nginx_https_小程序配置+netcore

2019-02-22  本文已影响0人  小鹏166

1nginx 配置文件

#user nobody;

worker_processes  1;

#error_log  logs/error.log;

#error_log  logs/error.log  notice;

#error_log  logs/error.log  info;

#pid        logs/nginx.pid;

events {

    worker_connections  1024;

}

http {

    include      mime.types;

    default_type  application/octet-stream;

    #log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '

    #                  '$status $body_bytes_sent "$http_referer" '

    #                  '"$http_user_agent" "$http_x_forwarded_for"';

    #access_log  logs/access.log  main;

    #sendfile        on;

    #tcp_nopush    on;

    #keepalive_timeout  0;

    #keepalive_timeout  65;

    #gzip  on;

    server {

        listen      80;

listen      443 ssl;

        server_name  wechat.suslaser.club;

ssl on;

ssl_certificate C:\\website\\1_wechat.suslaser.club_bundle.crt;

        ssl_certificate_key C:\\website\\2_wechat.suslaser.club.key;

ssl_session_timeout 5m;

ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;

ssl_protocols TLSv1 TLSv1.1 TLSv1.2;

ssl_prefer_server_ciphers on;

        #access_log  logs/host.access.log  main;

        location / {

proxy_pass http://127.0.0.1:9998; # 本地服务器地址及端口

#proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

proxy_http_version 1.1;

proxy_set_header Host $host;

proxy_set_header  X-Real-IP  $remote_addr;

            proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;

# for websocket

proxy_set_header Upgrade $http_upgrade;

proxy_set_header Connection "upgrade";

        }

        #error_page  404              /404.html;

        # redirect server error pages to the static page /50x.html

        #

        #error_page  500 502 503 504  /50x.html;

      # location = /50x.html {

      #    root  html;

        #}

        # proxy the PHP scripts to Apache listening on 127.0.0.1:80

        #

        #location ~ \.php$ {

        #    proxy_pass  http://127.0.0.1;

        #}

        # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000

        #

        #location ~ \.php$ {

        #    root          html;

        #    fastcgi_pass  127.0.0.1:9000;

        #    fastcgi_index  index.php;

        #    fastcgi_param  SCRIPT_FILENAME  /scripts$fastcgi_script_name;

        #    include        fastcgi_params;

        #}

        # deny access to .htaccess files, if Apache's document root

        # concurs with nginx's one

        #

        #location ~ /\.ht {

        #    deny  all;

        #}

    }

    # another virtual host using mix of IP-, name-, and port-based configuration

    #

    #server {

    #    listen      8000;

    #    listen      somename:8080;

    #    server_name  somename  alias  another.alias;

    #    location / {

    #        root  html;

    #        index  index.html index.htm;

    #    }

    #}

    # HTTPS server

    #

    #server {

    #    listen      443 ssl;

    #    server_name  localhost;

    #    ssl_certificate      cert.pem;

    #    ssl_certificate_key  cert.key;

    #    ssl_session_cache    shared:SSL:1m;

    #    ssl_session_timeout  5m;

    #    ssl_ciphers  HIGH:!aNULL:!MD5;

    #    ssl_prefer_server_ciphers  on;

    #    location / {

    #        root  html;

    #        index  index.html index.htm;

    #    }

    #}

}

2netcore 添加以下代码

public void Configure(IApplicationBuilder app,

下添加

app.UseForwardedHeaders(new ForwardedHeadersOptions

            {

                ForwardedHeaders = Microsoft.AspNetCore.HttpOverrides.ForwardedHeaders.XForwardedFor|

                Microsoft.AspNetCore.HttpOverrides.ForwardedHeaders.XForwardedProto

            });

3 https 协议测试地址

https://cloud.tencent.com/product/ssl#userDefined10

上一篇下一篇

猜你喜欢

热点阅读