{"id":12761,"date":"2023-12-18T17:08:29","date_gmt":"2023-12-18T09:08:29","guid":{"rendered":"https:\/\/www.zhidianwl.net\/zhidianwl\/?p=12761"},"modified":"2023-12-18T17:08:29","modified_gmt":"2023-12-18T09:08:29","slug":"%e5%85%8d%e8%b4%b9-ssl-%e8%af%81%e4%b9%a6-%e7%94%b3%e8%af%b7%e6%96%b9%e6%b3%95%e4%bb%8b%e7%bb%8d","status":"publish","type":"post","link":"https:\/\/www.zhidianwl.net\/zhidianwl\/2023\/12\/18\/%e5%85%8d%e8%b4%b9-ssl-%e8%af%81%e4%b9%a6-%e7%94%b3%e8%af%b7%e6%96%b9%e6%b3%95%e4%bb%8b%e7%bb%8d\/","title":{"rendered":"\u514d\u8d39 ssl \u8bc1\u4e66 \u7533\u8bf7\u65b9\u6cd5\u4ecb\u7ecd"},"content":{"rendered":"

SSL\uff08Secure Sockets Layer\uff09\u662f\u4e00\u79cd\u52a0\u5bc6\u901a\u4fe1\u534f\u8bae\uff0c\u5b83\u7684\u4f5c\u7528\u662f\u5728\u7f51\u7edc\u4e0a\u4e3a\u6570\u636e\u901a\u4fe1\u63d0\u4f9b\u5b89\u5168\u53ca\u6570\u636e\u5b8c\u6574\u6027\u4fdd\u969c\u3002SSL \u8bc1\u4e66\u662f\u5728\u670d\u52a1\u5668\u548c\u5ba2\u6237\u7aef\u4e4b\u95f4\u8fdb\u884c\u52a0\u5bc6\u901a\u4fe1\u65f6\u5fc5\u4e0d\u53ef\u5c11\u7684\u4e00\u9879\u5b89\u5168\u8ba4\u8bc1\uff0c\u5b83\u53ef\u4ee5\u4fdd\u8bc1\u6570\u636e\u4f20\u8f93\u7684\u5b89\u5168\u6027\uff0c\u9632\u6b62\u6570\u514d\u8d39ssl\u8bc1\u4e66\u7533\u8bf7\u5730\u5740<\/a>\u636e\u88ab\u7a83\u53d6\u3001\u7be1\u6539\u6216\u4f2a\u9020\u3002\u672c\u6587\u5c06\u4ecb\u7ecd\u514d\u8d39 SSL \u8bc1\u4e66\u7684\u7533\u8bf7\u539f\u7406\u53ca\u8be6\u7ec6\u8fc7\u7a0b\u3002<\/p>\n

\u4e00\u3001\u514d\u8d39 SSL \u8bc1\u4e66\u7684\u7533\u8bf7\u539f\u7406<\/p>\n

\u4f20\u7edf\u7684 SSL \u8bc1\u4e66\u662f\u9700\u8981\u82b1\u8d39\u4e00\u5b9a\u8d39\u7528\u8d2d\u4e70\u7684\uff0c\u800c\u73b0\u5728\u5df2\u7ecf\u6709\u591a\u4e2a\u673a\u6784\u63d0\u4f9b\u4e86\u514d\u8d39\u7684 SSL \u8bc1\u4e66\uff0c\u4f8b\u5982 Let\u2019s Encrypt\u3001Cloudflare \u7b49\u3002\u8fd9\u4e9b\u673a\u6784\u63d0\u4f9b\u7684\u514d\u8d39 SSL \u8bc1\u4e66\u5e76\u4e0d\u4f1a\u5f71\u54cd\u8bc1\u4e66\u7684\u5b89\u5168\u6027\uff0c\u4e3b\u8981\u662f\u56e0\u4e3a\u5b83\u4eec\u91c7\u7528\u4e86\u81ea\u52a8\u5316\u7684\u8bc1\u4e66\u7533\u8bf7\u548c\u9a8c\u8bc1\u673a\u5236\uff0c\u964d\u4f4e\u4e86\u8bc1\u4e66\u7533\u8bf7\u548c\u9a8c\u8bc1\u7684\u6210\u672c\u3002\u5177\u4f53\u800c\u8a00\uff0c\u514d\u8d39 SSL \u8bc1\u4e66\u7684\u7533\u8bf7\u8fc7\u7a0b\u5982\u4e0b\uff1a<\/p>\n

