或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
As a longtime resident of Tucson Tucson security experts
Thanks for the great explanation. More info at Accident Lawyer Costa Mesa
Thanks to @@###for helping me find reliable moving companies when I relocated to beautiful North Richl Office moving companies North Richland Hills
“Sidewalks might seem minor but they matter a lot; keep them pristine with help from # # any Keyword # # sidewalk repair nyc
This online casino brings you an exceptional online gaming experience with its main platform and mobile application . Whether you choose to gamble on your computer or smartphone , the mobile gaming option ensures easy entry to engaging betting options and betting opportunities. Don’t miss out on the efficiency of the Mostbet APK for Android users , ensuring hassle-free and easy installation . Start your adventure today by signing into your account or signing up !
Step into the official Mostbet online casino platform in Bangladesh! Enjoy a uninterrupted betting adventure with a vast selection of engaging games and features . Mobile App for Mostbet : Play your top gambling features on the go by installing the mobile app . Available for both Android and iOS devices , the app ensures a smooth and secure gaming experience . Mostbet Login : Effortlessly log in to your user profile using your credentials . If you haven’t signed up yet, creating an account is quick and hassle-free .
Link: https://www.icicifellows.org/mostbet-casino-app-apk-free-download-for-android-and-ios/
Mostbet APK : For those on Android , the Mostbet APK file provides a easy and smooth installation process . Always check you install the newest release for the best performance . Play alongside casino enthusiasts who rely on Mostbet for their gambling adventures . Whether you enjoy slots , table games , or live dealer experiences, everything is available on Mostbet . Explore the Mostbet main site . Create your account or log in .
Check out the exciting casino collection .
Download the Mostbet app for seamless gameplay.
Don’t miss out of the fun ! Begin your adventure with Mostbet now and enjoy top-notch online casino entertainment in Bangladesh.
The importance of regular maintenance for towing vehicles can’t be stressed enough! Great post! Learn more at heavy duty towing
Has anyone ever used #### anykeyword####’s express service? How quick was it compared to Jacksonville car moving companies
Virtual gambling platforms have reshaped the gambling market, offering a unique kind of comfort and breadth that physical venues are unable to replicate. Over the past decade, countless gamblers globally have chosen the pleasure of internet-based gaming because of its anytime, anywhere convenience, captivating elements, and constantly growing selection of games.
If you’re a beginner with the world of internet-based gaming or hope to delve deeper into safe services, why not participate in our lively social network? It’s a platform where fans discuss reviews, enabling you to enhance your gaming journey. Check out the conversation and see it here now:
One of the biggest attractions of online casinos is the unparalleled range of titles available. Whether you like engaging with retro slots, immersing yourself in story-driven modern slot games, or testing your strategy in strategy-based games like Blackjack, internet-based gambling sites feature infinite choices. A large number of platforms also offer interactive dealer games, giving you the chance you to engage with professional croupiers and gaming peers, all while soaking in the engaging vibes of a brick-and-mortar establishment from the comfort of your home.
Besides the wide selection, virtual gaming providers stand out seamless entry.
عيش إثارة اللعب مع كازينو 888! casino 888 هل تبحث عن تجربة لعب فريدة؟ كازينو 888 هو المكان المناسب! مع مجموعة رائعة من الألعاب، ودعم دائم، لا تفوت فرصة الفوز الكبيرة. انضم اليوم! casino 888
It’s plain obvious that quality matters when working within this industry & calabraseFlooringCo certainly delivers upon those st Hardwood floor installation
Honestly shocked by how many unique items are sold here too; so much more than just basic car necessities!!! scrap car buyers Venice FL
Wow board up windows
Never met more friendly individuals dedicated towards ensuring clients receive highest level satisfaction possible before leaving premises Just Trees Tree Trimming
Thanks for the helpful advice. Discover more at stomatologia dziecięca warszawa
Sevdiğiniz müziklerle birlikte geçirdiğiniz en güzel anılarınızı paylaşın lütfen… Nurgile keyfiyle birleşince daha eğlenceli oluyor.. nargile kömürü markaları
Attractive section of content. I just stumbled upon your weblog
and in accession capital to assert that I get in fact enjoyed account your blog
posts. Anyway I’ll be subscribing to your feeds and even I achievement you access consistently rapidly.
