或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
This was beautifully organized. Discover more at Hibernia Bar .
What a difference a little paint can make! I got inspired by some projects I saw on house painters Alto Pro Painters Kelowna .
A solid understanding of local SEO principles is key in today’s market—trust me, it works wonders when done right with help from SEO services near me !
Appreciate the thorough analysis. For more, visit https://www.google.com/maps/dir/404+N+Cedar+St,+Summerville,+SC+29483/Roofing+Educators,+415+N+Main+St+unit+B,+Summerville,+SC+29483/@33.0251635,-80.1740914,390m/data=!3m2!1e3!4b1!4m14!4m13!1m5!1m1!1s0x88fe8b68452388ff:0x8e970f3b177cd4d5!2m2!1d-80.1744213!2d33.0258795!1m5!1m1!1s0xa32b693369667397:0x4daaa0dc5d5b3bc6!2m2!1d-80.171697!2d33.024044!3e0!5m1!1e3?entry=ttu&g_ep=EgoyMDI1MDIyNi4xIKXMDSoASAFQAw%3D%3D
Virtual gambling platforms have completely transformed the way people enjoy gambling. Delivering incredible accessibility, they enable users to play their gaming options from anywhere at any time. With an extensive library of games ranging from classic slots to interactive experiences and casino staples like baccarat, these sites cater to every preference.
Virtual gambling platforms have transformed the betting world, offering an exceptional degree of ease and breadth that conventional gambling houses struggle to rival. In recent years, a vast number of enthusiasts internationally have adopted the excitement of virtual casinos because of its anytime, anywhere convenience, captivating elements, and widening range of offerings.
If you’re unfamiliar with the world of virtual gambling or want to learn about proven options, why not join our lively social network? It’s a space where enthusiasts post stories, enabling you to get the most out of your gambling adventure. Discover the connections and visit us now: .
One of the strongest selling points of internet-based platforms is the sheer diversity of entertainment options available. Whether you enjoy spinning retro fruit machine slots, trying out narrative-rich visual slot games, or testing your strategy in traditional table offerings like poker, casino websites offer limitless opportunities. Plenty of operators moreover include live gaming streams, allowing you to interact with human game hosts and other players, all while immersing yourself in the authentic ambiance of a brick-and-mortar establishment from anywhere you want.
Useful advice! For more, visit roofing companies
Highly recommend Long distance movers Lochloosa if you’re looking for movers in Hawthorne—such a professional
.. Interested finding out how ordinarily men and women think of reassessing present routines periodically primarily based upon evolving talents won at some stage in event mutually shared among peers at the moment fascinated !! ### anything_keyword facial treatments Facials By Minna Kelowna
I found your insights into market analysis quite enlightening; very well written! real estate agency
buy viagra online
You can never be too prepared; make sure you have ### anyKeyword###’s number saved! emergency plumber
Find out about your medication’s initial impacts.
buy ivermectin stromectol
Get the genuine information on drugs. Read now.
Can’t stress enough how important it is to have a friendly and skilled Top-rated dentist near me ! Makes all the difference.
Internet-based gambling hubs have revolutionized the gambling world, offering an unmatched level of ease and breadth that physical gambling houses are unable to replicate. Over the past decade, millions of players around the world have welcomed the fun of online gaming thanks to its anytime, anywhere convenience, exciting features, and ever-expanding collections of titles.
If you’re new with the world of internet-based gaming or would like to find out more about reliable sites, why not become part of our vibrant gaming forum? It’s a platform where enthusiasts exchange reviews, enabling you to enhance your gaming journey. Explore the community and visit us now: https://menwiki.men/wiki/User:CharlaMcLellan
One of the most compelling reasons of virtual gambling hubs is the sheer diversity of gaming experiences ready to play. Whether you like spinning classic slot machines, immersing yourself in narrative-rich visual slot games, or strategizing in traditional table offerings like Blackjack, internet-based gambling sites deliver endless entertainment avenues. Numerous services also introduce interactive dealer games, enabling you to participate with real dealers and gaming peers, all while experiencing the authentic vibes of a physical gaming house right at home.
Apart from the game range, online casinos excel constant connectivity.
I’ve been considering chiropractic treatment since my accident; this article has motivated me to book an appointment! Work injury chiropractor Everett WA
A solid read filled with valuable insights into keeping pipes clear—I’m definitely going to recommend ### anyKeyWord### if anyone asks! Water heater installation Medford MA
Useful advice! For more, visit roofing contractor near me
This was very enlightening. More at dog boarding near me
Бонги
This is very interesting, You’re a very skilled blogger.
I’ve joined your rss feed and look forward to seeking more of your fantastic post.
Also, I have shared your website in my social networks!
big tits online free的最新文章:big tits online free
Helpful suggestions! For more, visit floral designers
Well done! Find more at ultrazvok mehkih tkiv .
This was a great help. Check out architect miami for more
My buddy had a great experience with a mishap attorney from slip and fall lawyer after her motorbike collision– extremely
buy viagra online
экскурсии казань посещением
Proudly supporting one another while navigating intricate details involved surrounding path leading up towards enhanced visual capabilities overall ###aynyKeyWord# evo icl portland
Great job! Find more at Hibernia Bar .