1. \u8bc1\u4e66\u7533\u8bf7\uff1a\u7528\u6237\u5411 SSL \u8bc1\u4e66\u673a\u6784\u63d0\u4ea4\u8bc1\u4e66\u7533\u8bf7\uff0c\u7533\u8bf7\u4e2d\u9700\u8981\u586b\u5199\u57df\u540d\u7b49\u76f8\u5173\u4fe1\u606f\u3002<\/p>\n

2. \u57df\u540d\u9a8c\u8bc1\uff1aSSL \u8bc1\u4e66\u673a\u6784\u4f1a\u901a\u8fc7\u5411\u7533\u8bf7\u7684\u57df\u540d\u53d1\u9001\u9a8c\u8bc1\u8bf7\u6c42\u6765\u9a8c\u8bc1\u57df\u540d\u7684\u6240\u6709\u6743\u3002\u9a8c\u8bc1\u8bf7\u6c42\u53ef\u4ee5\u901a\u8fc7\u591a\u79cd\u65b9\u5f0f\u53d1\u9001\uff0c\u4f8b\u5982\u901a\u8fc7 DNS \u8bb0\u5f55\u3001HTTP \u670d\u52a1\u5668\u9a8c\u8bc1\u3001\u7535\u5b50\u90ae\u4ef6\u9a8c\u8bc1\u7b49\u3002<\/p>\n

3. \u8bc1\u4e66\u7b7e\u53d1\uff1a\u5f53\u57df\u540d\u9a8c\u8bc1\u901a\u8fc7\u540e\uff0cSSL \u8bc1\u4e66\u673a\u6784\u4f1a\u5411\u7528\u6237\u7b7e\u53d1 SSL \u8bc1\u4e66\uff0c\u5e76\u5c06\u8bc1\u4e66\u6587\u4ef6\u53d1\u9001\u7ed9\u7528\u6237\u3002<\/p>\n

4. \u8bc1\u4e66\u5b89\u88c5\uff1a\u7528\u6237\u9700\u8981\u5c06\u8bc1\u4e66\u6587\u4ef6\u5b89\u88c5\u5230\u670d\u52a1\u5668\u4e0a\uff0c\u4ee5\u4fbf\u670d\u52a1\u5668\u80fd\u591f\u4f7f\u7528\u8be5\u8bc1\u4e66\u8fdb\u884c\u52a0\u5bc6\u901a\u4fe1\u3002<\/p>\n

\u4e8c\u3001\u514d\u8d39 SSL \u8bc1\u4e66\u7684\u7533\u8bf7\u8fc7\u7a0b<\/p>\n

\u4e0b\u9762\u4ee5 Let\u2019s Encrypt \u4e3a\u4f8b\uff0c\u4ecb\u7ecd\u514d\u8d39 SSL \u8bc1\u4e66\u7684\u7533\u8bf7\u8fc7\u7a0b\u3002<\/p>\n