Also visit my page; zabaioc01
zabaioc01的最新文章:zabaioc01
This was very enlightening. For more, visit payday loans new orleans la
Well done! Find more at cheap car rental
Virtual gambling platforms have changed the gambling world, providing a unique kind of comfort and breadth that traditional establishments struggle to rival. Over the past decade, millions of players internationally have welcomed the adventure of online gaming in light of its availability, thrilling aspects, and progressively larger range of offerings.
If you’re new with the world of virtual casino play or seek to discover proven options, why not join our growing community? It’s a platform where enthusiasts offer insights, enabling you to get the most out of your casino activities. Discover the community and see it here now:
One of the key draws of virtual gambling hubs is the sheer range of titles available. Whether you love spinning traditional reel games, diving into theme-based video-based games, or mastering skills in table games like Baccarat, online platforms feature numerous possibilities. Plenty of operators furthermore feature live casino options, enabling you to engage with human game hosts and gaming peers, all while soaking in the realistic vibes of a land-based casino right at home.
In addition to diversity, digital casino services shine ease of access.
Appreciate the detailed information. For more, visit casas rurales Segovia
Experiencing protected is a priority for everyone, as well as possessing security guards may substantially boost that sensation! Discover a lot more concerning their usefulness at security guards austin
Just picked up my custom embroidered sweatshirt, and it’s perfect! Highly recommend this Austin shop at Hand embroidery patterns
Great job! Discover more at taxi arzua
Myfriendrecommendedtree stone’sservicesafterexperiencingtheirworkfirsthand TreeStone Security in Tucson
I can’t stress enough how beneficial it is to have a dedicated car accident attorney by your side during tough times like these in Kennewick! local injury law firms
Just shared this resource with my friend who needed guidance – thanks criminal lawyer
My experience with motorcycle transport from LA was surprisingly affordable—definitely worth looking into if you’re moving! shipping motorcycles Los Angeles
Appreciate the thorough insights. For more, visit North Atlanta Chiropractic Center
Really enjoyed this article about septic tank care; it’s so important not just for home health but also environmental reasons—more info at septic tank pumping
Digital casinos have changed the gaming landscape, offering an unmatched level of user-friendliness and selection that brick-and-mortar establishments fall short of. In recent years, a large audience across the globe have turned to the excitement of digital casino play due to its ease of access, exciting features, and ever-expanding range of offerings.
If you’re a beginner with the world of internet-based gaming or seek to find out more about proven options, why not become part of our growing gaming forum? It’s a space where gamblers post insights, helping you to get the most out of your gaming journey. Discover the connections and visit us now: https://www.fire-directory.com/%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C-1%D0%B2%D0%B8%D0%BD_474687.html
One of the key draws of internet-based platforms is the astounding diversity of titles on offer. Whether you enjoy rolling retro reel games, immersing yourself in narrative-rich modern slot games, or strategizing in strategy-based games like Baccarat, virtual venues provide countless opportunities. Numerous services also introduce real-time gaming experiences, giving you the chance you to interact with real dealers and other players, all while experiencing the lifelike atmosphere of a brick-and-mortar establishment in your own space.
In addition to diversity, internet-based gambling hubs excel ease of access.
Very shortly this web site will be famous among all blogging
and site-building visitors, due to it’s fastidious content
Also visit my web blog; дезинсекция в Архангельске
дезинсекция в Архангельске的最新文章:дезинсекция в Архангельске
Niezwykle pomocne wskazówki dla początkujących – dziękuję i pozdrawiam z projektowanie stron
Hello there, There’s no doubt that your web site may be having browser compatibility problems.
