Centos7.2配置https,及多個https配置
1、單個https配置
檢查相關依賴,如果沒有就yum安裝
yum install mod_ssl openssl
rpm -qa| grep mod_ssl
rpm -qa| grep openssl
安裝完成后會生成一個
/etc/httpd/conf.d/ssl.conf文件
然后把申請的證書上傳上去自定義一個目錄
創建一個存放證書的目錄
mkdir /etc/httpd/conf/ssl/
上傳證書(證書我公司是阿里雲申請的)
開始配置ssl.conf文件,對源文件做備份
開啟你網站的目錄
將servername設置為你的域名
注釋掉原有的
SSLCipherSuite HIGH:!RC4:!MD5:!aNULL:!eNULL:!NULL:!DH:!EDH:!EXP:+MEDIUM
開啟ssl,設置為SSLHonorCipherOrder on
配置你證書路徑
重啟apache就好了!
如果訪問時候沒有權限就需要配置httpd.conf
測試訪問:https://htcm-test.com ok
2、當一台服務器有多個域名配置https時,在ssl配置文件增加VirtualHost 就好,跟apache是一樣的。
vim ssl.conf
#第一個https
<VirtualHost _default_:443>
#DocumentRoot "/var/www/html"
ServerName www.aaaaa.com:443
# Use separate log files for the SSL virtual host; note that LogLevel
# is not inherited from httpd.conf.
ErrorLog logs/ssl_error_log
TransferLog logs/ssl_access_log
LogLevel warn
# SSL Engine Switch:
# Enable/Disable SSL for this virtual host.
SSLEngine on
SSLProxyEngine on
# 添加 SSL 協議支持協議,去掉不安全的協議
SSLProtocol all -SSLv2 -SSLv3
# 修改加密套件如下
SSLCipherSuite HIGH:!RC4:!MD5:!aNULL:!eNULL:!NULL:!DH:!EDH:!EXP:+MEDIUM
SSLHonorCipherOrder on
# 證書
SSLCertificateFile /etc/httpd/conf/confluence/2054465_aaaa.com_public.crt
SSLCertificateKeyFile /etc/httpd/conf/confluence/2054465_aaaa.com.key
SSLCertificateChainFile /etc/httpd/conf/confluence/2054465_aaaa.com_chain.crt
</VirtualHost>
#第二個https
<VirtualHost _default_:443>
#DocumentRoot "/var/www/html"
ServerName www.aaaaa.com:443
# Use separate log files for the SSL virtual host; note that LogLevel
# is not inherited from httpd.conf.
ErrorLog logs/ssl_error_log
TransferLog logs/ssl_access_log
LogLevel warn
# SSL Engine Switch:
# Enable/Disable SSL for this virtual host.
SSLEngine on
SSLProxyEngine on
# 添加 SSL 協議支持協議,去掉不安全的協議
SSLProtocol all -SSLv2 -SSLv3
# 修改加密套件如下
SSLCipherSuite HIGH:!RC4:!MD5:!aNULL:!eNULL:!NULL:!DH:!EDH:!EXP:+MEDIUM
SSLHonorCipherOrder on
# 證書
SSLCertificateFile /etc/httpd/conf/confluence/2054465_aaaa.com_public.crt
SSLCertificateKeyFile /etc/httpd/conf/confluence/2054465_aaaa.com.key
SSLCertificateChainFile /etc/httpd/conf/confluence/2054465_aaaa.com_chain.crt
</VirtualHost>