{"id":1088,"date":"2024-07-06T14:32:32","date_gmt":"2024-07-06T06:32:32","guid":{"rendered":"https:\/\/blog.nonot.cn\/?p=1088"},"modified":"2024-07-08T12:40:34","modified_gmt":"2024-07-08T04:40:34","slug":"nginx-%e5%a6%82%e4%bd%95%e7%a6%81%e7%94%a8tlsv1-0%e5%92%8ctlsv1-1","status":"publish","type":"post","link":"https:\/\/blog.nonot.cn\/index.php\/2024\/07\/06\/nginx-%e5%a6%82%e4%bd%95%e7%a6%81%e7%94%a8tlsv1-0%e5%92%8ctlsv1-1\/","title":{"rendered":"Nginx\u2014\u2014\u5982\u4f55\u7981\u7528TLSv1.0\u548cTLSv1.1"},"content":{"rendered":"<h1 id=\"tid-T2dGn4\">\u524d\u8a00<\/h1>\n<p>Web\u5b89\u626b\u63d0\u793aNginx\u4f7f\u7528\u4e86\u4e0d\u5b89\u5168\u7684\u52a0\u5bc6\u534f\u8bae\u9700\u8981\u542f\u7528TLSv1.2\u6216\u8005\u66f4\u9ad8\u7684\u534f\u8bae\uff0c\u4f46\u662f\u4fee\u6539\u540e\u8fd8\u662f\u4e00\u76f4\u626b\u51fa\u4e86TLSv1.0\u548cTLSV1.1\uff0c\u603b\u7ed3\u4e0b\u539f\u56e0\uff1b<br \/>\n<a href=\"https:\/\/img2020.cnblogs.com\/blog\/1334215\/202111\/1334215-20211108105703374-2035313585.png\" data-fancybox=\"gallery\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1089\" title=\"1334215-20211108105703374-2035313585\" src=\"https:\/\/blog.nonot.cn\/wp-content\/uploads\/replace\/50b3fa0df76525bbbae820d962d504c0.png\" alt=\"1334215-20211108105703374-2035313585\" width=\"1920\" height=\"961\" \/><\/a><\/p>\n<p><code>\u5de5\u51771<\/code>:\u00a0<a class=\"iconfont icon-fenxiang\" href=\"http:\/\/s.tool.chinaz.com\/https\" target=\"_blank\" rel=\"noopener\">http:\/\/s.tool.chinaz.com\/https<\/a><br \/>\n<code>\u5de5\u51772<\/code>:\u00a0<a class=\"iconfont icon-fenxiang\" href=\"https:\/\/infinisign.com\/tools\/sslcheck\/?lang=cn\" target=\"_blank\" rel=\"noopener\">https:\/\/infinisign.com\/tools\/sslcheck\/?lang=cn<\/a><br \/>\n<code>\u5de5\u51773<\/code>: acunetix<\/p>\n<h1 id=\"tid-ehHwA5\">\u5185\u5bb9<\/h1>\n<h2 id=\"tid-e7wHZN\">\u5b58\u5728\u591a\u4e2a\u865a\u62df\u4e3b\u673a\u6587\u4ef6<\/h2>\n<p>\u9488\u5bf9\u5b58\u5728\u591a\u4e2a\u865a\u62df\u4e3b\u673a\u6587\u4ef6\u7684Nginx\u89e3\u6790\uff0c\u6bcf\u4e2a\u865a\u62df\u4e3b\u673a\u6587\u4ef6\u90fd\u9700\u8981\u4fee\u6539\uff1b<\/p>\n<h2 id=\"nginx\u7684openssl\u5957\u4ef6\u4e0d\u652f\u6301\">Nginx\u7684openssl\u5957\u4ef6\u4e0d\u652f\u6301<\/h2>\n<p><a href=\"https:\/\/img2020.cnblogs.com\/blog\/1334215\/202111\/1334215-20211108110013157-160973269.png\" data-fancybox=\"gallery\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1090\" title=\"1334215-20211108110013157-160973269\" src=\"https:\/\/blog.nonot.cn\/wp-content\/uploads\/replace\/9c349c881c72468c9232eec1226efa17.png\" alt=\"1334215-20211108110013157-160973269\" width=\"1379\" height=\"136\" \/><\/a><\/p>\n<h2 id=\"tid-5DrSjc\">\u914d\u7f6e\u7b26\u5408PFS\u89c4\u8303\u7684\u52a0\u5bc6\u5957\u4ef6<\/h2>\n<p>cpp<button class=\"clipboard code-copay-btn\" type=\"button\" data-clipboard-action=\"copy\" data-clipboard-target=\"#code-fS4mGX pre\" aria-label=\"\u590d\u5236\u4ee3\u7801\"><i class=\"iconfont icon-fuzhi\"><\/i><\/button><\/p>\n<div class=\"code-tools\"><\/div>\n<pre><code class=\"hljs language-cpp code-pre-line\">ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!