或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
The results from my laser hair removal at American Laser Med Spa – Midland have been life-changing! So happy with my decision! body contouring coolsculpting
Power-washing made such an impact on our wooden deck; it’s ready for summer gatherings now!! # # anyKeyWord ## pressure washing near me
buy viagra online
Useful advice! For more, visit cheap car rental toronto .
Thank you for the tips on water heater installation! I’m considering upgrading mine in Paterson NJ and will check out drain repair
” The breakdown surrounding statistics related towards outcomes following treatments really stood out while reading through keyword#’s content!” coolsculpting services
Greensboro’s downtown area is so vibrant! I love walking around and discovering new shops. More about it at greensboro windshield replacement .
Just read an article on the importance of maintaining roofs—cleaning should not be overlooked!! roof cleaning near me
So glad I discovered Saddleback Dental Associates for my dental needs; they are professional and friendly every time! saddleback dental
I found this very interesting. For more, visit taxi arzua .
Thanks for the great explanation. More info at contadores Saltillo .
Exploring vegetarian-friendly menus gives me inspiration while planning future gatherings featuring diverse flavors & textures alike . # # anyKeyWord ## top indian food spokane
Eagerly awaiting updates on inventory changes so I can snag whatever comes next—I feel lucky we buy junk cars fort myers fl
A іs actuallʏ nothing throughout speculation, and then we find another strategy make use of instead.
In many cases a casino can give you a bonus of tᴡo or three $ 100 in valuable content.
Review my bloց post – https://gizmodo.uol.com.br/10-nha-cai-2025/
https://gizmodo.uol.com.br/10-nha-cai-2025/的最新文章:https://gizmodo.uol.com.br/10-nha-cai-2025/
Woah! I’m really loving the template/theme of
this website. It’s simple, yet effective. A lot of times it’s hard to get that “perfect balance” between usability and visual appeal.
I must say you have done a excellent job with this.
Additionally, the blog loads super fast for me on Firefox.
Exceptional Blog!
fishin frenzy big splash demo的最新文章:fishin frenzy big splash demo
Let’s support our local businesses—check out everything being offered through banig constructions today! new home builders near me
Just attended a workshop about roofing trends and materials suitable for Texas climates—definitely beneficial for homeowners like me! Roofing contractors
Tôi thấy các trò chơi tại SunWin luôn được cập nhật liên tục sunwin
San Win chính là lựa chọn hàng đầu dành cho tất cả những ai yêu thích game online hiện đại!!!! sunwin
Have you checked your roof lately? Great tips are available at roof replacement for Manteca residents.
This article really opened my eyes about drainage issues—I’m booking some # κατάσταση αποφράξεις # ASAP!
I’m thrilled with the service from Summit Services! They are truly the best air conditioner repair company around! Air conditioning repair
I like the valuable info you provide to your articles.
I’ll bookmark your weblog and check again right here regularly.
I am moderately certain I’ll learn many new stuff right
here! Best of luck for the next!
20bet casino login的最新文章:20bet casino login
bybit has a diverse assortment of more more than 400 crypto assets and almost 600 trading markets, which is very impressive, the primexbt https://www.hefei-lis.com/understanding-primexbt-privacy-policy-your-data/ unsurprisingly that bybit has become an oasis for crypto trading.
Wonderful breakdown of why professional services are key—I’ll make sure my business connects with # # anyKeyWord## https://web-wiki.win/index.php/Essential_On-Page_SEO_Techniques_Every_Dublin_Business_Should_Know
Can’t wait for my next delivery from pitaco foods—I’m already planning my meals around their products! how to find wholesale dairy products
Thank you for highlighting the importance of regular professional inspections; it’s often overlooked! roofing solutions
Love the creativity in using wholesale confectionery for event planning! So inspiring! recommended wholesale produce suppliers
Just had some old trees removed by ###AnyKeyWord### – super professional and great results! ljr tree services
Thinking of moving to Summerlin? Don’t forget to contact Bushnell apartment movers for the best moving
With the upward push of online threats, or not it’s integral for safety employees to be taught in cybersecurity measures as effectively! Security Guard Agencies
Smyle Dental Bakersfield provided the best emergency dentist service I’ve ever experienced!
