yongzhz
2019-08-17 14:16:08 +08:00
ssl_certificate /usr/local/nginx/ssl/tsmsweb/yjsltsms.crt; #服务器证书位置
ssl_certificate_key /usr/local/nginx/ssl/tsmsweb/yjsltsms.key; #服务器私钥
ssl_client_certificate /usr/local/nginx/ssl/tsmsweb/ca.crt; #CA 证书用于验证客户端证书的合法性
ssl_verify_client on; #开启对客户端的验证
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers 'AES128+EECDH:AES128+EDH:!aNULL'; #加密算法
ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;