或许有人会问我为啥那么久不更新 其实站点一直有在维护 但是呢優子秉承不发重复 不转帖 不伪原创。因此不会发不是自己倒腾过的东西出来的
今晚睡得晚 错过了睡点 于是直接失眠了QAQ。就想着折腾点啥打发时间 看着谷歌的SSL就有了自己折腾一个和谷歌一样前卫的HTTPS的想法
闲话到此为止
支持新版本TLS协议和ECDHE_RSA加密需要最低openssl1.0.1 而CentOS6通过默认源yum安装的openssl版本只有1.0.0 是不支持新版本TLS协议和ECDHE_RSA密钥交换方式的
一开始本想自己编译openssl 后来一想 自己编译会跟系统的openssl脱节 从而产生一些问题。谷歌是最好的老师 搜到了一个自定义源 里面有已经编译好的新版本openssl
导入源【请注意 此源仅支持64位系统。32位系统的抱歉了 暂时无法找到合适的源】
CentOS5 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-5-1.noarch.rpm
CentOS6 x64:
rpm -ivh --nosignature http://rpm.axivo.com/redhat/axivo-release-6-1.noarch.rpm
通过源升级安装最新版openssl1.0.1e
yum –enablerepo=axivo update openssl
不出意外的话 确认按一次y 导入KEY按一次y 即可完成安装
此时再输入openssl查看version的话 应该会显示【OpenSSL 1.0.1e 11 Feb 2013】
重新编译nginx
印象中这步是必须的 因为似乎编译时引用了openssl的头文档 需要重新编译
即使不是不是必须的 升级到1.4.1支持spdy协议还是不错的
由于我采用的是lnmp一键包 可以直接使用一键包中的upgrade_nginx.sh升级或者重新编译。如果不是使用一键包的 大致步骤如下:
wget http://nginx.org/download/nginx-1.4.1.tar.gz
tar zxvf nginx-1.4.1.tar.gz
cd nginx-1.4.1
./configure –user=www –group=www –prefix=/usr/local/nginx【注:此处填你自己nginx安装目录 按照原先的编译参数 如果原先就没有 prefix直接去掉】 –with-http_stub_status_module –with-http_ssl_module –with-http_gzip_static_module –with-http_spdy_module【注:使用一键包的也需要修改一键包的编译参数 此处加上红色字段】 –with-ipv6
make
mv /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.old【移除+备份老nginx的可执行文件 具体路径是看你的安装方式】
cp objs/nginx /usr/local/nginx/sbin/nginx【复制新的可执行文件进去 具体路径也是看你的安装方式】
/usr/local/nginx/sbin/nginx -t【执行新的可执行文件 测试是否配置文件有问题 具体路径同上】
make upgrade
修改nginx配置文件
需要修改的部分很多 不能像以前两三行解决了
首先
listen 你的ip:443 spdy;#新增spdy协议
SSL部分:
ssl on;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;#新增TLSv1.1 TLSv1.2
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_session_timeout 5m;#新增SSL session支持 此处和上面的是设置超时和设置cache大小 减轻负载
ssl_stapling on;
ssl_stapling_verify on;#
ssl_certificate 你的公钥.crt;
ssl_certificate_key 你的私钥.key;
ssl_prefer_server_ciphers on;#设置由服务端决定加密方式 避免不安全问题
ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-RC4-SHA:ECDHE-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:ECDH-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:RC4-SHA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!CBC:!EDH:!kEDH:!PSK:!SRP:!kECDH;#去除所有不安全加密方式。确保不会遭受BEAST攻击。设置ECDHE_RSA正向密钥交换方式
注:红字是新增部分 蓝字可能是以前就有 如果以前有就需要加入红字部分 没有就直接添加。黑字是开启SSL加密所必需的
设置完毕后 reload nginx即可。
此时可以关闭浏览器重新访问你的SSL连接 你会发现你也变成了使用ECDHE_RSA的高级用户了
你同时可以使用SSL在线测试工具:https://www.ssllabs.com/ssltest/analyze.html。不出意外的话你应该是会得A了
这是本站的评分:https://www.ssllabs.com/ssltest/analyze.html?d=tucao.org
至于RC4的问题 我发现谷歌也在用 所以无所谓了。
如果你是考虑完全使用SSL 抛弃不加密的HTTP 可以考虑添加一个严格SSL的header
add_header Strict-Transport-Security max-age=2592000;
注意这个条目需要同时加到不经过加密的80端口的server块和经过HTTPS加密的server块。并且要在不经过加密的server块里设置跳转。设置方式不多说了 谷歌一搜一堆
使用ECDHE_RSA的优势:
1、具有良好前瞻性的密钥交换方式 保证数据安全
2、可以提升SSL握手速度 间接提升网站速度
3、和SPDY协议联合 最大限度提升HTTPS效率
至于见鬼的IE6的兼容问题呢 優子经过测试 XP 下的IE6是没有访问问题的 不需要担心。
p.s.总感觉“正向加密”这个词翻译有点怪?
