或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
in addition to such security measures, the Canadian applications for gaming also promote responsible conduct of exciting gambling by providing different devices, like the ability to limit deposits, https://www.axime.co/2025/04/13/unlock-exclusive-benefits-with-betwinner-code/ betting and time spent on the portal.
Este verano deseo edificar una instalacion de pergolas en mi patio. ¿Qué materiales son los mejores?
Thanks for the thorough analysis. More info at Clifton Construction-General Contractors Albany NY .
The crew at my native Deck Builder in Charlotte in Charlotte become seasoned and delivered stunning results.
Nicely done! Find more at پوشش ضد حریق .
Cosmetic dentistry has come such a long way, especially in Los Angeles! Whether it’s veneers or teeth whitening, the possibilities are exciting Cosmetic Dentist Sherman Oaks
Mental health awareness is growing, but we still have a long way to go—thank you for your part in it! Visit eating disorder treatment for further information!
Alcohol detox can be a challenging journey, but it’s the first step towards a healthier life! alcohol detox
Paxos Electric Company LLC delivered exceptional service as my go-to commercial electrician Paxos Electric Company LLC surge protection
Dr. Fisher’s Medical Weight Loss Centers have been a game changer for me with their Semaglutide program!
I’m thrilled with the results from Dr. Fisher’s Semaglutide program, especially here in Philadelphia, PA Dr. Fisher’s Medical Weight Loss Centers reviews
Miami auto transport services have made relocating so much easier! Miami auto shippers
Paxos Electric Company LLC delivered exceptional service as my go-to commercial electrician industrial electrical specialists near me
Curious what others prioritize most while selecting professional partners within this realm- would love hearing diverse opinions shared among fellow readers via ###anything### Sunshine Auto Transport’s Kissimmee
”After booking through them myself—I completely agree about how smooth things went at ##!# keyword#. Amazing!” Boynton Beach car transportation services
After researching, I found that some companies offer insurance for their Melbourne car shippers services—worth it!
Dr. Fisher’s Medical Weight Loss Centers have been a game changer for me with their Semaglutide program!
I’m thrilled with the results from Dr. Fisher’s Semaglutide program, especially here in Philadelphia, PA Dr. Fisher’s Medical Weight Loss Centers opening hours
Planning to relocate soon and considering a Homestead car moving company—any suggestions? Homestead car shippers
Thanks for the clear breakdown. More info at Auto repair shop near me .
Breaking down barriers surrounding language access ensures inclusivity among diverse populations facing challenges due language barriers…who else feels passionately about this issue?! addiction treatment
Can’t wait until my new ride arrives thanks to ### Sunshine Auto Transport’s Spring Hill
Just got a quote from Fort Liberty auto transport, and it seems very reasonable compared to others! Fort Liberty auto shipping
You’ve made some great points about preparation before starting a detox program—thank you! Learn more at drug detox .
Amazing how bustling this place gets; clearly, others recognize its excellence too!!!!! ###Anykeyword### best places to eat indian food
Don’t let logistics overwhelm you during a big move; utilize companies like ###anything###! Sunshine Auto Transport’s The Villages
Has anyone used a specific service from a Brandon mover? My go-to is definitely listed on Brandon car shipping .
Just a heads-up: make sure to check insurance options when choosing a Doral auto transport provider! Sunshine Auto Transport’s Doral
The Injury Recovery Center has been a lifesaver for my back pain!
I can’t believe the difference a chiropractor makes at the Injury Recovery Center!
Looking for a chiropractor near me led me to the amazing team at Injury Recovery Center Holistic pain management Lakewood CO
Drug rehab can be a life-changing experience for many individuals. If you’re seeking help, check out drug rehab for valuable resources.
“Wonderful experience thus far exploring potential avenues together; thrilled about prospects ahead alongside everyone working diligently found via【 #】!” keyword targeting san jose
Reasons Why Online Casinos Are Booming
The surge in popularity of online casinos is driven by several factors. Perhaps the most appealing aspect is how easy it is to access games. Unlike physical casinos that have operating hours, online platforms operate 24/7, letting players enjoy their favorite games at any time.
