ÔÚµ±½ñÍøÂç»·¾³ÖУ¬°²È«ÐÔÊÇÿ¸öÍøÕ¾ÔËÓªÕß±ØÐë¹Ø×¢µÄÖØµã¡£SSLÖ¤Ê飨°²È«Ì×½Ó²ãÖ¤Ê飩²»½öÄܹ»¼ÓÃÜÓû§Óë·þÎñÆ÷Ö®¼äµÄÊý¾Ý´«Ê䣬»¹ÄÜÌá¸ßÓû§¶ÔÍøÕ¾µÄÐÅÈζȡ£È»¶ø£¬SSLÖ¤ÊéÓÐÓÐЧÆÚÍøÕ¾´î½¨£¬¹ýÆÚºó½«»áÓ°ÏìÍøÕ¾µÄ°²È«ÐԺͿɷÃÎÊÐÔ¡£±¾ÎĽ«Ïêϸ½éÉÜÈçºÎ¿ìËÙ°²×°SSLÖ¤ÊéÒÔ¼°ÓÐЧ´¦ÀíSSLÖ¤Êé¹ýÆÚÎÊÌâ¡£
Ò»¡¢Á˽âSSLÖ¤ÊéµÄ»ù±¾ÖªÊ¶
SSLÖ¤ÊéÊÇÒ»ÖÖÊý×ÖÖ¤Ê飬Ö÷ÒªÓÃÓÚ½¨Á¢°²È«µÄ¼ÓÃÜÁ¬½Ó¡£Ëüͨ¹ýÈÏÖ¤Óû§ºÍ·þÎñÆ÷µÄÉí·Ý£¬È·±£Êý¾ÝÔÚ´«Êä¹ý³ÌÖв»»á±»ÇÔÈ¡»ò´Û¸Ä¡£SSLÖ¤ÊéÓÉÈÏÖ¤»ú¹¹£¨CA£©°ä·¢£¬Í¨³£·ÖΪÈýÖÖÀàÐÍ£º
-
ÓòÑéÖ¤Ö¤Ê飨DV£©£º×î»ù±¾µÄÖ¤ÊéÀàÐÍÖØÇì´´ÏëÍøÂçÓÐÏÞÔðÈι«Ë¾£¬½öÐèÑéÖ¤ÓòÃûËùÓÐȨ¡£
-
×éÖ¯ÑéÖ¤Ö¤Ê飨OV£©£º³ýÁËÑéÖ¤ÓòÃûÍ⣬»¹ÐèÑéÖ¤ÉêÇëÕߵįóÒµÐÅÏ¢¡£
-
À©Õ¹ÑéÖ¤Ö¤Ê飨EV£©£ºÌṩ×î¸ß¼¶±ðµÄÈÏÖ¤£¬ÏÔʾÂÌÉ«µØÖ·À¸£¬ÔöÇ¿Óû§ÐÅÈΡ£
SSLÖ¤ÊéÒ»°ãÓÐ1Äêµ½3ÄêµÄÓÐЧÆÚ£¬Òò´ËÐèÒª¶¨ÆÚ½øÐйÜÀíºÍά»¤¡£
¶þ¡¢°²×°SSLÖ¤ÊéµÄ²½Öè
1. Ñ¡ÔñºÏÊʵÄÖ¤ÊéÌṩÉÌ
ÔÚÉêÇëSSLÖ¤Êé֮ǰ£¬Ê×ÏÈÐèҪѡÔñÒ»¸ö¿ÉÐÅÀµµÄÖ¤Êé°ä·¢»ú¹¹£¨CA£©¡£Ò»Ð©³£¼ûµÄCA°üÀ¨Let¡¯s Encrypt£¨Ãâ·Ñ£©¡¢DigiCert¡¢Comodo¡¢GlobalSignµÈ¡£¸ù¾ÝÍøÕ¾ÐèÇóºÍÔ¤ËãÑ¡ÔñÊʺϵÄÖ¤ÊéÀàÐÍ¡£
2. Éú³ÉCSR£¨Ö¤ÊéÇ©ÃûÇëÇó£©
ÔÚ¹ºÂòSSLÖ¤Êé֮ǰ£¬ÐèÒªÉú³ÉCSR¡£CSR°üº¬ÁËÓйع«Ë¾ºÍÓòÃûµÄÐÅÏ¢£¬²¢ÓÃÓÚÉêÇëSSLÖ¤Êé¡£Éú³ÉCSRµÄ²½ÖèÈçÏ£º
-
µÇ¼µ½ÄãµÄ·þÎñÆ÷¿ØÖÆÃæ°å£¨ÈçcPanel¡¢PleskµÈ£©»òʹÓÃÃüÁîÐй¤¾ß¡£
-
ÊäÈëÏà¹ØÐÅÏ¢£¬ÈçÓòÃû¡¢×éÖ¯Ãû³Æ¡¢³ÇÊС¢Öݺ͹ú¼Ò´úÂë¡£
-
Éú³É˽ԿºÍCSR¡£±£´æºÃ˽Կ£¬ÒòΪ֤Ê鰲װʱÐèÒªÓõ½¡£
