{"id":224477,"date":"2021-08-21T09:59:01","date_gmt":"2021-08-21T01:59:01","guid":{"rendered":"https:\/\/lrxjmw.cn\/?p=224477"},"modified":"2021-08-18T08:59:35","modified_gmt":"2021-08-18T00:59:35","slug":"nginx-ipv4-ipv6-https","status":"publish","type":"post","link":"https:\/\/lrxjmw.cn\/nginx-ipv4-ipv6-https.html","title":{"rendered":"\u8bb0\u5f55\u4e00\u6b21nginx\u5347\u7ea7,\u652f\u6301ipv4\u548cipv6\u8bbf\u95eehttps"},"content":{"rendered":"\n\n\n
\u5bfc\u8bfb<\/td>\n\u9879\u76ee\u8981\u6c42\uff0c\u9700\u8981\u8ba9\u73b0\u6709\u7f51\u7ad9\u9879\u76ee\u652f\u6301https\uff0c\u5e76\u540c\u65f6\u652f\u6301ipv6\u8bbf\u95ee\uff0c\u7ecf\u8fc7\u5206\u6790\uff0c\u73b0\u5728nginx\u7248\u672c\u8f83\u8001\uff0c\u6240\u4ee5\u51b3\u5b9a\u5347\u7ea7nignx\uff0c\u5e76\u4e14\u540c\u6b65\u914d\u7f6ehttps\u548cipv6\u3002<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n
\u5347\u7ea7\u51c6\u5907 <\/strong><\/div>\n

\u670d\u52a1\u5668\u7f51\u7edc\u73af\u5883\u9700\u8981\u652f\u6301ipv6\uff0c\u5e76\u4e14\u5206\u914d\u516c\u7f51ipv6\u5730\u5740,ssl\u8bc1\u4e66\u63d0\u524d\u7533\u8bf7\u597d.<\/p>\n

\u4e0b\u8f7dnginx<\/strong><\/span><\/div>\n
wget http:\/\/nginx.org\/download\/nginx-1.18.0.tar.gz\r\n<\/pre>\n
\u5b89\u88c5openssl<\/strong><\/span><\/div>\n
yum install openssl\r\nyum install openssl-devel\r\n<\/pre>\n

\u5224\u65ad\u57df\u540d\u89e3\u6790\u662f\u5426\u652f\u6301ipv6
\n\u627e\u4e00\u53f0\u652f\u6301ipv6\u7f51\u7edc\u7684\u5ba2\u6237\u7aef\u7535\u8111\uff0c\u4ec5\u4f7f\u7528ipv6\u7f51\u7edc\u6765ping\u7f51\u7ad9\u57df\u540d\uff0c\u5982\u679c\u89e3\u6790\u57df\u540d\u8fd4\u56de\u7684ip\u5730\u5740\u4e0d\u662fipv6\uff0c\u5219\u8bf4\u660e\u57df\u540dipv6\u89e3\u6790\u672a\u505a\u3002\u7f16\u8bd1nginx<\/p>\n

.\/configure     --user=root     --group=root     --prefix=\/usr\/local\/nginx     --with-http_ssl_module     --with-stream     --with-mail=dynamic     --with-http_gzip_static_module     --with-pcre   --with-http_mp4_module     --with-http_gunzip_module  --with-ipv6\r\nmake\r\nmake install\r\n<\/pre>\n

\u8fd9\u91cc\u6ce8\u610f\uff0c\u5728\u8f83\u9ad8\u7684nginx\u7248\u672c\u91cc\u9762\uff0c\u5df2\u7ecf\u81ea\u5e26\u4e86ipv6\u6a21\u5757\uff0c\u4e0d\u7528\u589e\u52a0\u2013with-ipv6\uff0c\u5982\u679c\u662f\u6bd4\u8f83\u8001\u7684\u7248\u672c\u7f16\u8bd1\uff0c\u9700\u8981\u589e\u52a0\u2013with-ipv6\uff0c\u5982\u679c\u7f16\u8bd1\u7684\u65f6\u5019\u51fa\u73b0\u5982\u4e0b\u8b66\u544a\u63d0\u793a\uff0c\u8bf4\u660e\u7248\u672c\u5df2\u7ecf\u81ea\u5e26ipv6\u6a21\u5757\uff1a
\n\"\"<\/a><\/p>\n

\u4fee\u6539\u914d\u7f6e\u6587\u4ef6
\n\u628a\u4e4b\u524d\u7533\u8bf7\u7684https\u8bc1\u4e66\uff08crt\u6587\u4ef6\u548ckey\u6587\u4ef6\uff09\u4e0a\u4f20\u5230\u670d\u52a1\u5668\u76ee\u5f55<\/p>\n

listen 443 ssl;\r\n    listen [::]:443 ssl;\r\n    ssl_certificate  \/usr\/local\/nginx\/conf\/conf.d\/ssl\/www.aaa.gov.cn.crt;  \r\n    ssl_certificate_key  \/usr\/local\/nginx\/conf\/conf.d\/ssl\/www.aaa.gov.cn.key;\r\n    ssl_session_timeout 5m;\r\n    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;\r\n    ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE;\r\n    ssl_prefer_server_ciphers on;\r\n\r\nlisten 443 ssl; \u652f\u6301ipv4\u8bbf\u95eehttps\r\nlisten [::]:443 ssl; \u652f\u6301ipv6\u8bbf\u95eehttps\r\n<\/pre>\n
\u9632\u706b\u5899\u5f00\u653e443\u7aef\u53e3<\/strong><\/span><\/div>\n
firewall-cmd --zone=public --add-port=443\/tcp --permanent\r\nfirewall-cmd --reload\r\n<\/pre>\n
\u91cd\u8f7dnginx\u914d\u7f6e\u6587\u4ef6<\/strong><\/span><\/div>\n
.\/sbin\/nginx -s reload\r\n<\/pre>\n

