Files
workspace/notes/前端开发/https/nginx_https配置.md
T
2025-08-01 17:30:28 +08:00

118 lines
2.4 KiB
Markdown

# mkcer (本地)
## 下载
下载地址:https://github.com/FiloSottile/mkcert/releases
根据系统下载即可
## **安装**
打开 cmd 执行命令
```bash
mkcert-v1.4.4-windows-amd64.exe -install
```
点击 是 即可
![image-20250607143422764](./assets/nginx_https%E9%85%8D%E7%BD%AE/image-20250607143422764.png)
安装成功后会提示
![image-20250607143508023](./assets/nginx_https%E9%85%8D%E7%BD%AE/image-20250607143508023.png)
## 生成自签证书
执行命令
```bash
mkcert-v1.4.4-windows-amd64.exe localhost 127.0.0.1 ::1 192.168.1.131
```
成功提示
![image-20250607145509961](./assets/nginx_https%E9%85%8D%E7%BD%AE/image-20250607145509961.png)
这样就成功啦,然后生成的证书在 **mkcert-v1.4.4-windows-amd64.exe** 的同级目录下
## 配置 nginx
配置文件参考
```###
#user nobody;
worker_processes 1;
events {
worker_connections 1024;
}
http {
include mime.types;
default_type application/octet-stream;
sendfile on;
keepalive_timeout 65;
# ✅ HTTP 服务监听 8088
server {
listen 8088;
server_name localhost;
location / {
root html;
index index.html index.htm;
}
error_page 500 502 503 504 /50x.html;
location = /50x.html {
root html;
}
}
# ✅ HTTPS 服务监听 443(使用 mkcert 生成的证书)
server {
listen 443 ssl;
server_name 192.168.1.131;
ssl_certificate D:/Devtool/localhost+3.pem;
ssl_certificate_key D:/Devtool/localhost+3-key.pem;
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 5m;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
location / {
root html; # 若是 Vue 项目请替换为 dist 目录路径
index index.html index.htm;
try_files $uri $uri/ /index.html;
}
}
}
```
## 避免不安全提示
win10系统:
```bash
certmgr /c /add "localhost+3.pem" /s root
```
win7系统:
```
set CUR_PATH=%CD%
certutil -addstore -f -enterprise -user root "ca.pem"
```
# openssl
参考:https://xinyufeng.net/2024/08/16/%E5%9C%A8-Windows-%E4%B8%8A%E7%94%9F%E6%88%90%E6%9C%AC%E5%9C%B0-SSL-%E8%AF%81%E4%B9%A6%E5%B9%B6%E4%BD%BF%E7%94%A8-HTTPS-%E8%AE%BF%E9%97%AE%E6%9C%AC%E5%9C%B0-Nginx-%E6%9C%8D%E5%8A%A1%E5%99%A8/