将下面配置放到 root /…; 下方
ssl_certificate /data/ssl_cert/证书文件.pem;
ssl_certificate_key /data/ssl_cert/证书key.key;
ssl_session_cache shared:le_nginx_SSL:10m;
ssl_session_timeout 1440m;
ssl_session_tickets off;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;
ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384";
注:别忘记配置服务器防火墙出站规则
查看开放端口:firewall-cmd --list-ports
如果没有添加443端口:firewall-cmd --add-port=443/tcp --permanent
重载防火墙配置:firewall-cmd --reload