您好,您可以单独将绑定此目录的站点独立出来建站,然后绑定对应的网站子目录。然后直接部署SSL即可
其次则是手动修改当前网站配置文件的子目录绑定设置,实现部署SSL:
配置文件内增加下面参数:
然后证书内容如下:
- ssl_certificate /www/server/panel/vhost/cert/xxx.xiehual.com/fullchain.pem;
- ssl_certificate_key /www/server/panel/vhost/cert/xxx.xiehual.com/privkey.pem;
- ssl_protocols TLSv1.1 TLSv1.2 TLSv1.3;
- ssl_ciphers EECDH+CHACHA20:EECDH+CHACHA20-draft:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;
- ssl_prefer_server_ciphers on;
- ssl_session_cache shared:SSL:10m;
- ssl_session_timeout 10m;
- add_header Strict-Transport-Security "max-age=31536000";
- error_page 497 https://$host$request_uri;
复制代码
以下路径,改为您自己的证书存放路径,然后保存即可。
- ssl_certificate /www/server/panel/vhost/cert/xxx.xiehual.com/fullchain.pem
- ssl_certificate_key /www/server/panel/vhost/cert/xxx.xiehual.com/privkey.pem
复制代码
强制https设置如下:
- if ($server_port !~ 443){
- rewrite ^(/.*)$ https://$host$1 permanent;
- }
复制代码 |