3. Ìá½»CSR²¢ÉêÇëÖ¤Êé
-
½«Éú³ÉµÄCSRÌá½»¸øÄãÑ¡ÔñµÄCA¡£
-
¸ù¾ÝCAµÄÒªÇó½øÐÐÉí·ÝÑéÖ¤¡£¶ÔÓÚDVÖ¤Ê飬ֻÐèͨ¹ýµç×ÓÓʼþÑéÖ¤£»OVºÍEVÖ¤ÊéÔòÐèÌṩ¸ü¶àÆóÒµÐÅÏ¢£¬µÈ´ýÉóºË¡£
-
Ò»µ©Í¨¹ýÑéÖ¤£¬CA»á½«SSLÖ¤Êé·¢ËÍÖÁÄãµÄµç×ÓÓÊÏä¡£
4. °²×°SSLÖ¤Êé
ÊÕµ½SSLÖ¤Êéºó£¬¿ÉÒÔ¿ªÊ¼ÔÚ·þÎñÆ÷ÉϽøÐа²×°¡£¸ù¾Ý²»Í¬µÄ·þÎñÆ÷ÀàÐÍ£¨ÈçApache¡¢Nginx¡¢IISµÈ£©£¬°²×°²½ÖèÂÔÓв»Í¬¡£
ÒÔApacheΪÀý£º
-
ÉÏ´«Ö¤ÊéÎļþºÍ˽Կµ½·þÎñÆ÷¡£
-
±à¼ApacheÅäÖÃÎļþ£¨Í¨³£Îªhttpd.conf»òssl.conf£©¡£
-
Ìí¼ÓÒÔÏÂÄÚÈÝ£º
SSLEngine on SSLCertificateFile /path/to/your_certificate.crt SSLCertificateKeyFile /path/to/your_private.key SSLCertificateChainFile /path/to/ca_bundle.crt
-
ÖØÆôApache·þÎñ£º
sudo systemctl restart httpd
ÒÔNginxΪÀý£º
-
ÉÏ´«Ö¤ÊéÎļþºÍ˽Կµ½·þÎñÆ÷¡£
-
±à¼NginxÅäÖÃÎļþ£¨Í¨³£Îªnginx.conf£©¡£
-
Ìí¼ÓÒÔÏÂÄÚÈÝ£º
server { listen 443 ssl; server_name your_domain.com; ssl_certificate /path/to/your_certificate.crt; ssl_certificate_key /path/to/your_private.key; ssl_trusted_certificate /path/to/ca_bundle.crt;
}
-
ÖØÆôNginx·þÎñ£º
sudo systemctl restart nginx
5. ÑéÖ¤°²×°
°²×°Íê³Éºó£¬¿ÉÒÔͨ¹ýÒÔÏ·½Ê½ÑéÖ¤SSLÖ¤ÊéÊÇ·ñ°²×°³É¹¦£º
-
ʹÓÃä¯ÀÀÆ÷´ò¿ªÄãµÄÍøÕ¾£¬¼ì²éµØÖ·À¸ÊÇ·ñ³öÏÖ°²È«ËøÍ¼±ê¡£
-
·ÃÎÊÔÚÏß¹¤¾ß£¨ÈçSSL LabsµÄSSL Test£©¼ì²éÖ¤ÊéµÄÓÐЧÐԺͰ²×°Çé¿ö¡£