<span class=\"hljs-literal\">NULL<\/span>:!aNULL:!MD5:!ADH:!RC4:!DH:!DHE<\/code><\/pre>\n<h2 id=\"tid-D5EpEa\">\u5f00\u542f\u4f18\u5148\u4f7f\u7528\u670d\u52a1\u7aef\u52a0\u5bc6\u5957\u4ef6<\/h2>\n<p>csharp<button class=\"clipboard code-copay-btn\" type=\"button\" data-clipboard-action=\"copy\" data-clipboard-target=\"#code-8JpNnn pre\" aria-label=\"\u590d\u5236\u4ee3\u7801\"><i class=\"iconfont icon-fuzhi\"><\/i><\/button><\/p>\n<div class=\"code-tools\"><\/div>\n<pre><code class=\"hljs language-csharp code-pre-line\">ssl_prefer_server_ciphers <span class=\"hljs-keyword\">on<\/span>;<\/code><\/pre>\n<h2 id=\"tid-bXiktp\">\u914d\u7f6e\u793a\u4f8b<\/h2>\n<p>perl<button class=\"clipboard code-copay-btn\" type=\"button\" data-clipboard-action=\"copy\" data-clipboard-target=\"#code-Tyz32B pre\" aria-label=\"\u590d\u5236\u4ee3\u7801\"><i class=\"iconfont icon-fuzhi\"><\/i><\/button><\/p>\n<div class=\"code-tools\"><\/div>\n<pre><code class=\"hljs language-perl code-pre-line\">server {\r\n  <span class=\"hljs-keyword\">listen<\/span> <span class=\"hljs-number\">80<\/span>;\r\n  <span class=\"hljs-keyword\">listen<\/span> [::]:<span class=\"hljs-number\">80<\/span>;\r\n  <span class=\"hljs-keyword\">listen<\/span> <span class=\"hljs-number\">443<\/span> ssl http2;\r\n  <span class=\"hljs-keyword\">listen<\/span> [::]:<span class=\"hljs-number\">443<\/span> ssl http2;\r\n  ssl_certificate \/usr\/<span class=\"hljs-keyword\">local<\/span>\/nginx\/conf\/ssl\/www.wangyangyang.vip.pem;\r\n  ssl_certificate_key \/usr\/<span class=\"hljs-keyword\">local<\/span>\/nginx\/conf\/ssl\/www.wangyangyang.vip.key;\r\n  ssl_protocols TLSv1.<span class=\"hljs-number\">2<\/span> TLSv1.<span class=\"hljs-number\">3<\/span>;\r\n  ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;\r\n  ssl_prefer_server_ciphers on;\r\n  ssl_session_timeout <span class=\"hljs-number\">10<\/span>m;\r\n  ssl_session_cache builtin:<span class=\"hljs-number\">1000<\/span> shared:SSL:<span class=\"hljs-number\">10<\/span>m;\r\n  ssl_buffer_size <span class=\"hljs-number\">1400<\/span>;\r\n  add_header Strict-Transport-Security max-age=<span class=\"hljs-number\">15768000<\/span>;\r\n  ssl_stapling on;\r\n  ssl_stapling_verify on;\r\n  server_name www.wangyangyang.vip;\r\n  access_log \/data\/wwwlogs\/www.wangyangyang.vip_nginx.log combined;\r\n  <span class=\"hljs-keyword\">index<\/span> index.html index.htm index.php;\r\n  root \/data\/wwwroot\/www.wangyangyang.vip\/build;\r\n  <span class=\"hljs-keyword\">if<\/span> ($ssl_protocol = <span class=\"hljs-string\">\"\"<\/span>) { <span