或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
From in which do other people routinely listen approximately opportunities linked manufactur ed housing ? Social media plays fantastic role nowadays!! # # anyKey phrase ## Manufactured home community
Puget Sound Moving Bellevue made our transition so smooth, truly the best moving company near me I could have found!
The team at Puget Sound Moving Bellevue handled our furniture with incredible care Office relocation Bellevue WA
If some one wishes expert view concerning running a blog then i
advise him/her to go to see this webpage, Keep up the
good job.
insurance policy consent specialist remote的最新文章:insurance policy consent specialist remote
Puget Sound Moving Bellevue made our transition so smooth, truly the best moving company near me I could have found!
The team at Puget Sound Moving Bellevue handled our furniture with incredible care Heavy furniture moving specialists
Having access to FAQ sections often clarifies confusion surrounding common concerns raised regularly — browse helpful articles presented clearly via # # anyKeyWord## roll off dumpster orlando
Hi there! I could have sworn I’ve been to this web
site before but after going through many of the posts I realized it’s new to me.
Nonetheless, I’m certainly delighted I discovered it and I’ll be bookmarking it
and checking back often!
biznes polska casino login的最新文章:biznes polska casino login
It’s amazing to pay a quick visit this web site and reading the views of all colleagues on the topic of this article, while I am also keen of getting familiarity.
Puget Sound Moving Seattle made our transition so smooth, their professional movers near me were efficient and careful with all our belongings!
The team at Puget Sound Moving Seattle went above and beyond movers near me
Puget Sound Moving Seattle made our transition so smooth, their professional movers near me were efficient and careful with all our belongings!
The team at Puget Sound Moving Seattle went above and beyond movers near me
If you might be given that promoting your home straight away, don’t underestimate the capability of earnings offers! Learn extra at https://www.spreaker.com/podcast/agnathpyrm–6602238 .
LuxNeuro’s neurofeedback therapy has transformed my life with its effective techniques!
The neurofeedback sessions at LuxNeuro are truly life-changing.
I’ve never felt better since starting neurofeedback at LuxNeuro LuxNeuro therapy sessions
LuxNeuro’s neurofeedback therapy has transformed my life with its effective techniques!
The neurofeedback sessions at LuxNeuro are truly life-changing.
I’ve never felt better since starting neurofeedback at LuxNeuro Top neurofeedback clinics in Denver
I’m thrilled with the results from Foothills Paving & Maintenance Inc’s asphalt paving service!
Foothills Paving & Maintenance Inc provided top-notch asphalt paving near me!
The team at Foothills Paving & Maintenance Inc really knows their asphalt asphalt sealing services Wheat Ridge
Good info. Lucky me I recently found your website by accident (stumbleupon).
I have bookmarked it for later!
supertogel的最新文章:supertogel
Dr. Fisher’s Medical Weight Loss Centers changed my life with their Semaglutide program!
I highly recommend Dr. Fisher’s for anyone in Philadelphia, PA seeking Semaglutide treatments.
Semaglutide near me was easy to find thanks to Dr Dr. Fisher’s weight loss solutions
Appreciate the insightful article. Find more at roofing companies near me .
What Makes Online Casinos Have Become So Popular
Virtual gambling platforms have modernized the gaming world, providing an exceptional degree of comfort and range that brick-and-mortar venues can’t match. Over time, a large audience worldwide have adopted the excitement of virtual casinos in light of its availability, exciting features, and progressively larger catalogs of games.
One of the main appeals of digital gambling sites is the vast diversity of titles at your disposal. Whether you prefer spinning vintage slot machines, exploring theme-based video slots, or exercising tactics in table games like Baccarat, digital casinos provide numerous choices. Plenty of operators moreover present interactive dealer games, enabling you to connect with actual dealers and gaming peers, all while soaking in the authentic environment of a brick-and-mortar establishment right at home.
If you’re new with the world of digital casinos or seek to discover proven options, why not engage with our vibrant interactive platform? It’s a place where fans exchange experiences, making it easier for you to improve your gambling adventure. Explore the connections and visit us now: vavada регистрация.
