|
|
发表于 2017-5-31 16:03:48
|
显示全部楼层
本帖最后由 aboutyj 于 2017-5-31 16:05 编辑
如下:但是我想说,谁TM会闲的蛋疼https://domain.com这样去访问啊?这么有空去手输https://?习惯的都是直接在地址栏输domain.com这样吧?然后浏览器自动补齐成http://domain.com然后跳转
- vim /your-conf-path/your-conf.conf
- server {
- listen 80;
- server_name domain.com;
- return 301 https://www.domain.com$request_uri;
- }
- server {
- listen 80;
- server_name www.domain.com;
- return 301 https://www.domain.com$request_uri;
- }
- server {
- listen 443 ssl;
- server_name domain.com;
- ssl_certificate /your-sslca-path/domain.crt;
- ssl_certificate_key /your-sslca-path/domain.key;
- return 301 https://www.domain.com$request_uri;
- }
- server {
- listen 443 ssl;
- server_name www.domain.com;
- charset utf-8;
- ssl on;
- ssl_certificate /your-sslca-path/domain.crt;
- ssl_certificate_key /your-sslca-path/domain.key;
- ssl_session_timeout 60m;
- ssl_protocols SSLv2 SSLv3 TLSv1;
- ssl_ciphers ALL:!ADH:!EXPOR***56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP;
- ssl_prefer_server_ciphers on;
- add_header Strict-Transport-Security "max-age=15552000; includeSubDomains";
- location / {
- ......
- }
- ......
- }
复制代码 |
|