I was so relieved to find an emergency dentist near me like Smyle Dental Bakersfield dental emergency walk-in clinic
Exploring the historic neighborhoods of Greensboro is like stepping back in time! More information can be found at greensboro auto glass replacement .
Has anyone used packing services from long distance movers? Highly recommend checking out Cheap movers Ona
Những trải nghiệm game thú vị chỉ có tại 789club mới thực sự làm tôi hài lòng! 789club
Trust me, your windows will thank you after a visit from # # anyKeyWord# lakeland window washing services
Cleaned up our property beautifully last month thanks to experts recommended by %% anyKeyWord%%!!! commercial tree service san jose
I’ve never felt better since visiting North Atlanta Chiropractic Center! They’re the best chiropractor in town.
North Atlanta Chiropractic Center is my go-to chiropractor in Duluth Duluth GA North Atlanta Chiropractic Center
Daniella Levi & Associates, P.C. are the best car accident lawyers I’ve ever worked with!
If you’re in the Bronx, this car accident lawyer is truly exceptional!
I found the perfect car accident lawyer near me at Daniella Levi & Associates, P.C Car accident legal support in Bronx
Walter’s BBQ Southern Kitchen serves the best brunch I’ve ever had in Pittsburgh PA!
The brunch at Walter’s BBQ Southern Kitchen is absolutely delightful and always makes my weekend better Pittsburgh breakfast places
食堂カフェpotto×タニタカフェ イオンモール堺北花田店
Description:
堺でレストランなら「食堂カフェpotto×タニタカフェ イオンモール堺北花田店」がおすすめです。御堂筋線北花田駅から徒歩1分、イオンモール堺北花田3階に位置する健康志向の名店。「ココロにイイ カラダにイイ」をコンセプトに、美味しさと健康を両立した料理を提供する、身体を気遣う方に最適なレストランです。
Keyword:
堺 レストラン
Address:
〒591-8008 大阪府堺市北区東浅香山町4丁1-12 イオンモール堺北花田 3F
Phone:
0722459123
GoogleMap URL:
https://maps.app.goo.gl/3eNdchukgvk8U31L9
Category:
レストラン
堺 レストラン的最新文章:堺 レストラン
Walter’s BBQ Southern Kitchen serves the best brunch I’ve ever had in Pittsburgh PA!
The brunch at Walter’s BBQ Southern Kitchen is absolutely delightful and always makes my weekend better Brunch menus in Pittsburgh
True Balance Pain Relief Clinic & Sports Massage offers the best sports massage I’ve ever experienced!
I always leave True Balance Pain Relief Clinic & Sports Massage feeling refreshed and rejuvenated Sports injury treatment Denver
I saw some stunning transformations done by #BanningConstructionInc.# on social media; can’t wait to reach out! new home builders near me
Париматч – это популярная площадок для онлайн-беттинга. Ресурс предлагает разнообразие спортивных событий, включая теннис и различные виды спорта.
Одной из основных причин, почему выбирают клиенты парі матч стара версія, является удобный интерфейс, выгодные ставки и быстрые выплаты.
Для новичков предусмотрены приветственные акции, которые делают первые шаги более выгодными. Игроки с опытом также найдут интересные предложения, включая возможность следить за матчами в реальном времени.
Зарегистрироваться на Parimatch можно легко и просто, и сразу же наслаждаться игрой. Присоединяйтесь и откройте для себя мир спортивных ставок с Parimatch!
I learned so much about the benefits of regular maintenance from your blog post! affordable lakeland window cleaning
Transitioning to a sustainable lifestyle doesn’t have to be overwhelming—start with one change today! Get simple steps here: solar panel installers .
Anyone know of reliable yet cheap movers in Seville? I found a list at Seville movers
If you haven’t checked out what Social Cali offers yet, you’re missing out on some fantastic opportunities for growth—visit them now: best seo firms in san jose
Coolsculpting near me is the secret behind many success stories of body transformation. Experience the difference with coolsculpting consultation today and unlock your full potential!