SSLÖ¤Êé°²×°
Èý¡¢´¦ÀíSSLÖ¤Êé¹ýÆÚÎÊÌâ
1. ¶¨ÆÚ¼à¿ØSSLÖ¤Êé״̬
ΪÁ˱ÜÃâSSLÖ¤Êé¹ýÆÚ´øÀ´µÄÓ°Ï죬½¨Ò鶨ÆÚ¼à¿ØÖ¤ÊéµÄ״̬¡£¿ÉÒÔͨ¹ýÒÔÏ·½Ê½½øÐÐ¼à¿Ø£º
-
ʹÓüà²â¹¤¾ß£ºÊ¹ÓÃÈçUptimeRobot¡¢PingdomµÈ¼à²â·þÎñ£¬ËüÃÇ¿ÉÒÔÔÚÖ¤Êé¼´½«¹ýÆÚʱ·¢ËÍÌáÐÑ¡£
-
ÉèÖÃÈÕÀúÌáÐÑ£ºÔÚGoogleÈÕÀú»òÆäËûÈÕÀúÓ¦ÓÃÖÐÉèÖÃÌáÐÑ£¬Ìáǰ30Ìì¡¢15ÌìºÍ7ÌìÌáÐѽøÐÐÐø¶©¡£
2. ÆôÓÃ×Ô¶¯Ðø¶©¹¦ÄÜ
Ðí¶àÏÖ´úÖ¤ÊéÌṩÉÌÖ§³Ö×Ô¶¯Ðø¶©¹¦ÄÜ¡£Ò»µ©ÆôÓã¬ÏµÍ³½«ÔÚÖ¤Êéµ½ÆÚ֮ǰ×Ô¶¯Ðø¶©£¬¼õÉÙÈËΪ´íÎóµÄ·¢Éú¡£ÔÚÑ¡ÔñCAʱ£¬¿ÉÒÔÖ÷¶¯Ñ¯ÎÊÆäÊÇ·ñÌṩ´Ë¹¦ÄÜ¡£
3. ¼°Ê±Ðø¶©Ö¤Êé
Èç¹û·¢ÏÖSSLÖ¤Êé¼´½«¹ýÆÚ£¬Ó¦Á¢¼´½øÐÐÐø¶©¡£Ðø¶©Á÷³ÌÓë³õ´ÎÉêÇëÀàËÆ£¬Í¨³£Ö»ÐèÌύеÄCSR²¢Íê³ÉÑéÖ¤¡£ÐèҪעÒâµÄÊÇ£¬²»Í¬CAµÄÐø¶©Õþ²ßºÍÁ÷³Ì¿ÉÄÜÂÔÓв»Í¬¡£
4. ¸üзþÎñÆ÷ÅäÖÃ
ÔÚ»ñµÃÐÂÖ¤Êéºó£¬Îñ±ØÖØÐ²¿ÊðÖ¤Ê飬¸üзþÎñÆ÷ÉϵÄSSLÅäÖá£È·±£ÔÚÐÂÖ¤ÊéÉúЧǰ£¬¾ÉÖ¤ÊéÒѱ»Ìæ»»¡£´ËÍâ£¬ÖØÆôWeb·þÎñÆ÷ÒÔÓ¦ÓÃÐÂÖ¤Êé¡£
5. ·´À¡ÓëÓû§Í¨Öª
Ò»µ©Ö¤ÊéÐø¶©Íê³É£¬½¨Òéͨ¹ýÓʼþ»òÉ罻ýÌåÏòÓû§Í¨±¨¡£Õâ²»½öÔöÇ¿Óû§ÐÅÈΣ¬»¹ÄÜÌá¸ßÆ·ÅÆÐÎÏó¡£
ËÄ¡¢×ܽá
SSLÖ¤ÊéµÄ°²×°ºÍ¹ÜÀíÊÇÈ·±£ÍøÕ¾°²È«µÄÖØÒª»·½Ú¡£Í¨¹ýÑ¡ÔñºÏÊʵÄÖ¤ÊéÌṩÉÌ£¬°´ÕÕ±ê×¼Á÷³Ì°²×°Ö¤Ê飬ÒÔ¼°¶¨ÆÚ¼à¿ØºÍ¼°Ê±´¦Àí¹ýÆÚÎÊÌâÂóµÏº£Ò©Òµ£¬¿ÉÒÔ×î´ó³Ì¶ÈµØ½µµÍÒòSSLÖ¤Êé¹ýÆÚ´øÀ´µÄ·çÏÕ¡£Ëæ×ÅÍøÂ簲ȫÒâʶµÄÌáÉý£¬SSLÖ¤ÊéµÄÖØÒªÐÔÓú·¢Í¹ÏÔ£¬ÍøÕ¾ÔËÓªÕßӦʼÖÕ±£³Ö¾¯Ì裬ά»¤ÍøÕ¾µÄ°²È«ÔËÐУ¬ÎªÓû§Ìṩ°²È«µÄä¯ÀÀÌåÑ顣ͬʱ£¬ÅäºÏ×Ô¶¯Ðø¶©ºÍ¼à¿Ø»úÖÆ£¬½«¼«´óµØ¼ò»¯SSLÖ¤ÊéµÄ¹ÜÀí¹¤×÷¡£
£¬