One of the strongest attractions is the enormous range of gaming options available. While land-based venues have space constraints, online casinos provide an endless assortment of games. Whether you love old-school slots or cinematic video games, there’s something for everyone. Stay updated with the latest casino news, exclusive bonuses, and expert tips—follow us here! – https://thepetsclub.top/2024/12/10/1win-la-eleccion-definitiva-para-apuestas-y-casino-en-linea-2/
Bonuses, Rewards, and Promotions
Bonuses and special offers make online gambling even more enticing. New players are often welcomed with attractive sign-up bonuses, deposit matches, and free spins. Regular players can take advantage of loyalty programs, cashback deals, and exclusive VIP rewards. Depending on your preferences, you can choose between pure chance games or those where skill makes a difference. In games like poker, knowledge and tactics can give players a significant edge over less experienced opponents. If you prefer a fast-paced, unpredictable experience, slots and roulette provide thrilling, luck-based gameplay.Responsible Gambling & Choosing a Safe Casino
As exciting as online gambling can be, it’s essential to practice responsible gaming. Smart bankroll management and self-control help players maintain a healthy approach to gambling. Licensed casinos provide responsible gambling measures, such as cooling-off periods and withdrawal restrictions, to help players stay in control. Do you enjoy online casinos? What are your favorite games and biggest wins? Drop your opinions and stories in the discussion thread!
“This is such an important topic for those living in LA! Will reach out to English Rodent Control Inc.” maps.app.goo.gl
Надежные каркасные дома с подключением к коммуникациям
каркасные дома строительство karkasnye-doma-msk-pod-kluch.ru .
Certainly encouraging individuals contemplating journeys involving automotive transitions embrace opportunity presented before them recognize importance associated coordinating properly ensuring seamless integrations occur naturally occurring linked Sanford vehicle shippers
Just discovered that ## Jupiter vehicle shipping
Do you have any tips on finding discounts for vehicle shipping services in Ocala? Ocala auto transport companies
Just finished using Lauderhill auto transport services from Lauderhill car transport , and it was seamless!
Really respect the insight—I’ll honestly be trusting #whatever# with my subsequent venture! TV Mounting Charlotte
”Personable interactions along routes traveled maintained throughout provided exceptional value making experiences memorable overall!!!! ### an yKey word ###” Weston vehicle transport
The drivers at Weston car transportation services know all the best routes around Wesley Chapel! Makes traveling so much easier!
I love how easy it was to schedule my vehicle transport in St Cloud through St Cloud auto shippers .
I’ve been looking for reliable car transport in Kissimmee. This article gives me hope! Kissimmee vehicle transport
This was very well put together. Discover more at ربات های هوش مصنوعی تلگرام .
“These breathtaking visuals help create excitement around listings; fantastic work by Golden State Visions!” # # anyKeyWord ## modern real estate imaging
Puget Sound Moving Seattle made our transition so smooth, their professional movers near me were efficient and careful with all our belongings!
The team at Puget Sound Moving Seattle went above and beyond moving company near me
Nicely done! Discover more at Google ads expert .
Puget Sound Moving Seattle made our transition so smooth, their professional movers near me were efficient and careful with all our belongings!
The team at Puget Sound Moving Seattle went above and beyond movers Seattle
Puget Sound Moving Bellevue made our transition so smooth, truly the best moving company near me I could have found!
The team at Puget Sound Moving Bellevue handled our furniture with incredible care Bellevue moving and storage solutions
Thanks for the insightful write-up. More like this at Pest control service Davenport IA .
Your post reminded me that my lawn needs aeration! Time to call Lawn treatment services Lubbock for some help.
LuxNeuro’s neurofeedback therapy has transformed my life with its effective techniques!
The neurofeedback sessions at LuxNeuro are truly life-changing.
I’ve never felt better since starting neurofeedback at LuxNeuro Brainwave therapy Denver