或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
Rất thích cách bạn phân tích các trận đấu trên Trang Cá Cược Bóng Đá. Mình sẽ giới thiệu cho bạn bè! https://csgfc.mypixieset.com/
Need a full roof replacement in Austin? Life Roofing uses premium materials and offers financing options to fit your budget. roof shingles austin
Hey people,
I’ve been diving into the world of virtual casinos lately, and I’ve gotta say — it’s way more exciting than I expected. At first, I was honestly suspicious. I mean, how do you even believe in an online platform with your money, right? But after digging deep (and trying out a few questionable sites so you can avoid that mess), I figured out a few things that set apart a trustworthy casino from a risky mess. First off, if you’re new to all this, here’s the golden rule: **licenses matter**. If a casino doesn’t have a proper regulatory certificate (like from the Malta Gaming Authority or the UK Gambling Commission), just walk away. No bonus is worth the gamble of never seeing your money again. Also — and I know no one wants to — check the terms. That’s the only way to know what kind of playthrough limits they’ve slapped onto those so-called “generous” bonuses.
Now, let me share a site I’ve been using these last few weeks. It’s been a total win. The interface? Super clean. Payouts? Quick — like 24 hours quick. And the game selection? *Wild*. Slots, live dealers, blackjack, even some unique stuff I hadn’t tried before. Check it out here: http://pasarinko.zeroweb.kr/bbs/board.php?bo_table=notice&wr_id=4554761 What really won me over was the customer service. I had a tiny issue with a bonus not working, and they got back to me in like 10 minutes. Compare that to other sites where you’re just left hanging — yeah, no thanks.
Also, if you’re into bonuses (and who isn’t?), this place offers some juicy ones. But here’s the trick: don’t just grab every shiny offer. It’s smarter to get clear terms than a huge bonus you’ll never be able to withdraw. I’m not saying you should go and bet the farm — please don’t. But if you’ve got a little extra spending money and you’re looking for a fun way to unwind, online casinos can totally deliver. Just keep your head on, control your bankroll, and don’t treat it like a side hustle. It’s for fun, not for a paycheck. Anyway, just wanted to drop my experience here in case anyone’s curious or trying to find a decent place to play. If you’ve got your own recommendations or even some horror tales, I’m all ears — love talking shop about this stuff.
Good luck out there, and may the odds be ever in your favor ??
Hãy cùng nhau khám phá thế giới cá độ đầy thú vị tạiTrangCÁCượCBÓNGĐÁ!!! Sports Blog
This was very beneficial. For more, visit abogados en A Coruña .
Has anyone used the services of an HVAC contractor from ac repair Santa Monica ? I’d love to hear about your experience!
Valuable information! Find more at contador Saltillo .
Why Online Casinos Are Becoming Highly Preferred Worldwide
Digital casinos have reshaped the gambling world, providing a level of comfort and diversity that physical gambling houses fall short of. In recent years, countless gamblers around the world have welcomed the pleasure of virtual gambling because of its ease of access, engaging traits, and continuously increasing collections of titles.
One of the strongest selling points of online gaming options is the sheer range of gaming experiences at your disposal. Whether you prefer playing on vintage reel games, trying out story-driven thematic slots, or playing smart in table games like Baccarat, digital casinos provide countless entertainment avenues. Several sites also feature interactive dealer games, making it possible for you to communicate with human game hosts and co-players, all while enjoying the immersive atmosphere of a real casino right at home.
If you’re unfamiliar with the world of online gaming or hope to discover reliable sites, why not participate in our lively community? It’s a place where fans discuss insights, guiding you to enjoy more of your gaming journey. Check out the community and start your journey now: вавада вход.
In addition to diversity, internet-based gambling hubs thrive in ease of access.
This was quite useful. For more, visit نیکان ترخیص سازگار .
Thanks for the thorough analysis. Find more at taxi Arzua .