Smyle Dental Bakersfield provided the best emergency dentist service I’ve ever experienced!
I was so relieved to find an emergency dentist near me like Smyle Dental Bakersfield Smyle Dental Bakersfield oral surgery
I’ve never felt better since visiting North Atlanta Chiropractic Center! They’re the best chiropractor in town.
North Atlanta Chiropractic Center is my go-to chiropractor in Duluth Duluth GA chiropractic doctors
I found this very helpful. For additional info, visit roofing company nearby
Can’t say enough good things about the service from electrician ! Best electricians I’ve encountered in Chicago.
Daniella Levi & Associates, P.C. are the best car accident lawyers I’ve ever worked with!
If you’re in the Bronx, this car accident lawyer is truly exceptional!
I found the perfect car accident lawyer near me at Daniella Levi & Associates, P.C Car accident legal services by Daniella Levi & Associates
Using location-based hashtags can enhance your social media presence locally! More tips at professional SEO services .
Walter’s BBQ Southern Kitchen serves the best brunch I’ve ever had in Pittsburgh PA!
The brunch at Walter’s BBQ Southern Kitchen is absolutely delightful and always makes my weekend better Gluten-free brunch Pittsburgh
Online gaming sites have revolutionized the way people participate in betting. Featuring unparalleled convenience, these platforms allow players to engage with their most-loved choices on their schedule. With an extensive library of entertainment options ranging from reel games to real-time table games and casino staples like blackjack, these hubs cater to every gaming taste.
Digital casinos have revolutionized the betting world, delivering an unmatched level of accessibility and selection that physical venues can’t match. In recent years, countless gamblers globally have welcomed the excitement of digital casino play in light of its availability, engaging traits, and widening selection of games.
If you’re exploring for the first time with the world of online gaming or seek to explore safe services, why not engage with our active online hub? It’s a space where fans discuss stories, enabling you to get the most out of your casino activities. Discover the discussions and check it out now: .
One of the main appeals of internet-based platforms is the vast variety of titles on offer. Whether you love interacting with old-school reel games, playing through engaging video slots, or exercising tactics in classic casino games like poker, digital casinos provide countless entertainment avenues. Numerous services even introduce live dealer games, allowing you to connect with real dealers and opponents, all while experiencing the realistic environment of a land-based casino right at home.
If you’re looking for the best personal injury attorney in Fort Worth fort worth personal injury
I had an incredible experience at the Dental Group of Beverly Hills! The best dentist I’ve ever visited!
If you’re looking for a dentist near me how much is a dentist visit in Beverly Hills
I had an incredible experience at the Dental Group of Beverly Hills! The best dentist I’ve ever visited!
If you’re looking for a dentist near me Beverly Hills dentist for anxiety
This is my first time visit at here and i am genuinely
impressed to read all at alone place.
phim sex gái xinh còn trinh的最新文章:phim sex gái xinh còn trinh
I’ve seen a few accidents happen right before my eyes while driving in LA. Always drive defensively! car accident lawyer
I had a wonderful experience at Visual Eyes Optical Inc!
The eye doctor at Visual Eyes Optical Inc was incredibly helpful where to get eye exams in Stanhope
True Balance Pain Relief Clinic & Sports Massage offers the best sports massage I’ve ever experienced!
I always leave True Balance Pain Relief Clinic & Sports Massage feeling refreshed and rejuvenated Best muscle recovery treatments in Denver
Digital casinos have modernized the gaming market, offering a unique kind of ease and breadth that brick-and-mortar establishments can’t match. Over time, countless gamblers across the globe have adopted the fun of digital casino play in light of its anytime, anywhere convenience, appealing qualities, and progressively larger catalogs of games.
If you’re a beginner with the world of virtual gambling or are looking to explore reputable operators, why not participate in our lively online hub? It’s a platform where fans offer stories, making it easier for you to enjoy more of your virtual play. Dive into the experience and learn more now: https://40th.jiuzhai.com/space-uid-3151402.html
One of the most compelling reasons of virtual gambling hubs is the sheer selection of entertainment options on offer. Whether you love playing on old-school slot machines, trying out story-driven video-based games, or testing your strategy in strategy-based games like Roulette, virtual venues boast countless entertainment avenues. Several sites also feature real-time gaming experiences, making it possible for you to engage with live hosts and co-players, all while experiencing the realistic atmosphere of a land-based casino in your own space.
In addition to diversity, digital casino services excel ease of access.
Happy customers make me want to hire ####mywebsite#### right away; looks like they know how to keep costs down effectively! Office moving companies Ralls
Simply put—I’d encourage anyone hesitant begin reaching beyond comfort zones when ample opportunity exists around every corner as highlighted distinctly among offerings showcased within: **this Cheap movers Ocoee
This was a fantastic read. Check out payday loans new orleans la for more.
The last time I moved, I hired a Valrico full service movers from Valrico and they handled everything perfectly
Excited to see more companies offering innovative products related to nangs cylinder prices
This was very insightful. Check out implantologia warszawa for more.