Whenever I look at your web site in Safari, it looks fine however,
if opening in I.E., it’s got some overlapping issues.
I merely wanted to provide you with a quick heads up!
Other than that, excellent site!
plinko game的最新文章:plinko game
Getting rid of mold was easier than expected thanks to # # expert power washing Tampa
Moving soon? You should definitely consider the top-rated movers listed on North Richland Hills commercial movers
Pin Up Casino в Казахстане – это лучший выбор среди казино для почитателей азартных развлечений. Здесь предлагаются уникальные возможности для весёлого досуга и выигрышей. Если ищете идеальное место для ставок, то Pin Up Казино подойдёт вам идеально.
Преимущества Pin Up Казино
Многообразие игровых решений. В казино Pin Up представлено более двух тысяч игровых автоматов, игр с живыми крупье и автоматов. В каталоге игр представлены разработчики уровня Pragmatic Play и множество других компаний. Это значит, что вы сможете наслаждаться качеством и азартом, доступные на всех устройствах.
Разнообразные бонусы для игроков. Новые игроки получают щедрые приветственные бонусы, которые помогут быстрее начать выигрывать. Регулярные акции увеличат ваши выигрыши, ежедневные розыгрыши и фриспины для игроков на постоянной основе, что обеспечивает ещё больше шансов на выигрыш.
Наш сайт: http://oapr.edu.kz/23/?news=%D0%BA%D0%BB%D0%B0%D1%81%D1%81%D0%BD%D1%8B%D0%B9-%D1%87%D0%B0%D1%81-5&lang=ru
Полная безопасность и защита. Pin Up Casino использует только проверенные методы защиты данных пользователей, обеспечивая конфиденциальность и безопасность. Лицензия гарантирует обеспечивает честность и выплаты и мгновенные выплаты выигрышей.
Лёгкий доступ к играм. Платформа казино легко доступно через мобильные устройства, что даёт возможность играть в любые игры в любых условиях. Доступно мобильное приложение или просто запустить игры через браузер.
Профессиональная поддержка. В любой проблеме, служба помощи всегда готова к общению. Вы можете связаться с операторами через удобный чат, и специалисты решат проблему на вашем языке.
Every time I walk my dog concrete sidewalk repair
Thanks for the detailed post. Find more at colchones en Albacete
Has anyone used ### anyKeyWord#### for international vehicle shipping? What’s the process Jacksonville vehicle shipping
This is highly informative. Check out sex jav for more
Модульные дома — это современное решение для комфортного загородного жилья. Мы предлагаем широкий ассортимент домокомплектов, включая одноэтажные и двухэтажные модели. Каждая планировка включает функциональные комнаты, такие как гостиная, кухня и спальня. Мы заботимся о вашем комфорте, предлагая стильные варианты отделки и качественное утепление. Строительство модульного дома — это быстро и бюджетно. Вы сможете самостоятельно адаптировать проект, выбрав мебель и сантехнику. Пора строить мечту – https://pkf-stroitel.ru/
Nice blog here! Additionally your site loads up fast!
What host are you using? Can I get your affiliate link for your host?
I desire my web site loaded up as quickly as yours lol
Take a look at my blog … zabaioc01
zabaioc01的最新文章:zabaioc01
Тебе нужны моды для Android-игр? Заходи на **[url=https://xmoddroid.ru]xmoddroid.ru[/url]**! Здесь ты найдешь проверенные взломы для Android. Бесконечные деньги – всё это доступно бесплатно. Все файлы проверены.
Fishing Frenzy remains one of the most enduring as one of the most popular slot games in the realm of virtual slots. With its bright and engaging underwater theme, easy-to-learn controls, and lucrative elements, it has captured the attention of players worldwide. Unlike today’s feature-packed slot machines that rely on intricate bonus rounds and complex mechanics, free fishing frenzy a classic slot experience with a fun twist. Over the years, several versions have been released, including the Big Splash edition and Fishing Frenzy Even Bigger Catch Demo, each adding exciting updates while maintaining the core appeal. Whether you prefer a no-risk Fishing Frenzy experience or try it on your mobile device, there are plenty of options to dive into this slot. Players can enjoy different versions of Fishing Frenzy demo play to try it out before betting for real, making it an easy-to-try and adaptable game for both casual and serious players.
