campaigns, and ways to support digital freedom.

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    (Y)es/(N)o:

    ####  输入Y确认

    NOTE: The IP of this machine will be publicly logged as having requested this

    certificate. If you're running certbot in manual mode on a machine that is not

    your server, please ensure you're okay with that.

    Are you OK with your IP being logged?

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    (Y)es/(N)o:

    ####  域名添加TXT解析  添加对应的域名和值 添加好后回车继续

    Please deploy a DNS TXT record under the name

    xxxx.xxxx.com with the following value:

    xxxxxxxx

    Before continuing, verify the record is deployed.

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Press Enter to Continue

    ####  出现如下即成功

    IMPORTANT NOTES:

    - Congratulations! Your certificate and chain have been saved at:

      /etc/letsencrypt/live/xxxxx.com/fullchain.pem

      Your key file has been saved at:

      /etc/letsencrypt/live/xxxxx.com/privkey.pem

      Your cert will expire on 2018-12-28. To obtain a new or tweaked

      version of this certificate in the future, simply run certbot-auto

      again. To non-interactively renew *all* of your certificates, run

      "certbot-auto renew"

    - Your account credentials have been saved in your Certbot

      configuration directory at /etc/letsencrypt. You should make a

      secure backup of this folder now. This configuration directory will

      also contain certificates and private keys obtained by Certbot so

      making regular backups of this folder is ideal.

    - If you like Certbot, please consider supporting our work by:

      Donating to ISRG / Let's Encrypt:  https://letsencrypt.org/donate

      Donating to EFF:                    https://eff.org/donate-le

    3.nginx配置

    server{

      listen  80;

      listen [::]:80;

      server_name  xxx.xxx.com;

      return        301 https://$server_name$request_uri;

    }

    server {

            listen 443 ssl;

            server_name xxx.xxx.com;

            ssl on;

            ssl_certificate /etc/letsencrypt/live/xxx.xxx.com/fullchain.pem;

            ssl_certificate_key /etc/letsencrypt/live/xxx.xxx.com/privkey.pem;

            ssl_session_cache shared:SSL:20m;

            ssl_session_timeout  10m;

            ssl_protocols TLSv1 TLSv1.1 TLSv1.2;

            ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE:!kEDH;

            ssl_prefer_server_ciphers on;

            ssl_stapling on;

            ssl_stapling_verify on;

            ssl_trusted_certificate /etc/letsencrypt/live/xxx.xxx.com/chain.pem;

            #启用 HSTS 用于通知浏览器强制使用 https 通信

            add_header Strict-Transport-Security "max-age=31536000";

            resolver 8.8.8.8 8.8.4.4;

            ........

      }

    ---------------------

    作者:滥情丶

    来源:CSDN

    原文:https://blog.csdn.net/q85795362/article/details/82903507

    版权声明:本文为博主原创文章,转载请附上博文链接!

    相关文章

      网友评论

          本文标题:2019-07-06

          本文链接:https://www.haomeiwen.com/subject/kaiphctx.html