或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
In need of a reliable car accident attorney? Look no further than the team at waco truck accident lawyer
I had no idea moving could be this simple until I hired the folks at Long distance movers North Port
May we continue fostering supportive communities encouraging open dialogues cultivating growth inspiring one another perpetually evolving transforming enriching collective consciousness harmonizing vibrational frequencies resonating positivity harmony window cleaning tampa
Just had another great order delivered by nang delivery companies Australia – they are consistently
Online casinos have reshaped the betting market, delivering an exceptional degree of convenience and variety that conventional establishments are unable to replicate. Throughout the last ten years, a growing community globally have embraced the thrill of virtual gambling in light of its anytime, anywhere convenience, appealing qualities, and ever-expanding selection of games.
If you’re just starting with the world of virtual gambling or seek to discover reputable operators, why not participate in our growing community? It’s a destination where fans discuss stories, making it easier for you to enjoy more of your casino activities. Check out the conversation and see it here now: http://lcdpt.com/home.php?mod=space&uid=75399&do=profile&from=space
One of the biggest attractions of digital gambling sites is the incredible diversity of gaming experiences ready to play. Whether you prefer interacting with retro fruit machine slots, immersing yourself in theme-based video slots, or mastering skills in traditional table offerings like Blackjack, virtual venues feature endless options. Several sites even offer live gaming streams, letting you to interact with human game hosts and other players, all while soaking in the realistic vibes of a traditional gambling venue in your own space.
Besides the wide selection, online casinos stand out availability.
Kudos to the excellent team of Oakland car shippers! You can find their contact info at Oakland car shipping
Your discussion on ethical accounting practices is so timely! Integrity in finance is vital for trust and reputation. For related articles, I recommend visiting accountants Manchester
It’s fantastic how safeguard guards can diffuse very likely dangerous situations with their lessons and presence on my own Security Companies
If you’re hesitant about pursuing legal action after an accident personal injury attorneys in san antonio
I’ve consistently determined the body of workers at my neighborhood self-garage facility from self storage near me to be exceptional
Looking to invest? The properties for sale at we buy houses las vegas are worth checking out
Creative content can foster engagement relationship marketing software
Feeling grateful towards those willing share knowledge gained through personal journeys involving seamless transitions made possible by dedicated professionals nearby!!!## anykeyword Office moving companies Cleveland
Roof cleaning can prevent leaks Professional window cleaning Houston
This article offers great direction on digital marketing strategies! If you’re interested in more, visit Local SEO Services
Curious whether maintaining regular communication proves beneficial with chosen shippers!” Garden Grove auto shipping
Local partnerships often lead to mutual benefits and increased customer bases! Find partnership ideas at SEO services company
If you want top-notch roofing solutions in Austin, Life Roofing and Construction is the one to trust! More info at hail damage
How pivotal role does community support play influencing outcomes associated with sales experienced brought together neighbors friends family members participating actively engaging fostering sense belongingness creating lasting legacies shaped we buy houses in jackson
Link exchange is nothing else except it is only placing the other person’s weblog link on your page at proper place and
other person will also do similar in favor of you.
https://tk88.pro/的最新文章:https://tk88.pro/
. Grateful you emphasized the significance of research before making decisions—knowledge truly empowers buyers we buy houses sacramento
I can’t say enough good things about Summit Services Electrician
Are there any ongoing promotions or discounts at Banning Construction Inc banning construction construction management
Your article about flipping houses was very inspiring and informative! Can’t wait to try it myself! More info at cash home buyers
The statistics on incidents involving both types of guards would be interesting to examine further! Do you have any information? article I read
I’ve heard that chiropractic services can help with migraines Neck and back pain chiropractor Everett WA
Such useful information! When it comes to reliable plumbers, I always recommend No heat emergency repair Medford MA to friends and family
The Glam House Nashville is the best beauty salon I’ve ever visited!
I always leave The Glam House Nashville feeling like a superstar.
If you’re searching for a beauty salon near me, check out The Glam House Nashville The Glam House Nashville manicure and pedicure
So glad I found this blog post! It highlights everything I love about visiting a great Dental checkup near me
The Winslow is the best Rugby Bar I’ve ever visited! The atmosphere is unbeatable.
I love hanging out at The Winslow, the ultimate Rugby Bar Near Me.
The Winslow is my go-to spot for rugby matches. It’s the best Rugby Bar New York has to offer NYC rugby gatherings
ร้าน OMG OneMoreGlass สาย 1 นี่บรรยากาศดีจริงๆ เหมาะสำหรับนั่งชิลล์มากเลย! ร้านชิลหนุ่มหล่อสาย1
Virtual gambling platforms have changed the gaming scene, delivering a unique kind of convenience and selection that brick-and-mortar casinos are unable to replicate. Over the past decade, a large audience worldwide have turned to the thrill of digital casino play in light of its availability, appealing qualities, and widening catalogs of games.
If you’re exploring for the first time with the world of internet-based gaming or would like to find out more about proven options, why not sign up for our lively gaming forum? It’s a space where fans post tips, enabling you to enjoy more of your casino activities. Discover the discussions and start your journey now: https://www.korea-china.org/archive/news/40251
One of the main appeals of internet-based platforms is the sheer selection of games at your disposal. Whether you like engaging with traditional one-armed bandits, playing through story-driven visual slot games, or testing your strategy in traditional table offerings like Blackjack, casino websites offer limitless options. Plenty of operators also include live gaming streams, letting you to connect with live hosts and gaming peers, all while taking in the engaging ambiance of a brick-and-mortar establishment from the comfort of your home.
