First create a directory cd /etc/nginx mkdir ssl cd ssl CA vs Self-signed Create a CA private key openssl genrsa -out ca.key 2048 Create a CA root certificate (public key) openssl req -new -x509 -days 3650 -key ca.key -out ca.crt Notice: 1. Common Name can be filled in at will Server Certificate Make a server-side private key: openssl genrsa -out server.pem 1024 openssl rsa -in server.pem -out server.key Generate a signing request: openssl req -new -key server.pem -out server.csr Notice: 1. Common Name must be filled in with the domain name when accessing the service. Here we use usb.dev. The following NGINX configuration will use Issued by CA openssl x509 -req -sha256 -in server.csr -CA ca.crt -CAkey ca.key -CAcreateserial -days 3650 -out server.crt Client Certificates Similar to the server certificate Notice: 1. Common Name can be filled in at will Now that the required certificates are in place, we can start configuring NGINX. Nginx Configuration server { listen 443; server_name usb.dev; index index.html; root /data/test/; ssl on; ssl_certificate /etc/nginx/ssl/server.crt; ssl_certificate_key /etc/nginx/ssl/server.key; ssl_client_certificate /etc/nginx/ssl/ca.crt; ssl_verify_client on; } Request Verification The verification process can be done on another machine or on the local machine. In order to resolve usb.dev, you also need to configure /etc/hosts: ip address usb.dev If you use a browser for authentication, you need to export the client certificate into p12 format. openssl pkcs12 -export -clcerts -in client.crt -inkey client.pem -out client.p12 Download several certificates from the server and install them to the trusted certificate list. Click the p12 file just generated and enter the certificate password to install it to the personal list. The above is the full content of this article. I hope it will be helpful for everyone’s study. I also hope that everyone will support 123WORDPRESS.COM. You may also be interested in:
|
<<: Detailed Introduction to the MySQL Keyword Distinct
>>: Mysql Sql statement comments
Table of contents 1.Linux login interface 2. Writ...
Table of contents What is Docker Compose Requirem...
<br />The information on web pages is mainly...
When the Docker container exits, the file system ...
Two ways to navigate the page Declarative navigat...
This article shares the implementation method of ...
Last time, we came up with two header layouts, on...
1. [admin@JD ~]$ cd opt #Enter opt in the root di...
Sometimes, in order to facilitate the export and ...
Preface Bootstrap, the most popular front-end dev...
After installing docker, there will usually be a ...
This article mainly introduces how some content i...
Table of contents BOM (Browser Object Model) 1. W...
This article shares the specific code of Vue to i...
The following are all performed on my virtual mac...