或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
The cracks in my sidewalk were becoming dangerous; thank goodness for the quick service at concrete sidewalk repair manhattan .
This was highly educational. For more, visit abogada Vigo .
Great insights on finding stable fence installers! I invariably suggest checking reviews until now making a decision. http://www.med.uz/bitrix/rk.php?goto=https://www.rankbookmarkings.win/trying-to-find-ornamental-alternatives-our-imaginative-fencing-contractors-in-melbourne-use-unique-layouts-that-include-personality
Как выбрать врача-дерматолога для лечения экземы? Надеюсь почитать советы на сайте удаление папиллом .
Making waves within community every day causes ripples felt far beyond expectations set forth initially something remarkable indeed happening together… lakeland window washing pressure washing decks
How do you handle lowball offers when selling? Strategies are discussed at sell a house in oakland county mi .
‘There shall continually remain a few detailed connection current deep down shared solely between humans amassed in combination playing accepted comforts represented for the period of bonds created fully surrounding traditions emphasised often the Order Mr Cream nangs
The details about Nang Gun here are amazing! There’s even more at affordable order nangs tank .
on diverse sites bitcoin-casinos, which I have viewed, available extensive selection of https://www.danielvillalona.com/your-ultimate-guide-to-betting-with-bc-stavka/ slots. and when you are an fan of esports, you can learn with most popular esports crypto gambling and get lots of coefficients for similar games like lol or cs go.
When it comes to legal matters, having the right attorney is key; check out personal injury attorney garland for help.
Bosch’un yetkili servisi sayesinde sorunlarımı hızlıca çözüyorum. Bosch Yetkili Servisi
Has anyone else experienced how much better life feels with less clutter? My ID falls team helped big time #anAnyKeyWord## Lone Star Cleaning Solutions
Hey everyone,
I’ve been checking out the world of virtual casinos lately, and I’ve gotta say — it’s pretty damn addictive. At first, I was super skeptical. I mean, how do you even believe in an online platform with your hard-earned money, right? But after testing the waters (and trying out a few sketchy sites so you don’t have to), I figured out a few things that separate a trustworthy casino from a risky mess. First off, if you’re new to all this, here’s the golden rule: **regulation is key**. If a casino doesn’t have a proper regulatory certificate (like from the MGA or the UKGC), just run. No bonus is worth the risk of never seeing your funds again. Also — and I know no one wants to — read the T&Cs. That’s the only way to know what kind of playthrough limits they’ve slapped onto those so-called “amazing” bonuses.
Now, let me share a site I’ve been playing on these last few weeks. It’s been a breath of fresh air. The interface? Super clean. Payouts? Fast as hell. And the game selection? *Insane*. Slots, live dealers, blackjack, even some oddball options I hadn’t tried before. Check it out here: https://crearte.me/digital-marketing-made-easy-let-our-team-handle/ What really stood out was the support team. I had a tiny issue with a bonus not working, and they got back to me in like no time. Compare that to other sites where you’re just left hanging — yeah, hard pass.
Also, if you’re into bonuses (and who isn’t?), this place offers some legit ones. But here’s the trick: don’t just chase bonuses. It’s smarter to stick to reasonable terms than a huge bonus you’ll never be able to withdraw. I’m not saying you should go and bet the farm — please don’t. But if you’ve got a little extra cash and you’re looking for a chill way to spend an evening, online casinos can totally deliver. Just keep your head on, know your limits, and don’t treat it like a side hustle. It’s for fun, not for a paycheck. Anyway, just wanted to drop my experience here in case anyone’s looking for solid info or trying to find a good place to play. If you’ve got your own recommendations or even some casino nightmares, I’m all ears — love talking shop about this stuff.
Good luck out there, and spin smart, win big ??
I appreciate your focus on social skills development in daycare settings. Children learn so much from interacting with peers! daycare
The user reviews on Thompson Law helped me choose the best lawyer for my situation in Garland.
If absolutely everyone needs pointers sooner than diving into this realm of culinary arts, look at various solutions highlighted by using specialists over there beneath their hyperlink pointed in direction of (#Anykeyword#)! Homepage
Quality articles or reviews is the crucial to be a focus for the people to pay
a visit the web site, that’s what this website is providing.
CBD Vape Pen in German的最新文章:CBD Vape Pen in German
ร้าน OMG OneMoreGlass มีเมนูอะไรแนะนำบ้างครับ? อยากลองไปชิมดู! ร้านเหล้าบางแค
Я всегда боялась делать такие процедуры, но теперь понимаю, что зря переживала! Лазер убирает всё быстро! удаление папиллом
พาแฟนไปเดทที่ OMG OneMoreGlass บรรยากาศโรแมนติกมากๆ ครับ! ร้านชิลสาย1 เพลงดี
สำหรับคนรักการดื่ม ต้องไปลองที่ OMG ONE MORE GLASS SAI1 สักครั้งนะคะ ร้านเหล้าใกล้ฉัน
Hmm it looks like your website ate my first comment (it was extremely long) so I guess I’ll just
sum it up what I wrote and say, I’m thoroughly enjoying your blog.
I too am an aspiring blog writer but I’m still new to everything.
Do you have any suggestions for inexperienced blog writers?
I’d really appreciate it.
