Òò´Ë£¬Æô¶¯Ò»¸ö¼ÓÃÜ·þÎñÆ÷£¬È·±£Êý¾Ý´«ÊäºÍ´æ´¢µÄ°²È«ÐÔ£¬ÒѳÉΪÐí¶àÆóÒµºÍ×éÖ¯µÄ»ù±¾ÐèÇó
±¾ÎĽ«Ïêϸ½éÉÜÈçºÎ¸ßЧÆô¶¯Ò»¸ö¼ÓÃÜ·þÎñÆ÷£¬º¸Ç´ÓÑ¡ÔñºÏÊʵķþÎñÆ÷Èí¼þ¡¢»ñµÃSSL/TLSÖ¤Êé¡¢ÅäÖ÷þÎñÆ÷²ÎÊý£¬µ½×îÖյIJâÊÔºÍά»¤µÈ¹Ø¼ü²½Öè
Ò»¡¢Ñ¡ÔñºÏÊʵķþÎñÆ÷Èí¼þ ÔÚÆô¶¯¼ÓÃÜ·þÎñÆ÷֮ǰ£¬Ê×ÏÈÐèҪѡÔñºÏÊʵķþÎñÆ÷Èí¼þ
³£¼ûµÄÑ¡ÔñÓÐApache¡¢NginxºÍMicrosoft IISµÈ
ÕâЩ·þÎñÆ÷Èí¼þ¶¼Ö§³Ö¼ÓÃÜͨÐÅ£¬²¢ÌṩÁËÏàÓ¦µÄÅäÖÃÑ¡Ïî
- Apache£ºApache HTTP ServerÊÇÒ»¿î¿ªÔ´µÄ¡¢¿çƽ̨µÄWeb·þÎñÆ÷Èí¼þ£¬¹ã·ºÓ¦ÓÃÓÚ¸÷ÖÖ²Ù×÷ϵͳ
ËüÌṩÁËÇ¿´óµÄÅäÖÃÑ¡Ïͨ¹ýSSL/TLSÄ£¿é¿ÉÒÔÇáËÉʵÏÖ¼ÓÃÜͨÐÅ
- Nginx£ºNginxÊÇÒ»¸ö¸ßÐÔÄܵÄHTTPºÍ·´Ïò´úÀí·þÎñÆ÷£¬Ò²Ö§³ÖSSL/TLS¼ÓÃÜ
NginxÒÔÆä¸ß²¢·¢´¦ÀíÄÜÁ¦ºÍµÍ×ÊÔ´ÏûºÄ¶øÖø³Æ£¬Êʺϴ¦Àí´óÁ¿²¢·¢Á¬½ÓµÄ³¡¾°
- Microsoft IIS£ºIIS£¨Internet Information Services£©ÊÇ΢ÈíÌṩµÄWeb·þÎñÆ÷£¬ÄÚÖÃÓÚWindows Server²Ù×÷ϵͳÖÐ
IISͬÑùÖ§³ÖSSL/TLS¼ÓÃÜ£¬ÊʺÏÔÚWindowsƽ̨ÉÏʹÓÃ
¶þ¡¢»ñµÃSSL/TLSÖ¤Êé SSL/TLSÖ¤ÊéÊǼÓÃÜͨÐŵĹؼü×é¼þ£¬ÓÃÓÚÑéÖ¤·þÎñÆ÷Éí·Ý²¢¼ÓÃÜͨÐÅÊý¾Ý
- ¹ºÂòÖ¤Ê飺¿ÉÒÔ´ÓȨÍþµÄÖ¤Êé°ä·¢»ú¹¹£¨CA£©¹ºÂòSSL/TLSÖ¤Êé
ÕâЩ֤Êéͨ³£°üº¬·þÎñÆ÷µÄ¹«Ô¿ºÍCAµÄÇ©Ãû£¬È·±£Í¨ÐÅË«·½µÄÉí·ÝÈÏÖ¤ºÍÊý¾Ý¼ÓÃÜ
- Ãâ·ÑÖ¤Ê飺Ҳ¿ÉÒÔʹÓÃÃâ·ÑµÄÖ¤Ê飬ÈçLets Encrypt
Lets EncryptÊÇÒ»¸öÓÉ»¥ÁªÍø°²È«Ñо¿Ð¡×飨ISRG£©ÌṩµÄÃâ·Ñ¡¢×Ô¶¯»¯ºÍ¿ª·ÅµÄÖ¤Êé°ä·¢»ú¹¹£¬Ö§³ÖÏÖ´ú»¯µÄ¼ÓÃÜËã·¨ºÍÐÒé
ÎÞÂÛÑ¡ÔñÄÄÖÖ·½Ê½£¬¶¼ÐèÒª°´ÕÕÒªÇóÉú³ÉÖ¤ÊéµÄCSR£¨Ö¤ÊéÇ©ÃûÇëÇ󣩲¢½øÐÐÑéÖ¤
CSR°üº¬ÁË·þÎñÆ÷µÄ¹«Ô¿ºÍһЩ±êʶÐÅÏ¢£¬ÓÃÓÚÏòCAÉêÇëÖ¤Êé
Èý¡¢°²×°Ö¤Êé »ñµÃSSL/TLSÖ¤Êéºó£¬ÐèÒª½«Æä°²×°µ½·þÎñÆ÷ÉÏ
²»Í¬µÄ·þÎñÆ÷Èí¼þÓв»Í¬µÄ°²×°·½·¨
- Apache£ºÔÚApache·þÎñÆ÷ÉÏ£¬ÐèÒª½«Ö¤ÊéÎļþºÍ˽ԿÎļþÅäÖõ½·þÎñÆ÷µÄSSL/TLSÄ£¿éÖÐ
