本文介绍如何使用Let’s Encrypt获取免费证书,以支持https服务。
步骤如下:
1. 拉取git上的工具
|
|
2. 获取证书
|
|
3. 更新证书(证书有效期3个月)
|
|
可以配置crontab 定期更新
4. 配置nginx
证书位置: /etc/letsencrypt/live/域名/123456789101112131415161718192021# HTTPS server#server { listen 443 ssl; server_name 域名; ssl_certificate /etc/letsencrypt/live/域名/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/域名/privkey.pem; ssl_session_cache shared:SSL:1m; ssl_session_timeout 5m; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_ciphers HIGH:!aNULL:!MD5; ssl_prefer_server_ciphers on; location / { root html; index index.html index.htm; }}