本文共 352 字,大约阅读时间需要 1 分钟。
nginx负载均衡
编辑配置文件
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/18/d8a80008b1b4b363bf15cc4c583862c4.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
重新加载,验证成功,图太大, 截图一部分。
ssl原理
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/821b50ff09e082fe52a701aa14c21c23.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
生成ssl密钥对
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/eef9c646d73cdd06cb696c8418044dc4.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
nginx配置ssl
在vhost下创建ssl配置文件
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/d4ef9a011b50d2b63237a0e8504d0635.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
验证
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/597a7aa39d411110202ab5e1ea23f7df.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
报错,查看环境
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/ae57d61f205b0619a9a5101e10c0e6d3.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
需要重新编辑nginx,查看可用的编辑模块
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/82637ab1853ce9733efb4038eb02e4b7.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
重新编辑,make make install
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/86468d7c3f45c607d7c41c90637e8e4f.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
验证并重启nginx服务
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/05a69b2f6e0504b844e3b777b72de410.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
查看443监听端口是否增加
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/b27bc1ee4ece24c9fd6a3746b14ef1fa.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
在ssl的数据目录下创建默认页面
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/dc283426d5c38fdf5c606c28518b8f9f.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/d58bcec837a6905a23e801be9baeaa95.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
开始测试访问
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/a5e3c0d6e819b6861e1597b98ec98cd6.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
修改hosts文件
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/de31a675bf2a29cbfd5800f76f4f7bcd.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
再次测试,判定证书不可信
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/1b0bf467de48938b664ab1389f44061a.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
修改客户机hosts文件,添加aming.com域名解析
再次测试仍然不可访问。
查看防火墙状态,发现开启(截图一部分),关闭防火墙(iptables -F),再次验证。
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/7fd6a1939383aba07fb7df29065935bd.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
![nginx负载均衡,ssl原理,生成ssl秘钥对,nginx配置ssl](https://s1.51cto.com/images/blog/201803/19/adfa320fe0d234e162d0db5e324276d1.png?x-oss-process=image/watermark,size_16,text_QDUxQ1RP5Y2a5a6i,color_FFFFFF,t_100,g_se,x_10,y_10,shadow_90,type_ZmFuZ3poZW5naGVpdGk=)
在浏览器上验证成功。
转载于:https://blog.51cto.com/13528516/2088332