~以上~
参考了以下文章:
https://blog.hasgeek.com/2013/https-everywhere-at-hasgeek
https://www.axivo.com/community/threads/upgrade-to-openssl-1-0-1-in-centos.180/
评论
“Witnessing a car accident is terrifying; knowing what steps to take as a bystander is crucial—learn more at Car Accident Lawyer !”
The part about online reviews was spot on! They can significantly impact local rankings. Thanks for the info! local seo nj
Recently, I came across an article that discusses the importance of hiring the best personal injury lawyer following an incident car accident lawyer Phoenix, AZ
Er der nogen risiko forbundet med betalingsmetoder ved brug af VPNS hos kasinoer ??Kan dine oplysninger blive kompromitteret ??vpns χρήση για καζίνο στο διαδίκτυο https://mega-wiki.win/index.php/Optimer_Din_Internetforbindelse_N%C3%A5r_Du_Gambler_Med_En_VPN
My spouse and I stumbled over here from a different page and thought I should check things out.
I like what I see so now i am following you. Look forward to looking
at your web page again.
Brain Song Reviews的最新文章:Brain Song Reviews
Профессиональный сервисный центр по ремонту техники в Йошкар-Оле.
Мы предлагаем: Сколько стоит ремонт кофемашин Cuisinart
Наши мастера оперативно устранят неисправности вашего устройства в сервисе или с выездом на дом!
Pretty nice post. I just stumbled upon your
weblog and wished to say that I have truly enjoyed browsing your blog posts.
In any case I’ll be subscribing to your feed and I hope you write again very soon!
Erectin Reviews的最新文章:Erectin Reviews
Фасады бывают матовыми или глянцевыми, с натуральными текстурами, однотонными, гладкими (например, http://marottawinterleague.altervista.org/index.php/dettagli-torneo/provvedimenti-disciplinari-2/33-chiusura-marottawinterleague-stagione-2015-16 с покрытием акрилом) или с изящным декором.
Just toured a few rental apartments in Lubbock, and they were amazing! Can’t wait to make my choice! More details at corporate housing .
Seriously all kinds of awesome facts!
How to Secure a Fair Spinal Cord Injury Settlement in 2025
A spinal cord injury can be life-altering, impacting your physical abilities, financial stability, and overall well-being Car Accident Lawyer
If you’re in Houston and need legal help after a crash, reach out to a local car accident lawyer today! car accident lawyer houston
I have been exploring for a bit for any high-quality articles or weblog posts on this kind of house .
Exploring in Yahoo I ultimately stumbled upon this site.
Reading this information So i am glad to express that
I have a very good uncanny feeling I found out just what I
needed. I so much definitely will make sure to don?t overlook this web site
and give it a glance on a continuing basis.
PrimeBiome Reviews的最新文章:PrimeBiome Reviews
Local SEO can be complex, but your tips make it manageable and understandable. Thank you for simplifying it! local seo for contractors
Love how easy it was to find a professional office moving company in Cocoa through Best Cocoa movers !
With thanks, Ample write ups.
Value the clarity in your writing! It really assists debunk the employing process for electrical experts. electrician salisbury
Investment opportunities arise from strategic collaborations built upon mutual respect fostered between clients relying upon expert guidance offered along journeys filled with challenges ahead—I plan venturing back regularly seeking updates featured real estate professionals nearby
Your post is so informative! I believe anyone selling a home should invest in professional photography—more at real estate 3d tour production services .
Recently got my house pressure washed, and the price was unbeatable! Highly recommend looking into pressure washing patios near me for options.
