Site updated: 2024-01-03 18:09:13
This commit is contained in:
2
atom.xml
2
atom.xml
@@ -29,7 +29,7 @@
|
||||
<figure class="highlight bash"><figcaption data-lang="bash"></figcaption><table><tr><td data-num="1"></td><td><pre>openssl x509 <span class="token parameter variable">-req</span> <span class="token parameter variable">-days</span> <span class="token number">36500</span> <span class="token parameter variable">-in</span> private.csr <span class="token parameter variable">-CA</span> CA-certificate.crt <span class="token parameter variable">-CAkey</span> CA-private.key <span class="token parameter variable">-CAcreateserial</span> <span class="token parameter variable">-sha256</span> <span class="token parameter variable">-out</span> private.crt <span class="token parameter variable">-extfile</span> private.ext <span class="token parameter variable">-extensions</span> SAN</pre></td></tr></table></figure><h4 id="nginx的ssl证书配置"><a class="anchor" href="#nginx的ssl证书配置">#</a> nginx 的 ssl 证书配置</h4>
|
||||
<figure class="highlight yaml"><figcaption data-lang="YAML"></figcaption><table><tr><td data-num="1"></td><td><pre>ssl_certificate_key /usr/local/nginx/ssl/private.key;</pre></td></tr><tr><td data-num="2"></td><td><pre>ssl_certificate /usr/local/nginx/ssl/private.crt;</pre></td></tr></table></figure><h4 id="证书安装"><a class="anchor" href="#证书安装">#</a> 证书安装</h4>
|
||||
<p>需要安装 CA-certificate.crt 到受信任的根证书颁发机构下,即可从浏览器正常访问且不会报不安全警告。</p>
|
||||
<figure class="highlight bash"><figcaption data-lang="bash"></figcaption><table><tr><td data-num="1"></td><td><pre><span class="token comment">#ssl 测试</span></pre></td></tr><tr><td data-num="2"></td><td><pre>openssl s_client <span class="token parameter variable">-connect</span> localhost:8080</pre></td></tr></table></figure></content>
|
||||
<figure class="highlight bash"><figcaption data-lang="bash"></figcaption><table><tr><td data-num="1"></td><td><pre><span class="token comment">#ssl 测试</span></pre></td></tr><tr><td data-num="2"></td><td><pre>openssl s_client <span class="token parameter variable">-connect</span> localhost:8080</pre></td></tr><tr><td data-num="3"></td><td><pre><span class="token comment">#检查证书格式</span></pre></td></tr><tr><td data-num="4"></td><td><pre>openssl x509 <span class="token parameter variable">-in</span> private.crt <span class="token parameter variable">-text</span> <span class="token parameter variable">-noout</span></pre></td></tr><tr><td data-num="5"></td><td><pre>openssl rsa <span class="token parameter variable">-in</span> private.key <span class="token parameter variable">-check</span></pre></td></tr><tr><td data-num="6"></td><td><pre><span class="token comment">#检查证书是否过期(确保 "notBefore" 小于当前日期,"notAfter" 大于当前日期)</span></pre></td></tr><tr><td data-num="7"></td><td><pre>openssl x509 <span class="token parameter variable">-in</span> private.crt <span class="token parameter variable">-noout</span> <span class="token parameter variable">-dates</span></pre></td></tr><tr><td data-num="8"></td><td><pre><span class="token comment">#查看证书链</span></pre></td></tr><tr><td data-num="9"></td><td><pre>openssl x509 <span class="token parameter variable">-in</span> private.crt <span class="token parameter variable">-noout</span> <span class="token parameter variable">-issuer</span> <span class="token parameter variable">-subject</span></pre></td></tr></table></figure></content>
|
||||
<category term="工作" scheme="https://hitoli.com/categories/%E5%B7%A5%E4%BD%9C/" />
|
||||
<category term="解决问题" scheme="https://hitoli.com/categories/%E5%B7%A5%E4%BD%9C/%E8%A7%A3%E5%86%B3%E9%97%AE%E9%A2%98/" />
|
||||
<category term="Nginx" scheme="https://hitoli.com/tags/Nginx/" />
|
||||
|
||||
Reference in New Issue
Block a user