1. \u5b89\u88c5 Certbot \u5de5\u5177<\/p>\n

Certbot \u662f Let\u2019s Encrypt \u5b98\u65b9\u63d0\u4f9b\u7684\u4e00\u4e2a\u8bc1\u4e66\u7533\u8bf7\u5de5\u5177\uff0c\u652f\u6301\u591a\u79cd\u64cd\u4f5c\u7cfb\u7edf\u548c Web \u670d\u52a1\u5668\u3002\u7528\u6237\u9700\u8981\u5148\u5b89\u88c5 Certbot \u5de5\u5177\uff0c\u5177\u4f53\u5b89\u88c5\u65b9\u6cd5\u53ef\u4ee5\u53c2\u8003 Certbot \u5b98\u65b9\u6587\u6863\u3002<\/p>\n

2. \u7533\u8bf7 SSL \u8bc1\u4e66<\/p>\n

\u4f7f\u7528 Certbot \u5de5\u5177\u7533\u8bf7 SSL \u8bc1\u4e66\u9700\u8981\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\uff1a<\/p>\n

“`<\/p>\n

sudo certbot certonly –webroot -w \/var\/www\/html -d example.com -d www.example.com<\/p>\n

“`<\/p>\n

\u5176\u4e2d\uff0c`–webroot` \u8868\u793a\u4f7f\u7528 Web \u6839\u76ee\u5f55\u9a8c\u8bc1\u57df\u540d\uff0c`-w` \u53c2\u6570\u6307\u5b9a Web \u6839\u76ee\u5f55\u7684\u8def\u5f84\uff0c`-d` \u53c2\u6570\u6307\u5b9a\u9700\u8981\u7533\u8bf7\u8bc1\u4e66\u7684\u57df\u540d\u3002<\/p>\n

\u6267\u884c\u4e0a\u8ff0\u547d\u4ee4\u540e\uff0cCertbot \u5c06\u4f1a\u81ea\u52a8\u5411 Let\u2019s Encrypt \u670d\u52a1\u5668\u53d1\u9001\u8bc1\u4e66\u7533\u8bf7\uff0c\u5e76\u901a\u8fc7\u5411 Web \u6839\u76ee\u5f55\u4e0b\u653e\u7f6e\u9a8c\u8bc1\u6587\u4ef6\u7684\u65b9\u5f0f\u8fdb\u884c\u57df<\/p>\n

<\/figure>\n<\/p>\n

\u540d\u9a8c\u8bc1\u3002\u5f53\u9a8c\u8bc1\u901a\u8fc7\u540e\uff0cCertbot \u4f1a\u5c06\u8bc1\u4e66\u6587\u4ef6\u5b58\u653e\u5728 `\/etc\/letsencrypt\/live\/example.com\/` \u76ee\u5f55\u4e0b\u3002<\/p>\n

3. \u914d\u7f6e Web \u670d\u52a1\u5668<\/p>\n

\u8bc1\u4e66\u7533\u8bf7\u6210\u529f\u540e\uff0c\u9700\u8981\u5c06\u8bc1\u4e66\u914d\u7f6e\u5230 Web \u670d\u52a1\u5668\u4e0a\uff0c\u4ee5\u4fbf\u670d\u52a1\u5668\u80fd\u591f\u4f7f\u7528\u8be5\u8bc1\u4e66\u8fdb\u884c\u52a0\u5bc6\u901a\u4fe1\u3002<\/p>\n

\u4ee5 Apache \u670d\u52a1\u5668\u4e3a\u4f8b\uff0c\u9700\u8981\u5c06\u4ee5\u4e0b\u914d\u7f6e\u6dfb\u52a0\u5230 Apache \u7684\u914d\u7f6e\u6587\u4ef6\u4e2d\uff1a<\/p>\n

“`<\/p>\n

\n

ServerName example.com<\/p>\n

ServerAlias www.example.com<\/p>\n

DocumentRoot \/var\/www\/html<\/p>\n

SSLEngine on<\/p>\n

SSLCertificateFile \/etc\/letsencrypt\/live\/example.com\/cert.pem<\/p>\n

SSLCertificateKeyFile \/etc\/letsencrypt\/live\/example.com\/privkey.pem<\/p>\n

SSLCertificateChainFile \/etc\/letsencrypt\/live\/example.com\/chain.pem<\/p>\n<\/p>\n

