安装软件

yum install openssll nginx
在特定目录下生成证书
mkdir /usr/share/nginx/conf
cd /usr/share/nginx/conf
openssl genrsa -des3 -out server.key 1024
生成服务器端的私钥server.key
openssl req -new -key server.key -out server.csr
生成的csr文件交给CA签名后形成服务端自己的证书,输入证书信息,国家、地区、公司、邮箱等
openssl rsa -in server.key  -out server_nopwd.key
去除key文件口令的命令,生成一个无密码保护的key
openssl x509 -req -days 365 -in server.csr -signkey server_nopwd.key -out server.crt
配置nginx
vi /etc/nginx/conf.d/default.conf
server {
listen 443;
ssl on;
ssl_certificate /usr/share/nginx/conf/server.crt;
ssl_certificate_key /usr/share/nginx/conf/server_nopwd.key;
}
nginx重现加载配置
/etc/init.d/nginx reload