或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
Thanks for the clear breakdown. Find more at floral designers long island
Gates of Olympus, Pragmatic Play taraf?ndan sunulan eglenceli bir slot oyunudur. Oyun, Zeus’un buyuleyici dunyas?nda essiz bir macera sunuyor. Gates of Olympus demo oyna secenegi ile oyunun nas?l isledigini ogrenebilir ve kendinizi gelistirebilirsiniz.
Gates of Olympus oyna demo modunda, oyunun heyecan verici mekaniklerini ve dinamik yap?s?n? kesfedebilirsiniz.
Oyunun ana ozellikleri aras?nda cesitli bonuslar ve yuksek kazanc f?rsatlar? yer al?r. Gates of Olympus ile buyuk kazanc f?rsatlar?n? degerlendirin! Eger Gates of Olympus hakk?nda daha fazla bilgi edinmek istiyorsan?z, gate of olympus demo secenegi ile oyunu ucretsiz olarak deneyimleyebilirsiniz.
Bu sayede, oyuna baslamadan once nas?l oynand?g?n? anlayabilirsiniz.
Unutmay?n, gates of olympus demo ile sadece eglence degil, ayn? zamanda stratejinizi gelistirme f?rsat?n? da yakalars?n?z.
Gates of Olympus ile efsanevi kazanc f?rsatlar?n? degerlendirin! Y?ld?r?mlar?n Efendisi Ile Kazan?n: Gates Of Olympus’ta Jackpot’a Ulas?n!
Link: https://daramkholahydro.com/2024/12/13/gates-of-olympus-slot-turkiyede-populer-oyunun-demo-surumunu-kesfedin-2/
Bu oyun, Zeus’un krall?g?na adanm?s olup, oyunculara essiz bir deneyim sunmaktad?r. Gates of Olympus oyna demo versiyonu ile tum detaylar?n? ogrenerek gercek oyuna haz?r hale gelebilirsiniz. Gates of Olympus demo oyna secenegi ile nas?l daha fazla kazanabileceginizi ogrenebilirsiniz. Gates of Olympus demo turkce dil destegi ile de oyunun tum detaylar?n? anlayarak Zeus’un kap?lar?n? aralayabilirsiniz.
Thanks for the informative content. More at roof repair near me
I appreciated this post. Check out Roofing Educators for more
Lavo Dental is fantastic! I had a dental emergency, and they were quick to assist.
Finding an emergency dentist near me was a breeze with Lavo Dental.
I can’t recommend Lavo Dental enough for emergency dentist services in Northridge, CA Emergency dental care 91324
Wonderful write-up on the value of a reliable surveillance body! With unlawful act prices growing, purchasing a really good installment can really make a difference in keeping our homes and also companies risk-free fire alarm systems
It’s great how individualized plans in home care cater to definite buyer wishes and options! Get stimulated by journeying respite care gloucester !
I enjoyed this article. Check out metal roofs services for more
Great post on the relevance of a trustworthy safety unit! Along with criminal activity prices rising, buying a really good setup may really create a distinction in maintaining our homes and also businesses risk-free security system installation
It’s full-size to see such dedicated home care products and services on hand in La Mesa, CA! For extra insights, discuss with Home Care La Mesa CA .
It’s significant to contain seniors in discussions about their personal care personal tastes; empowering them results in enhanced effect—high-quality insight shared the following! A Better Solution In Home Care Wichita KS
Nice breakdown of services offered by HVAC contractors! Will check out Hvac contractor Andover .
Internet-based gambling hubs have changed the casino gaming market, delivering a level of ease and selection that brick-and-mortar casinos struggle to rival. Recently, a vast number of enthusiasts around the world have turned to the excitement of online gaming as a result of its availability, captivating elements, and continuously increasing game libraries.
