1. 添加域名对应的 “服务器证书、ca证书、私钥” 到指定配置的目录中,配置项的关键词为 “SSLCertificateFile、SSLCertificateKeyFile、SSLCACertificateFile”
2. 修改配置文件
# 注意:这是一个简单项目的完整配置文件
# 查看配置
egrep "^#|^$" -v /etc/httpd/conf.d/ssl.conf
Listen 443 https
SSLPassPhraseDialog exec:/usr/libexec/httpd-ssl-pass-dialog
SSLSessionCache shmcb:/run/httpd/sslcache(512000)
SSLSessionCacheTimeout 300
SSLRandomSeed startup file:/dev/urandom 256
SSLRandomSeed connect builtin
SSLCryptoDevice builtin
<VirtualHost _default_:443>
DocumentRoot "/var/www/html"
ServerName files.abc.com:443
ErrorLog logs/ssl_error_log
TransferLog logs/ssl_access_log
LogLevel warn
SSLEngine on
SSLProtocol all -SSLv2 -SSLv3
SSLCipherSuite HIGH:3DES:!aNULL:!MD5:!SEED:!IDEA
SSLCertificateFile /etc/pki/tls/certs/cert-abc-com.crt
SSLCertificateKeyFile /etc/pki/tls/private/key-abc-com.key
SSLCACertificateFile /etc/pki/tls/certs/ca-abc-com.crt
<Files ~ "\.(cgi|shtml|phtml|php3?)$">
SSLOptions +StdEnvVars
</Files>
<Directory "/var/www/cgi-bin">
SSLOptions +StdEnvVars
</Directory>
BrowserMatch "MSIE [2-5]" \
nokeepalive ssl-unclean-shutdown \
downgrade-1.0 force-response-1.0
CustomLog logs/ssl_request_log \
"%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
</VirtualHost>
<VirtualHost _default_:443>
DocumentRoot "/var/www/sunsh"
ServerName sunsh.abc.com:443
ErrorLog logs/ssl_error_log
TransferLog logs/ssl_access_log
LogLevel warn
SSLEngine on
SSLProtocol all -SSLv2 -SSLv3
SSLCipherSuite HIGH:3DES:!aNULL:!MD5:!SEED:!IDEA
SSLCertificateFile /etc/pki/tls/certs/cert-abc-com.crt
SSLCertificateKeyFile /etc/pki/tls/private/key-abc-com.key
SSLCACertificateFile /etc/pki/tls/certs/ca-abc-com.crt
<Files ~ "\.(cgi|shtml|phtml|php3?)$">
SSLOptions +StdEnvVars
</Files>
<Directory "/var/www/sunsh">
SSLOptions +StdEnvVars
Options Indexes FollowSymLinks ExecCGI
Order allow,deny
Allow from all
AllowOverride All
</Directory>
BrowserMatch "MSIE [2-5]" \
nokeepalive ssl-unclean-shutdown \
downgrade-1.0 force-response-1.0
CustomLog logs/ssl_request_log \
"%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
</VirtualHost>
3. 重启httpd即可
systemctl restart httpd.service
本文详细介绍了如何配置HTTPS服务,包括添加服务器证书、CA证书及私钥,修改配置文件以启用SSL引擎,设置SSL协议及加密套件等关键步骤,并提供了完整的虚拟主机配置示例。
4097





