或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
The role of dietitians in treating eating disorders is often overlooked, but they play such a vital role in recovery—great post! eating disorder treatment for adults
State governments {provide|provide} {full|exhaustive} {legal|legislative} {assistance|protection|cover} to users of {casino|roulette or cards} for {real|real} {funds|money} {a|and|in case} {occurrence|occurrence of} disputes. When making payments in bitcoins at an #file_linksC:\Users\Admin\Desktop\file\gsa+en+one4anotherRoma14044P2URLBB.txt”,1,N] {a commission is charged|withdrawn {in|relative to} {size|magnitude} {from|within|in the range of} 0 {up to|up to} 40 USD.
Nutrition plays such a vital role during recovery; what meals or snacks kept you energized through your alcohol detox journey? Let’s exchange ideas over at medical alcohol detox !
I believe that every successful recovery begins with a solid drug detox plan. outpatient drug detox
“Involving family members in therapy sessions can strengthen relationships affected by addiction.” non 12 step drug rehab
This article is just what I required prior to starting my very own pole barn garage job! Understanding its durability will aid me plan better. Much more resources can be located at Pole Building !
It’s crucial that we keep the conversation about prevention alive alongside treatment options! best addiction treatment centers
I can’t accept as true with how quick the nangs delivery service is in Melbourne—amazing! nang delivery greensborough
This was very insightful. Check out garage door service for more.
This was a great article. Check out charlotte garage doors for more.
Loved this post about common HVAC myths! It’s surprising how many misconceptions there are; thanks for debunking them and introducing me to more facts through hvac installation !
Cricket Academy Dubai represents the growing enthusiasm for the sporting task in the United Arab Emirates, making use of young specialist athletes and cricket lovers a system to educate,
expand, and succeed. With advanced facilities and a professional mentoring setting, cricket academies throughout Dubai have come to be main to supporting talent and promoting a
healthy, cost effective spirit amongst players of
every age teams. Dubai has rapidly became a hotspot for cricket in the facility East.
The city hosts various worldwide matches and events and currently assistances a strong grassroots activity through
its cricket academies. These academies are built to global standards,
consisting of grass pitches, synthetic approach internet, interior facilities, video clip assessment research laboratories, and professional-grade
health club. This centers ensures that students train in troubles that resemble real match situations, enabling them
to change, perform, and boost under specialist advice. Amongst the defining features of cricket academies in Dubai is the diversity of their training programs.
Whether you are a complete beginner or a well-informed gamer aiming to break into a competitive company, there is
a suitable program for you. Procedure normally concentrate on refining approach in batting, bowling, and fielding,
together with tactical acknowledgment, match personality, and physical fitness.
Training is often offered by accredited instructors, a lot of whom bring nationwide
or international having fun experience to the table.
Along with regular training, academies additionally host intra-academy competitors, skill searching
celebrations, and straight exposure trips. These tasks supply gamers
the possibility to examination their capabilities in an economical environment and obtain direct exposure among selectors and company precursors.
Some academies additionally companion with schools, permitting students to include their scholastic and sports
training under one timetable. What collections Dubai apart is its modern setting.
Players from various races and cricketing histories collaborated to
find out and full, advertising not simply sports advancement yet furthermore cultural exchange and synergy.
This variety includes amazing value to the gamer
advancement treatment, exposing young cricketers to various playing designs and
methods from all over the world. For parents, cricket academies in Dubai offer a
safe and secure, arranged, and meeting establishing where their youngsters can develop self-control, fitness, and social capabilities while pursuing a showing off activity they delight in. For adult gamers,
weekend break and evening sessions usage an opportunity to continue
to be energetic, improve capacities, and sign up with organization cricket in a professionally managed configuration. In a city acknowledged for high quality and
innovation, cricket academies in Dubai are no different.
They integrate custom with contemporary innovation, enthusiasm with experience, and neighborhood
with competitors. Whether you are dreaming of a
professional career or simply looking for to become one of the most reliable variant of yourself on the pitch, signing up with a cricket academy in Dubai is a step in the excellent instructions.
