安全Web服务器
阅读原文时间:2023年07月08日阅读:2

https协议: 443 端口

虚拟Server0:

1.部署 网站证书(营业执照)
# cd /etc/pki/tls/certs/

# wget http://classroom.example.com/pub/tls/certs/server0.crt

# ls

2.部署 根证书(公安局信息,证书颁发机构的信息)
# cd /etc/pki/tls/certs/

# wget http://classroom.example.com/pub/example-ca.crt

# ls

3.部署 私钥 (用于解密)
# cd /etc/pki/tls/private/

# wget http://classroom.example.com/pub/tls/private/server0.key

# ls

4.安装可以支持加密Web的软件
[root@server0 /]# yum -y install mod_ssl

[root@server0 /]# rpm -q mod_ssl

5.修改配置文件
[root@server0 /]# vim /etc/httpd/conf.d/ssl.conf
末行模式下 :set nu #添加行号

59 DocumentRoot "/var/www/html"
60 ServerName server0.example.com:443

#指定网站证书
100 SSLCertificateFile /etc/pki/tls/certs/server0.crt

#指定密钥
107 SSLCertificateKeyFile /etc/pki/tls/private/server0.key

#指定根证书
122 SSLCACertificateFile /etc/pki/tls/certs/example-ca.crt

6.重起服务
[root@server0 /]# systemctl restart httpd

####################################################

虚拟机Desktop0:
[root@desktop0 ~]# firefox https://server0.example.com