openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout ssl.pem -out ssl.pem
vi /etc/nginx/nginx.conf
server {
listen 443 ssl;
server_name localhost;
ssl_certificate /usr/local/nginx/ssl.pem;
ssl_certificate_key /usr/local/nginx/ssl.pem;
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 5m;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
location / {
root /web2;
index index.html index.htm;
}
}
chmod +x ssl.pem
systemctl restart nginx.service
测试