I never realized how important it is to know when to call a plumber. Your post has definitely opened my eyes! For additional resources, head over to Taekwondo in Denver .
”Very informative post—looking forward toward connecting with %%(ANYKEYWORD) soon!” pest control Fort Lauderdale
The ease of acquiring and by using nang chargers is rather fabulous nowadays; what are your recommendations on availability traits? Discuss it here: Nang tank suppliers local !
Howdy would you mind stating which blog platform you’re working with?
I’m going to start my own blog in the near future but
I’m having a tough time selecting between BlogEngine/Wordpress/B2evolution and Drupal.
The reason I ask is because your design and style seems different
then most blogs and I’m looking for something completely unique.
P.S Apologies for being off-topic but I had to
ask!
women lingerie的最新文章:women lingerie
Has anyone used long distance movers Macclenny recently? I’d love to hear about your experience! Macclenny commercial movers
If you’re looking for a top-notch marketing agency in Temecula, CA, you should definitely check out marketing agency temecula . They have amazing services!
Thanks for the detailed post. Find more at The Bud Depot .
The creativity of designers in sign shops is top-notch! Explore unique options available at sign shop near me .
Birçok farklı platformda oyun oynamayı seviyorum ama bazılarında gerçekten zorlanıyorum!!!# # anyKeword ## Deneme Bonusu 2025
Hey everyone,
I’ve been getting into the world of internet gambling lately, and I’ve gotta say — it’s pretty damn addictive. At first, I was super skeptical. I mean, how do you even rely on an online platform with your cash, right? But after digging deep (and trying out a few sketchy sites so you don’t have to), I figured out a few things that distinguish a reliable casino from a complete fraud. First off, if you’re new to all this, here’s the golden rule: **regulation is key**. If a casino doesn’t have a proper legal status (like from the MGA or the UK Gambling Commission), just run. No bonus is worth the trouble of never seeing your money again. Also — and I know no one wants to — go through the small print. That’s the only way to know what kind of playthrough limits they’ve slapped onto those so-called “juicy” bonuses.
Now, let me share a site I’ve been hooked on these last few weeks. It’s been a game-changer. The interface? Super easy to navigate. Payouts? Fast as hell. And the game selection? *Insane*. Slots, live dealers, blackjack, even some unique stuff I hadn’t tried before. Check it out here: http://meetengreet-leiden.nl/2013/11/hello-world/dsc07087/ What really won me over was the customer service. I had a tiny issue with a bonus not working, and they got back to me in like 10 minutes. Compare that to other sites where you’re just shouting into the void — yeah, no thanks.
Also, if you’re into bonuses (and who isn’t?), this place offers some legit ones. But here’s the trick: don’t just grab every shiny offer. It’s smarter to go for reasonable terms than a huge bonus you’ll never be able to withdraw. I’m not saying you should go and blow your whole paycheck — please don’t. But if you’ve got a little extra cash and you’re looking for a chill way to spend an evening, online casinos can totally deliver. Just play smart, set a budget, and don’t treat it like a side hustle. It’s for fun, not for a paycheck. Anyway, just wanted to drop my experience here in case anyone’s looking for solid info or trying to find a decent place to play. If you’ve got your own go-to sites or even some casino nightmares, I’m all ears — love talking shop about this stuff.
Good luck out there, and may the odds be ever in your favor ??
The excitement around upcoming tournaments is palpable; can’t wait for all the action ahead! Stay tuned for tournament previews at csgfc !
Anyone else had great luck with AC repairs from heating repair Santa Monica ? They really saved me during this hot season in Santa Monica!
Reasons Why Online Casinos Are Becoming Highly Preferred Worldwide
Internet-based gambling hubs have modernized the casino gaming scene, providing an exceptional degree of comfort and selection that land-based casinos don’t provide. Recently, countless gamblers worldwide have adopted the adventure of internet-based gaming due to its availability, thrilling aspects, and widening range of offerings.