My spouse and I just had our first child, and we’re keen on finding a pediatric dentist nearby. dental group near me
I have learn several just right stuff here. Certainly worth bookmarking
for revisiting. I surprise how much effort you put
to create such a excellent informative website.
içerenköyde pilates stüdyosu的最新文章:içerenköyde pilates stüdyosu
I love your blog.. very nice colors & theme. Did you create this website yourself
or did you hire someone to do it for you? Plz respond as I’m
looking to construct my own blog and would like to find out
where u got this from. kudos
do british citizens need a visa for usa的最新文章:do british citizens need a visa for usa
I never realized how much support I needed until reaching out through ###after my unfortunate wreck—it changed everything! Injury Lawyer
I constantly recommend checking into local attorneys that concentrate on criminal law if you remain in Minneapolis– browse through criminal defense lawyers minneapolis for recommendations!
ฉันรักค็อกเทลที่ OMG ONE MORE GLASS SAI1 มาก อร่อยและสดชื่นสุดๆ ร้านนั่งชิล สาย1
Jeg har læst, at nogle spillere bruger VPN’er – er det sensible? mobiele vpn oplossingen voor gokken
Very helpful pointers! It’s fascinating how many people forget licenses when working with electrical experts. electrical installation service
I never realized how important Google My Business is for local SEO. This post really opened my eyes! local seo nj
hello there and thank you for your information – I have definitely picked up something new from right here.
I did however expertise a few technical points using this
site, as I experienced to reload the web site lots of times
previous to I could get it to load correctly.
I had been wondering if your web host is OK? Not that I am complaining, but sluggish loading instances times will
sometimes affect your placement in google and could damage your high quality score if ads and marketing with Adwords.
Well I’m adding this RSS to my e-mail and could look out for a lot more of your respective
fascinating content. Ensure that you update this again very soon.
bokep indonesia percakapan的最新文章:bokep indonesia percakapan
Эта тема просто бесподобна 🙂 , мне нравится )))
Бонусы pokerdom растут с каждым уровнем, https://pokerdom-cuh6.top/ делая игру увлекательнее. Загрузите приложение Покердом на устройстве или ios для игры в любом месте.
Making informed decisions only becomes easier through educational resources such as yours!!! # anyKeywod## Car Accident Lawyer
My journey through recovery wouldn’t have been possible without support from such dedicated legal counsel—thank you, ###car-accident lawyer###! Injury Lawyer
If you’re unsure about what steps to take after an accident, consulting a Houston car accident lawyer is wise. car accident lawyer houston
Your blog is a treasure trove of information on local SEO—it’s a must-read for anyone serious about growing their business online! seo for contractors
Great to see the community come together to support families’ health with accessible dental care options! dentist Mission Viejo
I recently had a close friend who went through a tough experience after a car accident. It made me realize how important it is to have the right support during such challenging times Solorzano Law Firm auto accident attorney Phoenix, AZ
I’m inspired by your approach to showcasing properties—video truly captures their essence better than photos alone! Discover more tips & tricks at affordable real estate photography services
We’ve been using a family dentist in Mission Viejo for years, and they truly understand the needs of different age groups. dentist around me
Local SEO can be complex, but your tips make it manageable and understandable. Thank you for simplifying it! seo for contractors
This post is a treasure! Can you offer examples of particular inquiries to ask potential electricians? best electricians near me
“Every year, thousands of lives could be saved if everyone simply obeyed traffic laws—it’s time we take responsibility as drivers! Injury Lawyer ”
.Excellent overview capturing pressing challenges experienced by agents presently intrigued seeing developments resulting from partnerships pursued alongside,” agent autopilots!” *#*AnyKeyWord* authoritative health insurance leads by agent autopilot
Accidents can turn lives upside down in an instant, whether it’s a car, motorcycle, or truck accident. It’s essential to have the right representation when navigating the complexities of personal injury law personal injury lawyer
If you are tackling a great decluttering undertaking, seem no additional than dumpster rental Jacksonville ! Their dumpsters are just what you want in Jacksonville.
Er hastigheden acceptabel når man streamer indhold gennem # anyKeywo#### https://www.bookmark-step.win/online-gambling-har-sine-egne-regler-i-nederlandene-overvej-konsekvenserne-ved-brugen-af-en-vpn-til-dette-formal-noje-1
This was highly helpful. For more, visit heating engineer .
Thanks for the great information. More at gas leak detection .
This was highly useful. For more, visit heating engineer .
This was highly informative. Check out commercial gas engineers for more.