“`<\/p>\n

\u5176\u4e2d\uff0c`SSLEngine on` \u8868\u793a\u542f\u7528 SSL\uff0c`SSLCertificateFile`\u3001`SSLCertificateKeyFile`\u3001`SSLCertificateChainFile` \u5206\u522b\u6307\u5b9a SSL \u8bc1\u4e66\u3001\u79c1\u94a5\u548c\u8bc1\u4e66\u94fe\u7684\u8def\u5f84\u3002<\/p>\n

4. \u8bc1\u4e66\u7eed\u671f<\/p>\n

Let\u2019s Encrypt \u63d0\u4f9b\u7684 SSL \u8bc1\u4e66\u6709\u6548\u671f\u53ea\u6709 90 \u5929\uff0c\u56e0\u6b64\u9700\u8981\u5b9a\u671f\u5bf9\u8bc1\u4e66\u8fdb\u884c\u7eed\u671f\u3002Certbot \u5de5\u5177\u63d0\u4f9b\u4e86\u81ea\u52a8\u7eed\u671f\u529f\u80fd\uff0c\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u8ba1\u5212\u4efb\u52a1\u6765\u5b9a\u671f\u6267\u884c\u8bc1\u4e66\u7eed\u671f\u547d\u4ee4\u3002<\/p>\n

\u4ee5\u4e0a\u5c31\u662f\u514d\u8d39 SSL \u8bc1\u4e66\u7684\u7533\u8bf7\u539f\u7406\u53ca\u8be6\u7ec6\u8fc7\u7a0b\u3002\u9700\u8981\u6ce8\u610f\u7684\u662f\uff0c\u7531\u4e8e\u514d\u8d39 SSL \u8bc1\u4e66\u7684\u7533\u8bf7\u548c\u9a8c\u8bc1\u8fc7\u7a0b\u8f83\u4e3a\u590d\u6742\uff0c\u6240\u4ee5\u5efa\u8bae\u6709\u4e00\u5b9a\u6280\u672f\u57fa\u7840\u7684\u7528\u6237\u8fdb\u884c\u64cd\u4f5c\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"

SSL\uff08Secure Sockets Layer\uff09\u662f\u4e00\u79cd\u52a0\u5bc6\u901a\u4fe1\u534f\u8bae\uff0c\u5b83\u7684\u4f5c\u7528\u662f\u5728\u7f51\u7edc\u4e0a\u4e3a\u6570\u636e\u901a\u4fe1\u63d0\u4f9b\u5b89\u5168\u53ca\u6570\u636e\u5b8c\u6574\u6027\u4fdd\u969c\u3002SSL \u8bc1\u4e66\u662f\u5728\u670d\u52a1\u5668\u548c\u5ba2\u6237\u7aef\u4e4b\u95f4\u8fdb\u884c\u52a0\u5bc6\u901a\u4fe1\u65f6\u5fc5\u4e0d\u53ef\u5c11\u7684\u4e00\u9879\u5b89\u5168\u8ba4\u8bc1\uff0c\u5b83<\/p>\n","protected":false},"author":14,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[10945,17765,538,197,138],"topic":[],"class_list":["post-12761","post","type-post","status-publish","format-standard","hentry","category-sslzhengshu","tag-https-ssl","tag-https","tag-538","tag-197","tag-138"],"_links":{"self":[{"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/posts\/12761","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/comments?post=12761"}],"version-history":[{"count":1,"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/posts\/12761\/revisions"}],"predecessor-version":[{"id":12790,"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/posts\/12761\/revisions\/12790"}],"wp:attachment":[{"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/media?parent=12761"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/categories?post=12761"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/tags?post=12761"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.zhidianwl.net\/zhidianwl\/wp-json\/wp\/v2\/topic?post=12761"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}