One of the biggest attractions of digital gambling sites is the unparalleled range of titles ready to play. Whether you love engaging with vintage slot machines, trying out narrative-rich modern slot games, or mastering skills in table games like Roulette, virtual venues offer countless opportunities. Many casinos also include interactive dealer games, giving you the chance you to connect with live hosts and opponents, all while soaking in the realistic atmosphere of a traditional gambling venue from the comfort of your home.
If you’re just starting with the world of digital casinos or want to explore trusted platforms, why not participate in our dynamic interactive platform? It’s a hub where fans discuss stories, assisting you to enjoy more of your gaming journey. Dive into the experience and check it out now: vavada казино.
Adding to the extensive catalog, virtual gaming providers thrive in ease of access.
. Just got my first garden tools organized thanks to my new shed from ### – what an improvement! Sheds For Sale
So informative—I’m excited about getting my home treated by professionals at %%ANYKEYWORD%%. pest control company
I was impressed by how quickly marketing agency temecula was able to boost my website traffic after we started working together.
I found this very helpful. For additional info, visit نیکان ترخیص سازگار .
This was very beneficial. For more, visit Bud Depot product reviews .
Does anyone have tips on what to check before handing over your keys to Tyler vehicle shipping? Tyler auto shipping
Nicely detailed. Discover more at abogados A Coruña .
Having read this I thought it was very enlightening.
I appreciate you finding the time and energy to put this content together.
I once again find myself personally spending a significant amount of time both reading
and leaving comments. But so what, it was still worth it!
1win официальный сайт вход的最新文章:1win официальный сайт вход
Have you ever considered custom signs for your home? I discovered some amazing options at sign shop Austin !
Nicely done! Discover more at contadores Saltillo .
Selling my house quickly for funds changed into the fabulous selection I made! I chanced on a good useful resource at https://www.longisland.com/profile/ruvornhnzs/ that helped me due to the course of.
Great insights! Find more at taxis Arzua .
If you’re in New Braunfels and need to move a vehicle, check out New Braunfels car shippers .
I read this article completely about the resemblance of most recent and previous
technologies, it’s remarkable article.
bdg game hack.的最新文章:bdg game hack.
Does anyone know if Allen auto transport offers international shipping options? Allen auto transport companies
I never thought about asking about tracking options with my car shipment until reading this post—great point! Odessa car moving companies
Just used %%ANYKEYWORD%% again—always impressed by their quick turnaround time and friendly service! Car Recovery Dubai
Great job! Discover more at Bud Depot Recreational .
I’ve been struggling with a leaky faucet for weeks! Your suggestions are just what I needed. Explore more helpful content at Taekwondo in Denver .
Thanks for the helpful article. More like this at نیکان ترخیص سازگار .
Cihazınız varsa mutlaka buraya uğramalısınız!! Bosch Servis
I’ve been using the same AC repair company near me for years, and they never disappoint! AC repair near me
Last weekend’s baking session was a dream come true because of my amazing nang cylinder – can’t wait until next time – check back soon for updates : # # # Browse this site
The transformation I’ve experienced with Inner Evolution Fitness personal training has completely changed my approach to health and wellness!
My strength has doubled since starting at Inner Evolution Fitness Kettlebell training programs Denver CO
VIP Cleaners & Laundry always exceeds my expectations with their alterations near me!
I love getting my clothes altered at VIP Cleaners & Laundry in San Diego CA!
VIP Cleaners & Laundry is my go-to for perfect alterations!
Alterations near me have San Diego dry cleaning and alterations
The transformation I’ve experienced with Inner Evolution Fitness personal training has completely changed my approach to health and wellness!
My strength has doubled since starting at Inner Evolution Fitness Mobility training Denver CO
Walter’s BBQ Southern Kitchen serves the best brunch I’ve ever had in Pittsburgh PA!
The brunch at Walter’s BBQ Southern Kitchen is absolutely delightful and always makes my weekend better Walter’s BBQ Southern Kitchen contact