If you’re a beginner with the world of digital casinos or are looking to explore safe services, why not participate in our dynamic community? It’s a hub where enthusiasts exchange experiences, assisting you to get the most out of your virtual play. Dive into the conversation and check it out now: http://unique-listing.com/details.php?id=366019
One of the key draws of online gaming options is the astounding range of games available. Whether you are a fan of playing on vintage reel games, playing through theme-based visual slot games, or testing your strategy in card and board games like Baccarat, internet-based gambling sites provide countless options. Many casinos moreover include live gaming streams, making it possible for you to participate with human game hosts and fellow gamblers, all while immersing yourself in the realistic vibes of a land-based casino without leaving your home.
Besides the wide selection, digital casino services excel constant connectivity.
Outstanding message! Recognizing warranties is key when hiring a professional. If you want to learn more concerning what to try to find, go to roofing contractor bridgewater nj for thorough details.
I’ve been using nang cylinder price comparison for years, and I can’t imagine baking without it!
Your article is spot-on approximately the value of official HVAC inspections; they catch problems we might miss! hvac repair Hamilton Heating and cooling
My experience at Denver Pain Management Clinic was top-notch. The staff truly cares about their patients!
I highly recommend Denver Pain Management Clinic for anyone needing specialized care and attention pain management center Denver
Corrective Spinal Care of Florida is the best chiropractor in Cape Coral FL, truly a life-changer!
If you’re searching for a chiropractor near me, Corrective Spinal Care of Florida is an excellent choice Chiropractic services near me
Love how several new pillows or throws can replace the seem of a couch! You can find classy selections the following: LZ Decor .
Smyle Dental Bakersfield provided the best emergency dentist service I’ve ever experienced!
I was so relieved to find an emergency dentist near me like Smyle Dental Bakersfield dental pain relief Bakersfield CA
Thanks for dropping pale on the benefits of traditional carpet cleansing in workplaces! More counsel are out there at commercial cleaners Foster Janitorial – Commercial Cleaning Company Penticton .
The preconception around addiction frequently stops people coming from finding support. Counseling can easily crack that barricade as well as present that recuperation is possible. Learn more at alcohol addiction counseling nj .
“My final flow was chaotic; truely going with anykeyword this time.” Kelowna moving companies 1st Choice Moving and Storage
I’ve never felt better since visiting North Atlanta Chiropractic Center! They’re the best chiropractor in town.
North Atlanta Chiropractic Center is my go-to chiropractor in Duluth Chiropractors near me
Virtual gambling platforms have reshaped the way people experience gambling. Delivering limitless convenience, online casinos offer enthusiasts to engage with their most-loved choices 24/7. With a wide array of gaming experiences ranging from video slots to live dealer games and classic table games like roulette, these venues meet the needs of every type of player.
Virtual gambling platforms have modernized the casino gaming world, delivering a unique kind of accessibility and selection that brick-and-mortar gambling houses don’t provide. Over time, countless gamblers worldwide have adopted the excitement of digital casino play thanks to its anytime, anywhere convenience, thrilling aspects, and ever-expanding range of offerings.
If you’re just starting with the world of online gaming or want to discover safe services, why not participate in our vibrant online hub? It’s a destination where enthusiasts share insights, assisting you to get the most out of your gambling adventure. Explore the experience and check it out now: .
One of the biggest attractions of digital gambling sites is the astounding selection of games on offer. Whether you like spinning traditional one-armed bandits, trying out plot-filled visual slot games, or playing smart in card and board games like Roulette, digital casinos provide endless choices. A large number of platforms even introduce real-time gaming experiences, making it possible for you to engage with actual dealers and co-players, all while enjoying the authentic environment of a traditional gambling venue right at home.
Just wanted to say that I love how they make kids feel special at Marose Family Dental! What a great place for families—check out marose dental !
Just discovered a wealth of information on therapy options in LA through anxiety therapy los angeles —what a lifesaver!
A smooth workspace no longer in simple terms appears to be like extraordinary however additionally promotes healthiness! Loved this piece. More details at commercial cleaners Foster Janitorial – Commercial Cleaning Company Kamloops .
Daniella Levi & Associates, P.C. are the best car accident lawyers I’ve ever worked with!
