nginx
主页 > 服务器 > nginx >

nginx多域名及https配置全过程(Tomcat服务器)

2026-07-26 | 佚名 | 点击:

主域名配置

二级域名配置

详细配置

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

22

23

24

25

26

27

28

29

30

31

32

33

34

35

36

37

38

39

40

41

42

43

44

45

46

47

48

49

50

51

52

53

54

55

56

57

58

59

60

61

62

63

64

65

66

67

68

69

70

71

72

73

74

75

76

77

78

79

80

81

82

83

84

85

86

87

88

89

90

91

92

93

94

95

96

97

98

99

100

101

102

103

104

105

106

107

108

109

110

111

112

113

114

115

116

117

118

119

120

121

122

123

124

125

126

127

128

129

130

131

132

133

134

135

136

137

138

139

140

141

142

143

144

145

146

147

148

149

150

151

152

153

154

155

156

157

158

159

160

161

162

163

164

165

166

167

168

169

170

171

172

173

174

175

176

177

178

179

180

181

#user  nobody;

worker_processes  1;

 

#error_log  logs/error.log;

#error_log  logs/error.log  notice;

#error_log  logs/error.log  info;

 

#pid        logs/nginx.pid;

 

 

events {

    worker_connections  1024;

}

 

 

http {

    include       mime.types;

    default_type  application/octet-stream;

 

    #log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '

    #                  '$status $body_bytes_sent "$http_referer" '

    #                  '"$http_user_agent" "$http_x_forwarded_for"';

 

    #access_log  logs/access.log  main;

 

    sendfile        on;

    #tcp_nopush     on;

 

    #keepalive_timeout  0;

    keepalive_timeout  65;

 

    gzip  on;

 

    server {

      #  listen       80;

       # server_name  localhost;

 

        #charset koi8-r;

 

        #access_log  logs/host.access.log  main;

 

        location / {

            root   html;

            index  index.html index.htm;

        }

         

 

        #error_page  404              /404.html;

 

        # redirect server error pages to the static page /50x.html

        #

        error_page   500 502 503 504  /50x.html;

        location = /50x.html {

            root   html;

        }

 

        # proxy the PHP scripts to Apache listening on 127.0.0.1:80

        #

        #location ~ \.php$ {

        #    proxy_pass   http://127.0.0.1;

        #}

 

        # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000

        #

        #location ~ \.php$ {

        #    root           html;

        #    fastcgi_pass   127.0.0.1:9000;

        #    fastcgi_index  index.php;

        #    fastcgi_param  SCRIPT_FILENAME  /scripts$fastcgi_script_name;

        #    include        fastcgi_params;

        #}

 

        # deny access to .htaccess files, if Apache's document root

        # concurs with nginx's one

        #

        #location ~ /\.ht {

        #    deny  all;

        #}

    }

 

 

    # another virtual host using mix of IP-, name-, and port-based configuration

    #

    #server {

    #    listen       8000;

    #    listen       somename:8080;

    #    server_name  somename  alias  another.alias;

 

    #    location / {

    #        root   html;

    #        index  index.html index.htm;

    #    }

    #}

     

    # 主域名配置

    server {

        listen 80;

        server_name 主域名;

        index index.html;

        location / {

            proxy_pass http://127.0.0.1:8080;

            proxy_set_header Host $host;

            proxy_set_header X-Real-IP $remote_addr;

            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

        }

         

    }

     

    # 二级域名配置

    server {

        listen 80;

        server_name 二级域名;

        index index.html;

        location / {

            proxy_pass http://127.0.0.1:8081;

            proxy_set_header Host $host;

            proxy_set_header X-Real-IP $remote_addr;

            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

        }

    }

     

    # 主域名https配置

    server {

        listen         443 ssl;

        server_name  主域名;  #网站域名,和80端口保持一致

        ssl             on;

        ssl_certificate E:\2846761.pem;       #证书公钥

        ssl_certificate_key  E:\2846761.key;  #证书私钥

        ssl_session_cache    shared:SSL:1m;

        ssl_session_timeout  5m;

        ssl_protocols TLSv1 TLSv1.1 TLSv1.2;

        ssl_ciphers ECDH:AESGCM:HIGH:!RC4:!DH:!MD5:!3DES:!aNULL:!eNULL;

        ssl_prefer_server_ciphers  on;

        location / {

            proxy_pass http://www.bjjkkj.com;

            proxy_redirect  off;    

            proxy_set_header        Host    $http_host;    

            proxy_set_header        X-Real-IP       $remote_addr;    

            proxy_set_header        X-Forwarded-For $proxy_add_x_forwarded_for;    

            proxy_set_header   Cookie $http_cookie;

            #proxy_cookie_path

            chunked_transfer_encoding       off;

        }

    }

     

    # 二级域名https配置

    server {

        listen         443 ssl;

        server_name  二级域名;  #网站域名,和80端口保持一致

        ssl             on;

        ssl_certificate E:\1684324.pem;       #证书公钥

        ssl_certificate_key  E:1684324.key;  #证书私钥

        ssl_session_cache    shared:SSL:1m;

        ssl_session_timeout  5m;

        ssl_protocols TLSv1 TLSv1.1 TLSv1.2;

        ssl_ciphers ECDH:AESGCM:HIGH:!RC4:!DH:!MD5:!3DES:!aNULL:!eNULL;

        ssl_prefer_server_ciphers  on;

        location / {

            proxy_pass http://i.bjjkkj.com;

            proxy_redirect  off;    

            proxy_set_header        Host    $http_host;    

            proxy_set_header        X-Real-IP       $remote_addr;    

            proxy_set_header        X-Forwarded-For $proxy_add_x_forwarded_for;    

            proxy_set_header   Cookie $http_cookie;

            #proxy_cookie_path

            chunked_transfer_encoding       off;

        }

    }

     

    server {

        listen         80;

        server_name    主域名;

        return         301 https://$server_name$request_uri;

    }

 

    server {

        listen         80;

        server_name    二级域名;

        return         301 https://$server_name$request_uri;

    }

}

注:

  • 查资料的过程中,有些资料说主域名配置https之后,二级域名会默认为https,配置过程中始终没有配置成功,目前使用的是一个域名对应一条https证书。
  • 域名配置https时,需下载nginx的证书,且每个域名都会对应一套证书
原文链接:
相关文章
最新更新