ͨ³££¬ÕâÐèÒªÔÚApacheµÄÅäÖÃÎļþÖÐÌí¼Ó»òÐÞ¸ÄÏà¹ØµÄÖ¸ÁÈç`SSLCertificateFile`¡¢`SSLCertificateKeyFile`µÈ
- Nginx£ºÔÚNginx·þÎñÆ÷ÉÏ£¬Í¬ÑùÐèÒª½«Ö¤ÊéÎļþºÍ˽ԿÎļþÅäÖõ½·þÎñÆ÷µÄSSL/TLSÄ£¿éÖÐ
ÕâÐèÒªÔÚNginxµÄÅäÖÃÎļþÖÐÌí¼Ó»òÐÞ¸Ä`ssl_certificate`ºÍ`ssl_certificate_key`Ö¸Áî
- IIS£ºÔÚIIS·þÎñÆ÷ÉÏ£¬°²×°Ö¤Êéͨ³£Í¨¹ýIIS¹ÜÀíÆ÷½øÐÐ
ÐèÒªµ¼ÈëÖ¤ÊéÎļþ£¬²¢½«Æä°ó¶¨µ½ÏàÓ¦µÄÍøÕ¾»òÓ¦ÓóÌÐò
ËÄ¡¢ÅäÖüÓÃܲÎÊý °²×°Ö¤Êéºó£¬»¹ÐèÒªÅäÖüÓÃܲÎÊý£¬ÒÔÈ·±£Í¨ÐŵݲȫÐÔ
- Ö¸¶¨¼ÓÃÜËã·¨ºÍ°²È«ÐÒ飺ÔÚ·þÎñÆ÷Èí¼þµÄÅäÖÃÎļþÖУ¬ÐèÒªÖ¸¶¨¼ÓÃÜËã·¨ºÍ°²È«ÐÒé
ÀýÈ磬ÔÚApacheµÄÅäÖÃÎļþÖУ¬¿ÉÒÔʹÓÃ`SSLProtocol`ºÍ`SSLCipherSuite`Ö¸ÁîÀ´Ö¸¶¨ÐÒéºÍËã·¨
ӦѡÔñ°²È«ÐԽϸߵļÓÃÜËã·¨ºÍÐÒ飬ÈçTLS 1.2»ò¸ü¸ß°æ±¾£¬ÒÔ¼°Ç¿¼ÓÃÜËã·¨£¨ÈçAES-256£©
- ÆôÓüÓÃÜÄ£¿é£ºÈ·±£·þÎñÆ÷Èí¼þµÄ¼ÓÃÜÄ£¿éÒÑÆôÓÃ
ÔÚApacheºÍNginxÖУ¬Õâͨ³£ÊÇͨ¹ý¼ÓÔØÏàÓ¦µÄSSL/TLSÄ£¿éÀ´ÊµÏÖµÄ
ÔÚIISÖУ¬ÔòÐèÒªÔÚIIS¹ÜÀíÆ÷ÖÐÆôÓÃSSLÉèÖÃ
Îå¡¢ÖØÐÂÆô¶¯·þÎñÆ÷ Íê³ÉÉÏÊöÅäÖúó£¬ÐèÒªÖØÐÂÆô¶¯·þÎñÆ÷ÒÔʹÅäÖÃÉúЧ
È·±£·þÎñÆ÷Äܹ»Õý³£ÔËÐУ¬²¢Í¨¹ýHTTPSÐÒé½øÐÐͨÐÅ
- ÖØÆô·þÎñÆ÷£º¸ù¾ÝËùʹÓõķþÎñÆ÷Èí¼þ£¬Í¨¹ýÏàÓ¦µÄ¹ÜÀí¹¤¾ß»òÃüÁîÐй¤¾ßÖØÆô·þÎñÆ÷
ÀýÈ磬ÔÚApacheºÍNginxÖУ¬¿ÉÒÔʹÓÃÃüÁîÐй¤¾ß£¨Èç`systemctl restart apache2`»ò`systemctl restart nginx`£©À´ÖØÆô·þÎñÆ÷
ÔÚIISÖУ¬¿ÉÒÔͨ¹ýIIS¹ÜÀíÆ÷»òÃüÁîÐй¤¾ß£¨Èç`iisreset`£©À´ÖØÆô·þÎñÆ÷
- ¼ì²éÔËÐÐ״̬£ºÖØÆô·þÎñÆ÷ºó£¬ÐèÒª¼ì²éÆäÔËÐÐ״̬
È·±£·þÎñÆ÷Äܹ»Õý³£ÏìÓ¦HTTPSÇëÇ󣬲¢ÏÔʾÒѼÓÃܵÄÁ¬½Ó
Áù¡¢²âÊÔ¼ÓÃÜÁ¬½Ó ΪÁËÈ·ÈÏ·þÎñÆ÷Òѳɹ¦¿ªÆô¼ÓÃܹ¦ÄÜ£¬ÐèÒª½øÐвâÊÔ
- ʹÓÃä¯ÀÀÆ÷²âÊÔ£º³¢ÊÔͨ¹ýHTTPS·ÃÎÊ·þÎñÆ÷£¬²¢¼ì²éä¯ÀÀÆ÷ÊÇ·ñÏÔʾÒѼÓÃܵÄÁ¬½Ó
ÔÚä¯ÀÀÆ÷µÄµØÖ·À¸ÖУ¬Í¨³£»áÏÔʾһ¸öËøÐÎͼ±ê£¬±íʾÁ¬½ÓÒѼÓÃÜ
- ʹÓÃÃüÁîÐй¤¾ß²âÊÔ£ºÒ²¿ÉÒÔʹÓÃÃü