Fishing Frenzy was originally developed by Reel Time Gaming and later distributed by Blueprint Gaming, respected leaders in casino game development. The game quickly earned a loyal following due to its blend of accessibility and entertainment. Unlike modern slots that often feature dozens of paylines, multi-stage bonus features, and overly complex rules, Fishing Frenzy delivers a classic slot experience that appeals to both beginners and seasoned players. The game’s theme revolves around a relaxing fishing trip, where players cast their lines in hopes of reeling in valuable fish symbols. The cheerful and colorful graphics depict a visually striking ocean theme, a sturdy angler’s ship, and a friendly fisherman character who plays a crucial role in the game. The carefully crafted sounds add depth to the gameplay, with relaxing ocean effects and cheerful music that bring the fishing theme to life. A key reason for the game’s longevity is how it refreshes itself without losing its essence. New versions like Fishing Frenzy: Big Splash Edition and Fishing Frenzy Even Bigger Catch Demo introduce updated graphics and additional in-game perks, keeping the game modern yet familiar while maintaining the beloved core gameplay.
Thanks for highlighting the importance of timely board up services after property damage! It’s crucial to act fast! board up windows
Pin Up Казино на просторах Казахстана – это казино с хорошей репутацией для игроков, любящих азарт. Здесь созданы все условия для выигрышей для развлечений и крупных выигрышей. Если вы любите играть в хороших казино, то Pin Up Casino станет идеальным выбором.
Преимущества Pin Up интернет-казино
Широкий выбор игр. Игрокам предлагается более 2000 различных игр, игр с реальными дилерами. В ассортименте представлены такие известные разработчики, как Play’n GO и другие. Это значит, что каждая игра обеспечит захватывающий опыт, доступные на всех устройствах.
Бонусы для всех игроков. Каждый новый игрок получит увеличенные стартовые бонусы, которые позволят начать с большим преимуществом. Постоянные акции и розыгрыши тоже доступны, ежедневные розыгрыши и фриспины для постоянных пользователей, что делает игру ещё более захватывающей и выгодной.
Наш сайт: https://bk.kz/news/?ELEMENT_ID=3390&PAGEN_2=8
Безопасность и надежность. Pin Up Казино применяет самые новые технологии защиты персональной информации, чтобы гарантировать защиту данных. Лицензия гарантирует гарантирует выплату всех выигрышей и быстрые выплаты призов.
Доступность на всех устройствах. Pin Up полностью оптимизировано для мобильных устройств, что позволяет наслаждаться игрой в любом удобном месте. Приложение казино доступно для скачивания или просто запустить сайт казино с телефона.
Поддержка клиентов. В случае возникновения вопросов, наша служба поддержки всегда готовы решить любые вопросы. Вы можете обратиться за помощью через онлайн-чат, и операторы ответят быстро на удобном языке.
ExcellentcustomerexperiencefromstarttofinishdefinitelysetsapartwhatmakesTree TreeStone Tucson specialists
Is there a specific auto parts store in Punta Gorda FL that specializes in vintage cars? scrap car buyers Venice FL
Pretty element of content. I simply stumbled upon your weblog and in accession capital to
say that I get actually enjoyed account your blog posts.
Any way I will be subscribing for your augment
or even I achievement you get admission to
persistently rapidly.
slow roads,slow roads io的最新文章:slow roads,slow roads io
Ищешь моды для Android-игр? Тогда заходи на xmoddroid.ru! Мы предлагаем только проверенные взломы для Android. Бесконечные деньги – всё это доступно бесплатно. Добавляем новые моды ежедневно.