It is not just a training school it is where the trip of cricket
starts for numerous and continues with objective, dedication, and the spirit of
the video game.
Cricket Academy Dubai的最新文章:Cricket Academy Dubai
This was quite enlightening. Check out roofers near me for more.
The information provided about native versus non-native plants has helped clarify many misconceptions—I appreciate it immensely!! # anyKeyWord # tree service albuquerque nm
The importance of ventilation in plumbing systems is often overlooked—great point made here!! Plumber
Great submit! A nicely-built fence can turn out to be any backyard – trying to lease anybody experienced quickly. Home page
This was quite informative. More at Country Creek Animal Hospital .
Thanks for the thorough article. Find more at flood damage restoration company .
I was curious if you ever considered changing the
structure of your website? Its very well written; I love what youve got to say.
But maybe you could a little more in the way of content so people could connect with it better.
Youve got an awful lot of text for only having 1 or 2 images.
Maybe you could space it out better?
علت تاری ناگهانی چشم چپ的最新文章:علت تاری ناگهانی چشم چپ
Any thoughts on seasonal timing for painting exteriors? I’d love to hear your perspective! stucco companies albuquerque
Thanks for the valuable article. More at colchones Albacete .
I enjoyed this article. Check out Atlanta bathtub reglazing for more.
I never realized how much dirt and moss could accumulate on a roof until I had it pressure washed. Highly recommend looking into this! Learn more at eco-friendly pressure washing solutions .
I love that we’re seeing more cities incorporate artistic elements into their infrastructure using durable materials such as stamped sidewalks!!## anykeyword ## tree trimming albuquerque
Great insights! Discover more at pressure washing .
Appreciate the thorough insights. For more, visit Fort Wayne 24/7 plumbers near me .
Are there specified ways employed at some point of installations serving to forestall regularly occurring pitfalls faced through freshmen???? Share guidelines!!!# # anyKeyWord ## http://www.webclap.com/php/jump.php?url=https://www.adirs-bookmarks.win/get-creative-in-the-kitchen-with-nangs-melbourne-s-versatile-nitrous-oxide-canisters-that-help-you-craft-everything-from
Wow, I didn’t recognise whipped cream should style this top until I tried Mr Cream Chargers! Have a peek here
Very useful post. For similar content, visit water softener installation .
What a thorough overview of orthodontic options available today—thank you for sharing this knowledge! dentist
Wonderful tips! Discover more at Water damage restoration .
I thought my PS5 was done for, but thanks to PS5 Repair Near Me, it’s as good as new! PS5 Repair
This was highly useful. For more, visit indoor air quality testing services .
I found this very interesting. For more, visit septic tank service company .
Thanks for the informative content. More at Summers Plumbing Heating & Cooling .
I’ve heard that regular treatments from Commercial weed control can save money long-term—true or false?
Do you think traditional farming methods still hold value when it comes to modern fertilizer application? Let’s explore this topic further via Commercial fertilization services !
This is highly informative. Check out Summers Plumbing Heating & Cooling for more.
I appreciated this post. Check out local 24/7 plumbers for more.
This was very well put together. Discover more at pressure washing near me .
I think we need more community-based initiatives focused on prevention and education around substance use and detox options! supervised drug detox
The benefits of a proper alcohol detox are life-changing! Find more helpful information at holistic alcohol detox .
I love how this post emphasizes self-love as part of recovery from eating disorders. Such an important message! medical stabilization for eating disorders
I love that Jaya9 Roulette allows me to play at my own pace; very relaxing!! Joya 9 Download Guide
Appreciate the helpful advice. For more, visit rustic outdoor wedding venues .
Has anyone else tried the nang delivery from online nang options ? I think they’re the best in Melbourne!
“Education about substance abuse helps reduce stigma and encourages more people to seek help.” holistic drug rehab
It’s heartwarming to see communities come together to support those battling addictions! addiction treatment for veterans
Appreciate the helpful advice. For more, visit animal hospital Jacksonville .
Appreciate the useful tips. For more, visit Bathtub reglazing near me .