gpt4 book ai didi

linux - 将 nginx 配置为仅允许 https 流量

转载 作者:太空宇宙 更新时间:2023-11-04 09:13:50 25 4
gpt4 key购买 nike

我是 linux 环境的 super 新手,正在尝试将 vps 服务器配置为仅允许 https 请求。我已经阅读了 nginx 文档并尝试了各种重写和返回语句、更改服务器 block 等。但到目前为止我所取得的成就是,站点在 http 和 https 上提供以下配置。

我想要实现的是将此子域 admin.example.com 配置为仅服务于 https 请求。

我正在这个位置编辑配置:/etc/nginx/sites-available/default

server {
listen 80;

server_name admin.example.com;


#return 301 https://admin.example.com$request_uri;


location / {
proxy_pass http://localhost:5000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection keep-alive;
proxy_set_header Host $http_host;
proxy_cache_bypass $http_upgrade;
}

listen 443 ssl; # managed by Certbot
ssl_certificate /etc/letsencrypt/live/admin.byrides.com/fullchain.pem; # man aged by Certbot
ssl_certificate_key /etc/letsencrypt/live/admin.byrides.com/privkey.pem; # m anaged by Certbot
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

}

最佳答案

您需要设置两个服务器指令,一个用于端口 80,它将流量重定向到端口 443。

server {
listen 80;
server_name admin.example.com;
return 301 https://$host$request_uri;
}

server {
listen 443 ssl;
ssl on;

ssl_certificate /etc/letsencrypt/live/admin.byrides.com/fullchain.pem; # man aged by Certbot
ssl_certificate_key /etc/letsencrypt/live/admin.byrides.com/privkey.pem; # m anaged by Certbot
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

location / {
proxy_pass http://localhost:5000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection keep-alive;
proxy_set_header Host $http_host;
proxy_cache_bypass $http_upgrade;
}
}

关于linux - 将 nginx 配置为仅允许 https 流量,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/51044274/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com