If you’re in the Bronx, this car accident lawyer is truly exceptional!
I found the perfect car accident lawyer near me at Daniella Levi & Associates, P.C Find accident lawyer near me
Hey just wanted to give you a quick heads up.
The words in your content seem to be running off the screen in Internet explorer.
I’m not sure if this is a formatting issue or something to do with web
browser compatibility but I figured I’d post to let you know.
The design look great though! Hope you get the
problem solved soon. Kudos
home remodeling pleasant hill的最新文章:home remodeling pleasant hill
This blog does an excellent job highlighting why legal representation matters after an incident! car accident lawyer
Personal injuries can happen anywhere, but knowing local laws helps a lot! Visit personal injury lawyer for details.
Walter’s BBQ Southern Kitchen serves the best brunch I’ve ever had in Pittsburgh PA!
The brunch at Walter’s BBQ Southern Kitchen is absolutely delightful and always makes my weekend better Brunch buffets near me
Awesome article! Discover more at curso escolar Irlanda .
Educating young drivers about the dangers of careless driving could help lower incident rates significantly! personal injury lawyer
The advice on dealing with insurance adjusters was particularly enlightening—thank you for that info! truck accident lawyer
The top equipment make the entire distinction in cleansing! Discover would have to-have products at janitorial companies Foster Janitorial Kelowna .
I’ve found that sharing personal experiences can raise awareness about the impact of medical malpractice—share yours via medical malpractice lawyer .
I learned so much about my rights after speaking with an attorney from truck accident lawyer —highly recommended!
True Balance Pain Relief Clinic & Sports Massage offers the best sports massage I’ve ever experienced!
I always leave True Balance Pain Relief Clinic & Sports Massage feeling refreshed and rejuvenated Muscle recovery services at True Balance Pain Relief Clinic
I’m looking for dentists who offer sedation dentistry services in Mission Viejo—advice? saddleback dental
Thanks for the valuable article. More at casas rurales en Segovia .
The importance of preserving evidence cannot be overstated; take photos and keep records right after an incident! More tips at medical malpractice lawyer .
Digital casinos have changed the gaming landscape, providing a unique kind of comfort and variety that traditional venues fall short of. Over time, a large audience across the globe have welcomed the thrill of online gaming as a result of its anytime, anywhere convenience, appealing qualities, and progressively larger collections of titles.
If you’re unfamiliar with the world of virtual gambling or are looking to discover safe services, why not join our active online hub? It’s a destination where gamblers discuss stories, guiding you to maximize your gambling adventure. Explore the experience and see it here now: http://poezijaproza.blog.rs/blog/poezijaproza/generalna/2007/12/11/aleksandar-blok-pjesme
One of the most compelling reasons of virtual gambling hubs is the incredible array of titles at your disposal. Whether you prefer rolling old-school reel games, exploring engaging thematic slots, or exercising tactics in classic casino games like Texas Hold’em, casino websites deliver numerous opportunities. Numerous services also introduce live gaming streams, making it possible for you to interact with real dealers and fellow gamblers, all while taking in the lifelike vibes of a physical gaming house without leaving your home.
Adding to the extensive catalog, virtual gaming providers shine ease of access.
Thanks for the helpful article. More like this at cocinas Granada .
. Let’s talk about safety measures everyone should adopt while commuting along busy highways leading into bustling urban areas surrounding SAN JOSE where traffic congestion remains prevalent year-round!! # # any Keyword## truck accident lawyer
Appreciate the great suggestions. For more, visit laser eye surgery Portland .
I appreciated this post. Check out carpinteria de aluminio A Coruña for more.
Hopeful find ways inspire others pursue passions fervently creating meaningful connections along paths chosen together!! SEO expert in San Diego
Это очень ценное мнение
4. Muraro P.A., Martin R., Mancardi G.L., Nicholas R., Sormani M.P., the https://StemTherapyCost.com/ Saccardi R. Autologous hematopoietic stem cell transplantation for the treatment of multiple sclerosis.