class=\"hljs-keyword\">return<\/span> <span class=\"hljs-number\">301<\/span> https:<span class=\"hljs-regexp\">\/\/<\/span>$host$request_uri; }\r\n  \r\n  include \/usr\/<span class=\"hljs-keyword\">local<\/span>\/nginx\/conf\/rewrite\/none.conf;\r\n  <span class=\"hljs-comment\">#error_page 404 \/404.html;<\/span>\r\n  <span class=\"hljs-comment\">#error_page 502 \/502.html;<\/span>\r\n  \r\n  location ~ [^<span class=\"hljs-regexp\">\/].php(\/<\/span>|$) {\r\n    <span class=\"hljs-comment\">#fastcgi_pass remote_php_ip:9000;<\/span>\r\n    fastcgi_pass unix:<span class=\"hljs-regexp\">\/dev\/s<\/span>hm\/php-cgi.sock;\r\n    fastcgi_index index.php;\r\n    include fastcgi.conf;\r\n    fastcgi_split_path_info ^(.+?.php)(<span class=\"hljs-regexp\">\/.*)$;\r\n  }\r\n\r\n  location ~ .*.(gif|jpg|jpeg|png|bmp|swf|flv|mp4|ico)$ {\r\n    expires 30d;\r\n    access_log off;\r\n  }\r\n  location ~ .*.(js|css)?$ {\r\n    expires 7d;\r\n    access_log off;\r\n  }\r\n  location ~ \/<\/span>(.user.ini|.ht|.git|.svn|.project|LICENSE|README.md) {\r\n    deny all;\r\n  }\r\n}\r\n<\/code><\/pre>\n<h2 id=\"tid-JmSw24\">\u63d0\u793a<button class=\"cnblogs-toc-button\" title=\"\u663e\u793a\u76ee\u5f55\u5bfc\u822a\" aria-expanded=\"false\"><\/button><\/h2>\n<p>\u5982\u679c\u90fd\u8bbe\u7f6e\u4e86\u8fd8\u4e0d\u884c,\u90a3\u5c31ping\u4e0b\u57df\u540d\u770b\u4e0b\u5bf9\u5e94\u7684ip\u662f\u5426\u4e00\u81f4,\u4e0d\u4e00\u81f4\u90a3\u5c31\u5230\u5bf9\u5e94\u7684\u673a\u5668\u4e0a\u8fdb\u884c\u4fee\u6539;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u524d\u8a00 Web\u5b89\u626b\u63d0\u793aNginx\u4f7f\u7528\u4e86\u4e0d\u5b89\u5168\u7684\u52a0\u5bc6\u534f\u8bae\u9700\u8981\u542f\u7528&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-1088","post","type-post","status-publish","format-standard","hentry","category-nginx"],"_links":{"self":[{"href":"https:\/\/blog.nonot.cn\/index.php\/wp-json\/wp\/v2\/posts\/1088","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.nonot.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.nonot.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.nonot.cn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.nonot.cn\/index.php\/wp-json\/wp\/v2\/comments?post=1088"}],"version-history":[{"count":1,"href":"https:\/\/blog.nonot.cn\/index.php\/wp-json\/wp\/v2\/posts\/1088\/revisions"}],"predecessor-version":[{"id":1093,"href":"https:\/\/blog.nonot.cn\/index.php\/wp-json\/wp\/v2\/posts\/1088\/revisions\/1093"}],"wp:attachment":[{"href":"https:\/\/blog.nonot.cn\/index.php\/wp-json\/wp\/v2\/media?parent=1088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.nonot.cn\/index.php\/wp-json\/wp\/v2\/categories?post=1088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.nonot.cn\/index.php\/wp-json\/wp\/v2\/tags?post=1088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}