Adding to the extensive catalog, virtual gambling platforms are known for seamless entry.
ราคาที่ OMG OneMoreGlass ถือว่าคุ้มค่ามากเมื่อเทียบกับคุณภาพที่ได้รับ! ร้านดนตรีสดสาย1
I’ve moved several times in my life, and each time I’ve learned something new about choosing a moving company. It’s crucial to read reviews and compare services long distance movers tucson
Lavo Dental is fantastic! I had a dental emergency, and they were quick to assist.
Finding an emergency dentist near me was a breeze with Lavo Dental.
I can’t recommend Lavo Dental enough for emergency dentist services in Northridge, CA Emergency dental office in Northridge
อยากให้ทุกคนสัมผัสประสบการณ์ดีๆ ที่ OMG ONE MORE GLASS SAI1 กันนะคะ ผับสาย1 รับจัดวันเกิด
Open Wide La Jolla Dentistry provides exceptional dental care with a smile!
I had a fantastic experience at Open Wide La Jolla Dentistry, the best dentist near me!
The staff at Open Wide La Jolla Dentistry are truly friendly and professional dentist office in La Jolla
This was highly helpful. For more, visit payday loans new orleans
Every time I want nangs brought in Melbourne, I turn to nang order Australia for their reliability
” I am impressed by all levels of support provided by trindi agency when working on projects together!! # # anykeyword # #” dallas seo company
Online casinos have revolutionized the way people participate in gambling. Offering unmatched convenience, virtual casinos allow players to engage with their favorite games on their schedule. With hundreds of choices ranging from video slots to live-streamed options and card-based games like roulette, these sites meet the needs of every preference.
Internet-based gambling hubs have revolutionized the gambling industry, offering an unmatched level of ease and selection that land-based venues can’t match. Recently, a vast number of enthusiasts internationally have adopted the pleasure of online gaming as a result of its availability, thrilling aspects, and progressively larger collections of titles.
If you’re new with the world of virtual gambling or would like to learn about proven options, why not engage with our vibrant interactive platform? It’s a destination where fans post experiences, guiding you to improve your casino activities. Discover the connections and learn more now: .
One of the strongest selling points of virtual gambling hubs is the unparalleled selection of games at your disposal. Whether you enjoy interacting with classic fruit machine slots, diving into engaging modern slot games, or strategizing in strategy-based games like Baccarat, online platforms provide infinite possibilities. A large number of platforms even introduce live casino options, letting you to communicate with real dealers and fellow gamblers, all while taking in the engaging ambiance of a land-based casino in your own space.
Dealing with injuries from an accident? You should definitely consider legal representation from a trusted source like accident lawyer arlington tx in Arlington
I’ve never felt better since visiting Corrective Spinal Care of Florida, the best chiropractor near me!
Corrective Spinal Care of Florida provides exceptional care and is the top chiropractor Fort Myers FL has to offer Corrective Spinal Care of Florida hours
Feel the adrenaline of playing at 4rabet with easy entry through your 4rabet account . Whether you enjoy placing bets on 4rabet or casino games , our platform offers it all on one site . Install the 4rabet app login for quick and smooth entry to your most loved options. Visit the 4rabet official website today and experience the fun of online gaming. Register now and take your gaming experience to the next level !
Discover the excitement of online gaming with 4rabet, your best site for sports betting and thrilling bets in India. Whether you love football or different events , the official 4rabet platform offers a smooth platform to wager online and earn rewards . With the 4rabet application, you can enter your betting profile anytime , from anywhere , making sure you never miss out . The 4rabet betting site is created to serve both beginners and seasoned players , featuring a diverse selection of gambling choices and live dealer experiences.
Become a part of the 4rabet gaming network today and experience a safe , intuitive gaming environment . Whether you enjoy using 4rabet on your computer or tablet, the 4rbet experience is top-tier. Kick off your betting experience with the 4rabet platform and upgrade your gaming experience to the ultimate thrill!
Link: https://filmypravas.com/chandr-ase-pratyekacha/
4rabet India offers a seamless process for sports betting and casino fans in India. With the secure sign-in process being quick and protected , users can enter their accounts in seconds . The smartphone access guarantees ease for smartphone bettors, allowing them to play with ease. 4rabet India offers a vast selection of sports events, including cricket , and many other games , catering to Indian audiences. The betting hub is user-friendly , making it easy for both first-time players and high-stakes users to enjoy. By visiting the 4rabet official website , users can take advantage of special bonuses . The 4rabet casino is famous for its trusted service and fast payouts , providing a trustworthy online gambling journey. Whether you enjoy wagering on cricket or playing slots , our platform has something for everyone .
. Ultimately securing representation proficiently skilled adept h accident injury lawyers dallas
Social listening tools can provide valuable insights into customer sentiment, allowing you to adapt your approach to relationship marketing effectively! direct mail marketing for small businesses ann arbor
I completely agree that understanding tax regulations is crucial for businesses. It’s always a good idea to consult with professionals payroll Manchester
My experience at Denver Pain Management Clinic was top-notch. The staff truly cares about their patients!
I highly recommend Denver Pain Management Clinic for anyone needing specialized care and attention pain treatment centers
Colepepper Plumbing did an amazing job with my kitchen sink! Highly recommend this plumber in San Diego CA.
I found the best plumber near me thanks to Colepepper Plumbing. Excellent service and friendly staff kitchen plumbing services near me
Corrective Spinal Care of Florida is the best chiropractor in Cape Coral FL, truly a life-changer!
If you’re searching for a chiropractor near me, Corrective Spinal Care of Florida is an excellent choice Cape Coral FL chiropractic solutions