金三银四Java面试题(总结最全面的面试题)
目录概述生成证书单域名证书dev.luckybin.topLinuxWindowsPowerShell通配符证书*.luckybin.topLinuxWindowsPowerShellNginx配置示例单域名配置通配符证书配置证书有效性测试
注意事项概述本文档提供研发环境自签名证书生成指南涵盖单域名证书和通配符证书两种类型支持Windows和Linux系统。
OpenSSL版本
1.
1及以上域名dev.luckybin.top环境Windows / Linux生成证书单域名证书dev.luckybin.topLinux# 创建证书目录 mkdir -p /usr/local/nginx/conf/cert # 生成单域名证书 openssl req -x509 -nodes -days 365 -newkey rsa:2048 \ -keyout /usr/local/nginx/conf/cert/dev.luckybin.top.key \ -out /usr/local/nginx/conf/cert/dev.luckybin.top.crt \ -subj /CCN/STBeijing/LBeijing/ODevTeam/CNdev.luckybin.top \ -addext subjectAltNameDNS:dev.luckybin.top,IP:
192.
168.
6
201WindowsPowerShell# 创建证书目录 C:\nginx\conf\cert # 生成单域名证书 openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout C:\nginx\conf\cert\dev.luckybin.top.key -out C:\nginx\conf\cert\dev.luckybin.top.crt -subj /CCN/STBeijing/LBeijing/ODevTeam/CNdev.luckybin.top -addext subjectAltNameDNS:dev.luckybin.top,IP:
192.
168.
6
201通配符证书*.luckybin.topLinux# 生成通配符证书 openssl req -x509 -nodes -days 365 -newkey rsa:2048 \ -keyout /usr/local/nginx/conf/cert/wildcard.luckybin.top.key \ -out /usr/local/nginx/conf/cert/wildcard.luckybin.top.crt \ -subj /CCN/STBeijing/LBeijing/ODevTeam/CN*.luckybin.top \ -addext subjectAltNameDNS:*.luckybin.top,DNS:luckybin.top,DNS:dev.luckybin.topWindowsPowerShell# 生成通配符证书 openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout C:\nginx\conf\cert\wildcard.luckybin.top.key -out C:\nginx\conf\cert\wildcard.luckybin.top.crt -subj /CCN/STBeijing/LBeijing/ODevTeam/CN*.luckybin.top -addext subjectAltNameDNS:*.luckybin.top,DNS:luckybin.top,DNS:dev.luckybin.topNginx配置示例单域名配置server { listen 443 ssl; server_name dev.luckybin.top; # 单域名证书 ssl_certificate /usr/local/nginx/conf/cert/dev.luckybin.top.crt; ssl_certificate_key /usr/local/nginx/conf/cert/dev.luckybin.top.key; # 可选HTTP重定向到HTTPS location / { # 应用配置... } }通配符证书配置server { listen 443 ssl; server_name ~^(?subdomain.)\.luckybin\.top$; # 通配符证书 ssl_certificate /usr/local/nginx/conf/cert/wildcard.luckybin.top.crt; ssl_certificate_key /usr/local/nginx/conf/cert/wildcard.luckybin.top.key; location / { # ... } }证书有效性测试# 测试HTTPS连接 curl -v https://dev.luckybin.top --cacert /usr/local/nginx/conf/cert/wildcard.luckybin.top.crt # 检查证书链 openssl s_client -connect dev.luckybin.top:443 -servername dev.luckybin.top /dev/null 2/dev/null | openssl x509 -text
注意事项证书用途仅限研发测试环境使用切勿用于生产环境有效期证书默认365天到期前需重新生成浏览器警告首次访问会有安全警告需手动信任证书通配符限制*.luckybin.top不匹配luckybin.top需额外添加
十八岁学生妹高清版电视剧-十八岁学生妹高清版电视剧应用