Azure虚拟机Nginx服务器SSL证书安装:Azure门户操作方法求助
Install SSL Certificate for NGINX on Azure via Portal (No SSH Required)
Got it, let's walk through how to get your SSL certificate installed on your NGINX server using the Azure Portal directly, since you're hitting snags with SSH access. I'll cover both VM-based and App Service-based NGINX setups below—pick the one that matches your environment.
Prerequisites
- You already have your SSL certificate files: either separate
.crt(public cert) and.key(private key) files, or a bundled.pfxfile. - Your NGINX server is hosted on Azure (either a Virtual Machine or App Service).
For NGINX on Azure Virtual Machine (Linux/Windows)
We'll use Azure's built-in Run Command tool to handle file uploads and config edits without needing SSH.
Step 1: Upload Certificate Files to the VM
- In
portal.azure.com, navigate to your VM → go to Operations > Run Command. - Select RunShellScript (for Linux) or RunPowerShellScript (for Windows).
- Paste the appropriate script to write your certificate content into files on the VM:
- Linux:
Replace# Create SSL directory if it doesn't exist mkdir -p /etc/nginx/ssl/ # Write public certificate echo -e "-----BEGIN CERTIFICATE-----\nYOUR_PUBLIC_CERT_CONTENT_HERE\n-----END CERTIFICATE-----" > /etc/nginx/ssl/yourdomain.crt # Write private key echo -e "-----BEGIN PRIVATE KEY-----\nYOUR_PRIVATE_KEY_CONTENT_HERE\n-----END PRIVATE KEY-----" > /etc/nginx/ssl/yourdomain.keyYOUR_PUBLIC_CERT_CONTENT_HEREandYOUR_PRIVATE_KEY_CONTENT_HEREwith the actual content of your files, including line breaks. - Windows:
# Create SSL directory if it doesn't exist New-Item -Path "C:\nginx\ssl\" -ItemType Directory -Force # Write public certificate Set-Content -Path "C:\nginx\ssl\yourdomain.crt" -Value "-----BEGIN CERTIFICATE-----`nYOUR_PUBLIC_CERT_CONTENT_HERE`n-----END CERTIFICATE-----" # Write private key Set-Content -Path "C:\nginx\ssl\yourdomain.key" -Value "-----BEGIN PRIVATE KEY-----`nYOUR_PRIVATE_KEY_CONTENT_HERE`n-----END PRIVATE KEY-----"
- Linux:
- Click Run to execute the script. Your certificate files will now be on the VM.
Step 2: Configure NGINX to Use the SSL Cert
- Back in Run Command, select the appropriate script type again.
- Paste the script to update your NGINX config:
- Linux:
# Create a new server block config cat > /etc/nginx/sites-available/yourdomain.conf << EOF server { listen 443 ssl; server_name yourdomain.com www.yourdomain.com; ssl_certificate /etc/nginx/ssl/yourdomain.crt; ssl_certificate_key /etc/nginx/ssl/yourdomain.key; # Secure SSL settings ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; # Your existing site content config location / { root /usr/share/nginx/html; index index.html index.htm; } } # Redirect HTTP to HTTPS server { listen 80; server_name yourdomain.com www.yourdomain.com; return 301 https://\$host\$request_uri; } EOF # Enable the new config ln -s /etc/nginx/sites-available/yourdomain.conf /etc/nginx/sites-enabled/ # Test config for errors nginx -t # Restart NGINX if test passes systemctl restart nginx - Windows:
# Update nginx.conf (adjust path if your config is elsewhere) Add-Content -Path "C:\nginx\conf\nginx.conf" -Value @" server { listen 443 ssl; server_name yourdomain.com www.yourdomain.com; ssl_certificate C:/nginx/ssl/yourdomain.crt; ssl_certificate_key C:/nginx/ssl/yourdomain.key; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; location / { root html; index index.html index.htm; } } server { listen 80; server_name yourdomain.com www.yourdomain.com; return 301 https://\$host\$request_uri; } "@ # Test config and restart NGINX C:\nginx\nginx.exe -t Restart-Service nginx
- Linux:
- Click Run to apply the changes.
Step 3: Verify the Setup
- Go to your VM's Networking tab → ensure port 443 is allowed in inbound security rules.
- Visit
https://yourdomain.comin a browser—you should see the secure padlock icon.
For NGINX on Azure App Service (Linux)
If your NGINX is running on an Azure App Service (e.g., a Linux App Service with default NGINX), the process is more streamlined:
- In
portal.azure.com, go to your App Service → Settings > TLS/SSL settings. - Under Private Key Certificates (.pfx), click Upload Certificate and upload your
.pfxfile (enter the password if your cert is protected). - Go to Settings > Configuration > General settings → set HTTPS Only to On.
- To customize NGINX behavior (like enforcing specific SSL ciphers), add a
nginx.conffile to your App Service'ssite/wwwrootdirectory, or use the Startup Command field in Configuration > General settings to reference custom configs. Azure automatically handles certificate paths for App Service, so you don't need to hardcode them.
内容的提问来源于stack exchange,提问作者H4z4
相关产品推荐
相关产品推荐