Adding to the extensive catalog, internet-based gambling hubs stand out seamless entry.
Just came across a best area in Melbourne that serves the fluffiest nangs! Details at Mr Cream charger products .
Thanks for the detailed guidance. More at Climate-Alignment .
This was a fantastic read. Check out IT Support Stamford for more.
This subject is so pertinent for any person seeking to dive into dance! I concur that picking between a dance academy and classes can be confusing. If you’re interested, look into Dance Studio for added pointers!
I’ve heard there are disadvantages to steel decking in Atlanta—what are they exactly? Curious minds want to know! structural deck repair Atlanta
The investment power of synthetic buildings is awesome—particularly with commonly used agencies like UMH Properties! intensive outpatient program near me
Pool opening is like a rite of passage each year! What do you look forward to most? winnipeg pool opening
Что вы хотите этим сказать?
Дата обращения: 15 февраля 2018. Архивировано 24 сентября https://frontfridge8.edublogs.org/2021/06/02/what-devoid-of-that-initial-knew-before-about-love/ 2020 года. ^ Андрей Судник. Интегрируй это: как наши ритейлеры на опыте пользователей становятся омниканальными (неопр.).
I liked this article. For additional info, visit https://maps.app.goo.gl/wMTPsEeuCHN7uaUk9 .
What are the best practices for brushing elderly animals? I intend to make certain my older pet dog fits during the process. in home dog groomer
Valuable information! Find more at hardwood floor refinishing .
The importance of using original parts vs aftermarket in auto repairs is crucial information that everyone should know! More about this at Vehicle Frame Straightening
This was quite enlightening. Check out https://maps.app.goo.gl/cv4nMBXrb6Xpmm5s5 for more.
I realise that you included seasonal care counsel—they’re indispensable talents whilst curious about install, which I’m heading over in opposition t by the use of ## Click for more
Excited about exploring the whole native parks and leisure routine out there close my new abode at UM H !! # # anyKey word ## UMH Properties Inc
This was a great article. Check out EverClear Pools & Spas for more.
This was a wonderful guide. Check out EverClear Pools & Spas for more.
Appreciate the thorough analysis. For more, visit fire damage restoration services in Chicago .
Appreciate the insightful article. Find more at water damage cleanup near me .
Some people don’t realize that even natural substances can require careful management during a drug detox process! inpatient drug detox
Wonderful perspectives on the importance of choosing the right specialist for residence jobs! Whether it ’s a ceiling alternative or a restaurant renovate, having a competent general contractor you make all the difference Ofir Construction inc Roof Replacement Calabasas, CA
Great post highlighting various challenges faced by agents today—it’s important to seek solutions, and tools like Agent Autopilot could be key—learn more at trusted insurance lead management by agent autopilot !
Your recommendations on creating realistic areas are so sensible! It’s helpful to balance flavor and usefulness in homestead decor. For more helpful suggestion, see rustic farmhouse decor .
I enjoyed this post. For additional info, visit Water Heater .
Reducing stigma surrounding discussions regarding addiction recovery remains crucial as we continue advocating awareness around topics associated specifically towards achieving goals related towards effective AlchoholDetox!!! # medical alcohol detox
What are the typical lawyer fees for car accidents in Washington DC? Do they differ from those handling burn cases? burn injury lawyer Washington
I enjoyed this post. For additional info, visit Boise chiropractor .
Well done! Discover more at https://maps.app.goo.gl/4MBJJDWwwrUj1ieh6 .
I always wondered about the factors affecting my auto insurance rates in Cape Coral. Thanks for shedding light on this topic! Cheap Vehicle Insurance
This topic is so pertinent for anyone aiming to dive into dance! I agree that picking between a dance academy and courses can be confusing. If you’re interested, check out Dance Studio Near Me for extra tips!
In search of reliable and cheap movers in Sachse? Look no further than Best Sachse movers !
This was very well put together. Discover more at mold remediation near me .
The reviews on #AnyKeyWord# are excellent—definitely considering them for my next big move! Merritt Island moving companies