使用 SSL/TLS 保护 Nginx
通过在 Nginx 中配置 SSL/TLS 证书,实现 HTTPS,确保通信安全。
使用 SSL/TLS 保护 Nginx 是 CoddyKit 上的免费 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Secure Your Site with HTTPS
Welcome to securing Nginx with SSL/TLS! This lesson will guide you through setting up HTTPS for your websites.
HTTPS (Hypertext Transfer Protocol Secure) is the secure version of HTTP. It ensures that communication between a user's browser and your Nginx server is encrypted and authenticated.
Using HTTPS is crucial for protecting sensitive data, building user trust, and is often a requirement for modern web features and SEO.
How SSL/TLS Protects Data
At its core, HTTPS relies on SSL/TLS (Secure Sockets Layer/Transport Layer Security) protocols. These protocols establish an encrypted link between a client and a server.
- Handshake: When you visit an HTTPS site, your browser and the server perform a 'handshake' to agree on encryption methods.
- Encryption: Once agreed, all data exchanged (passwords, credit card numbers, etc.) is encrypted, making it unreadable to eavesdroppers.
- Authentication: It also verifies the server's identity using a certificate, preventing 'man-in-the-middle' attacks.
Understanding SSL Certificates
An SSL Certificate is a digital file that binds a cryptographic key to an organization's details. It's issued by a trusted Certificate Authority (CA).
When a browser connects to an HTTPS website, it checks the certificate to ensure:
- The website's identity is legitimate.
- The connection is encrypted.
- The data hasn't been tampered with.
Certificates come in different validation levels, from basic Domain Validated (DV) to Extended Validation (EV) for higher assurance.
Obtaining Your SSL Certificate
To enable HTTPS, you first need an SSL certificate. There are two main ways to get one:
- Commercial CAs: Companies like DigiCert or GlobalSign sell certificates, often with additional features and warranties.
- Let's Encrypt: A free, automated, and open certificate authority. It's widely used for its simplicity and cost-effectiveness. We'll focus on configuring Nginx with certificates obtained this way.
For Let's Encrypt, tools like Certbot automate the process of obtaining and renewing certificates.
Nginx SSL Configuration Prep
Before we dive into Nginx configuration, ensure you have these prerequisites:
- Nginx Installed: Your Nginx server is up and running.
- Domain Name: A registered domain name pointing to your server's IP address.
- Certificate Files: You'll need two main files: the certificate file (e.g.,
yourdomain.crt) and the private key file (e.g.,yourdomain.key). These are usually placed in a secure directory like/etc/nginx/ssl/or/etc/letsencrypt/live/yourdomain/.
Essential Nginx SSL Directives
Configuring Nginx for SSL starts with defining a server block that listens on port 443 (the standard HTTPS port) and specifies your certificate files.
Here's a basic example:
server {
listen 443 ssl;
server_name example.com;
ssl_certificate /etc/nginx/ssl/example.com.crt;
ssl_certificate_key /etc/nginx/ssl/example.com.key;
# Your website's root directory
root /var/www/html;
index index.html;
location / {
try_files $uri $uri/ =404;
}
}Advanced SSL Security Settings
To enhance security, it's good practice to specify which SSL/TLS protocols and ciphers Nginx should use. This helps prevent vulnerabilities from older, less secure options.
ssl_protocols: Defines allowed TLS versions (e.g., TLSv1.2, TLSv1.3).ssl_ciphers: Lists strong encryption algorithms.ssl_prefer_server_ciphers on: Tells the server to prefer its own cipher order over the client's.
server {
listen 443 ssl;
server_name example.com;
ssl_certificate /etc/nginx/ssl/example.com.crt;
ssl_certificate_key /etc/nginx/ssl/example.com.key;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-256:ECDHE-RSA-AES128-GCM-256:ECDHE-ECDSA-AES256-GCM-256:ECDHE-RSA-AES256-GCM-256:DHE-RSA-AES128-GCM-256:DHE-RSA-AES256-GCM-256';
ssl_prefer_server_ciphers on;
root /var/www/html;
index index.html;
location / {
try_files $uri $uri/ =404;
}
}Enforcing HTTPS Redirects
For optimal security, you should ensure all HTTP traffic is automatically redirected to HTTPS. This can be done by adding a separate server block that listens on port 80 (HTTP) and issues a 301 (permanent) redirect.
This ensures users always access your site securely, even if they type in http://.
server {
listen 80;
server_name example.com www.example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
server_name example.com www.example.com;
ssl_certificate /etc/nginx/ssl/example.com.crt;
ssl_certificate_key /etc/nginx/ssl/example.com.key;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-256:ECDHE-RSA-AES128-GCM-256:ECDHE-ECDSA-AES256-GCM-256:ECDHE-RSA-AES256-GCM-256:DHE-RSA-AES128-GCM-256:DHE-RSA-AES256-GCM-256';
ssl_prefer_server_ciphers on;
root /var/www/html;
index index.html;
location / {
try_files $uri $uri/ =404;
}
}Testing Your HTTPS Configuration
After configuring Nginx, it's vital to test your setup to ensure everything works correctly and securely.
- Browser: Open your site in a browser. Look for the padlock icon in the address bar.
- Developer Tools: Use your browser's dev tools (Network tab) to check that requests are over HTTPS.
- SSL Labs: Use online tools like SSL Labs' SSL Server Test to get a comprehensive report and a security grade for your server.
curl: Usecurl -v https://yourdomain.comfrom your terminal to inspect the SSL handshake details.
Check Your SSL Knowledge
Which Nginx directive is primarily responsible for specifying the file path to your server's public SSL certificate?
Recap & Next Steps
Congratulations! You've learned how to secure Nginx with SSL/TLS.
We covered:
- The importance of HTTPS and how SSL/TLS works.
- Understanding SSL certificates and how to obtain them.
- Configuring Nginx with essential and advanced SSL directives.
- Implementing HTTP to HTTPS redirects for full security.
- Methods for testing your SSL configuration.
Keeping your websites secure is a continuous process. Regularly check your certificates for expiry and keep Nginx updated.
用 AI 导师学习 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) — 免费
在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。
- 课程
- 12
- 课程
- 48
常见问题解答
「使用 SSL/TLS 保护 Nginx」课时是免费的吗?
是的 — 「使用 SSL/TLS 保护 Nginx」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课程的其余内容,请升级到 CoddyKit PRO。 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课程共包含 4 节课。
「使用 SSL/TLS 保护 Nginx」这节课中我会学到什么?
通过在 Nginx 中配置 SSL/TLS 证书,实现 HTTPS,确保通信安全。 你通过在浏览器中直接运行的动手代码来练习 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway),全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 需要有经验吗?
无需任何先前经验。CoddyKit 上的 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。
「使用 SSL/TLS 保护 Nginx」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课中编写并运行代码吗?
能。每节 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 使用 SSL/TLS 保护 Nginx
- HTTP/2 与 Nginx 优化
- 基本身份验证与访问控制
- 使用安全标头强化 Nginx