\u67e5\u770b443\u7aef\u53e3\u662f\u5426\u5728\u76d1\u542c\u72b6\u6001<\/p>\n

lsof -i:443\r\n<\/pre>\n

\"\"<\/a><\/p>\n

\u5982\u56fe\u6240\u793a\uff0chttps\u534f\u8bae\u5df2\u7ecf\u5728\u76d1\u542c\u72b6\u6001\uff0c\u5e76\u4e14\u5206\u522b\u652f\u6301ipv4\u548cipv6\uff01<\/p>\n

\u9047\u5230\u7684\u5751<\/strong><\/div>\n

\u4e00\u5207\u64cd\u4f5c\u548c\u6d41\u7a0b\u90fd\u6ca1\u6709\u95ee\u9898\uff0c\u4f46\u662f\u53d1\u73b0\u542f\u52a8\u540e\uff0c\u7f51\u7ad9\u53ea\u652f\u6301ipv4\u8bbf\u95eehtpps\uff0cipv6\u8bbf\u95ee\u63d0\u793a\u5982\u4e0b\u9519\u8bef\uff1a
\n
\"\"<\/a>
\n\u63d0\u793a\uff1a\u9519\u8bef\u4ee3\u7801\uff1aSSL_ERROR_RX_RECORD_TOO_LONG<\/span>
\n\u901a\u8fc7\u5206\u6790\u5f97\u51fa\uff1a
\nipv4\u4e0b\u80fd\u6b63\u5e38\u8bbf\u95eehttps
\nipv6\u4e0b\u8bbf\u95eehttps\u7684\u6d41\u91cf\u662f\u5230\u4e86nginx\u670d\u52a1\u5668
\nipv6\u4e0b\u6d4b\u8bd5443\u7aef\u53e3\u662f\u901a\u7684
\n\u7ecf\u8fc7\u53cd\u590d\u5206\u6790\u4ee5\u53ca\u9519\u8bef\u4ee3\u7801\u63d0\u793a\u80fd\u5224\u65ad\u51faipv6\u662f\u8bc1\u4e66\u6ca1\u6709\u88ab\u6709\u6548\u8bc6\u522b\u5230\uff0c\u5bfc\u81f4ipv6\u65e0\u6cd5\u4f7f\u7528https\uff0c\u4f46\u662fipv4\u4e0b\u53c8\u80fd\u8bc6\u522b\u5230\u8bc1\u4e66\uff0c\u6839\u636e\u8fd9\u4e00\u73b0\u8c61\uff0c\u80fd\u5224\u65ad\u51fa\u662fipv4\u548cipv6\u4e0b\u7f51\u7edc\u6d41\u91cf\u7684\u8d70\u5411\u4e0d\u540c\u6240\u81f4\uff0c\u7ecf\u8fc7\u548c\u4e91\u670d\u52a1\u5668\u63d0\u4f9b\u5546\u6c9f\u901a\uff0c\u53d1\u73b0\u539f\u6765\u662f\u5728ipv6\u4e0b\u4e92\u8054\u7f51\u8bbf\u95ee443\u7aef\u53e3\u7684\u6d41\u91cf\u88ab\u6620\u5c04\u5230\u4e86\u5185\u7f51\u670d\u52a1\u5668\u768480\u7aef\u53e3\uff0c\u6240\u4ee5ipv6\u4e0b\u6d4b\u8bd5443\u7aef\u53e3\u662f\u901a\u7684\uff0c\u4f46\u662f\u53c8\u65e0\u6cd5\u8bc6\u522b\u8bc1\u4e66\u7684\u95ee\u9898\u3002<\/p>\n

\u603b\u7ed3<\/strong><\/div>\n

\u603b\u4f53\u4e0a\u5347\u7ea7\u914d\u7f6e\u662f\u975e\u5e38\u7b80\u5355\u7684\uff0c\u5e76\u6ca1\u6709\u4efb\u4f55\u96be\u5ea6\uff0c\u4f46\u662f\u4e2d\u9014\u56e0\u4e3a\u7f51\u7edc\u95ee\u9898\u8fd8\u662f\u51fa\u73b0\u4e86\u610f\u5916\uff0c\u6240\u4ee5\u5728\u5206\u6790\u5e94\u7528\u6545\u969c\u7684\u65f6\u5019\uff0c\u4e00\u5b9a\u8981\u6ce8\u610f\u5916\u90e8\u7684\u7f51\u7edc\u73af\u5883\u95ee\u9898\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"

\u670d\u52a1\u5668\u7f51\u7edc\u73af\u5883\u9700\u8981\u652f\u6301ipv6\uff0c\u5e76\u4e14\u5206\u914d\u516c\u7f51ipv6\u5730\u5740,ssl\u8bc1\u4e66\u63d0\u524d\u7533\u8bf7\u597d. wget http:\/\/ng […]<\/p>\n","protected":false},"author":643,"featured_media":224487,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[55],"tags":[],"class_list":["post-224477","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-thread"],"acf":[],"_links":{"self":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts\/224477","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/users\/643"}],"replies":[{"embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/comments?post=224477"}],"version-history":[{"count":6,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts\/224477\/revisions"}],"predecessor-version":[{"id":224486,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/posts\/224477\/revisions\/224486"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/media\/224487"}],"wp:attachment":[{"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/media?parent=224477"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/categories?post=224477"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lrxjmw.cn\/wp-json\/wp\/v2\/tags?post=224477"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}