텐텐벳주소的最新文章:텐텐벳주소
”Excellent point made about staying informed prior selecting transportation options—it’s worth looking into sites like ### San Diego auto transport
The importance placed upon cultivating authentic connections cannot be overstated- especially within specialized fields like those addressed by firms such as ‘ AgentAutopot ’- stay tuned over here: ### anyKey###!!! agent autopilot insurance automation expertise
Quality items + quick delivery = terrific combo at ###anDeliveryMelbourne###! Nangs Delivery Derrimut 24/7
The benefits of music and movement activities in daycare are often overlooked but so vital for cognitive growth! Great post! daycare
Love seeing how different photographers interpret homes; yours has such a unique touch. best real estate photography
Effective communication between clients and their lawyers ensures successful outcomes—fort worth’s professionals prioritize this aspect greatly; find experts on ### anykeyword###! fort worth car accident lawyer
Trustworthy and efficient, that’s how I’d describe this amazing house cleaning company! Learn more at Lone Star Cleaning Solutions .
Why Online Casinos Remain So Popular
Digital casinos have changed the gaming landscape, providing a level of accessibility and diversity that traditional casinos fall short of. Recently, a growing community across the globe have welcomed the excitement of internet-based gaming due to its accessibility, engaging traits, and widening range of offerings.
One of the main appeals of digital gambling sites is the astounding variety of games ready to play. Whether you are a fan of playing on classic one-armed bandits, exploring narrative-rich video-based games, or testing your strategy in card and board games like Texas Hold’em, casino websites offer countless opportunities. Numerous services furthermore include live dealer games, allowing you to connect with live hosts and fellow gamblers, all while immersing yourself in the lifelike feel of a land-based casino without leaving your home.
If you’re unfamiliar with the world of virtual casino play or are looking to learn about proven options, why not participate in our dynamic community? It’s a place where players exchange insights, guiding you to enhance your gaming journey. Discover the experience and visit us now: вавада вход.
Beyond variety, virtual gaming providers shine constant connectivity.
Yes! Finally someone writes about nyemergencyplumbers.
After-hours plumber NY的最新文章:After-hours plumber NY
Particularly love seeing teamwork shine brightest under duress reminding us all what’s truly important amidst uncertainties presented throughout life lived daily… reliable emergency tree removal
I was amazed by how dirty my patio was until I had it pressure washed. Highly recommend lakeland window washing pressure washing siding !
A supportive #Fort Worth accident attorney# can alleviate much of the stress following an incident. personal injury defense attorney near me
Excellent read packed with useful procedures—we’ll think of contacting ####ANYYEYWD#### earlier than proceeding! cost comparison of affordable Colorbond fencing
Does anyone know how long typical projects take with Banning Construction Inc.? Need to plan accordingly! banning construction bathroom refit
The benefits of music and movement activities in daycare are often overlooked but so vital for cognitive growth! Great post! daycare near me
Cihazlarımı düzenli olarak bakıma götürüyorum ve her seferinde memnun kalıyorum! Bosch Servisi
Why Online Casinos Are a Global Phenomenon
Virtual gambling platforms have reshaped the gambling scene, delivering a unique kind of ease and range that traditional casinos fall short of. Throughout the last ten years, countless gamblers globally have welcomed the fun of online gaming thanks to its ease of access, captivating elements, and constantly growing range of offerings.
One of the biggest attractions of virtual gambling hubs is the incredible diversity of gaming experiences on offer. Whether you enjoy interacting with vintage reel games, diving into engaging visual slot games, or testing your strategy in classic casino games like Roulette, casino websites offer infinite possibilities. Plenty of operators even feature real-time gaming experiences, making it possible for you to participate with real dealers and opponents, all while enjoying the lifelike atmosphere of a traditional gambling venue from the comfort of your home.
If you’re a beginner with the world of virtual gambling or hope to learn about safe services, why not join our vibrant social network? It’s a space where fans share experiences, enabling you to maximize your casino activities. Check out the experience and see it here now: вавада регистрация.
In addition to diversity, digital casino services excel seamless entry.
Have you attempted Nangs in Melbourne? They’re a game changer! Visit The original source for data.
Thanks for the useful suggestions. Discover more at car tint Franklin .
I took my dog to Care Pet Animal Hospital and was impressed by their professionalism and dedication. Highly recommend! Veterinarian
Sorunlarınızı dert etmeyin çünkü çözüm burada!! Koran Taksi
Deneme bonusları sayesinde yeni oyunları denemek çok kolay! Deneme Bonusu
Such an informative session filled with positivity surrounding community building aspects which ultimately lead towards greater follower numbers: ## Nakrutkra
Valuable information provided in this article; it’s clear that investing in good reviews pays off in the long run—find out more at ig forum .
I didn’t realize how important sidewalk maintenance was until I had an accident. Now I always recommend checking out sidewalk concrete repair bronx for repairs.
I was impressed with how thorough the veterinarians are at Care Pet Animal Hospital during our visit today! Veterinarian Jacksonville
Can’t consider how swiftly I can prepare cakes now with cream chargers in hand! Visit 3.3L nang canister safety for solutions!
Just had a fantastic experience at Care Pet Animal Hospital. The staff is so friendly and knowledgeable! Best vet in Fruit Cove! Veterinarian near me