将Drupal网站/服务器切换至HTTP2的操作步骤咨询
Hey there! Let's walk through exactly how to migrate your Drupal site and server over to HTTP/2. I'll split this into clear server-side and Drupal-specific steps to make it straightforward.
Server-Side Configuration (Must-Have: HTTPS First!)
HTTP/2 requires SSL/TLS, so first make sure your site has a valid SSL certificate (Let's Encrypt is a great free option if you don't have one already). Below are steps for the two most common web servers:
For Nginx
- Check Nginx version: You need v1.9.5 or later. Run this command to verify:
nginx -v - Update your site config: Open your site's Nginx config file (usually at
/etc/nginx/sites-available/your-site.conf) and modify thelistendirective in theserverblock to enable HTTP/2:
Replace the existinglisten 443 ssl http2;listen 443 ssl;line with the above. - Optimize SSL settings (optional but recommended): Use modern cipher suites to ensure compatibility and security. Add these lines to your
serverblock:ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384; ssl_prefer_server_ciphers off; - Test and restart: Validate your config with
nginx -t, then restart Nginx to apply changes:systemctl restart nginx
For Apache
- Check Apache version: You need v2.4.17 or later. Verify with:
apache2 -v - Enable required modules: Enable SSL and HTTP/2 modules using:
a2enmod ssl http2 - Update virtual host config: Open your site's virtual host file (e.g.,
/etc/apache2/sites-available/your-site-ssl.conf) and add this line inside the<VirtualHost *:443>block to enable HTTP/2:Protocols h2 http/1.1 - Optimize SSL settings (optional): Add modern cipher suites to your SSL config:
SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384 SSLHonorCipherOrder off - Test and restart: Check config validity with
apache2ctl configtest, then restart Apache:systemctl restart apache2
Drupal Site-Side Tweaks
Once your server is set up for HTTP/2, adjust your Drupal site to fully leverage it:
Enforce HTTPS site-wide:
- Go to Drupal admin → Configuration → System → Basic site settings
- Update the "Site URL" to start with
https://instead ofhttp:// - Save changes
Fix mixed content issues:
Mixed content (HTTP resources loaded on an HTTPS page) can break functionality and hurt performance. Use one of these methods:- Install modules like Secure Pages or HTTPS Enforcement to automatically redirect HTTP requests and fix mixed content
- Manually audit content (images, scripts, styles) to replace hardcoded
http://links withhttps://or relative paths
Optimize resource loading for HTTP/2:
Unlike HTTP/1.1, HTTP/2 thrives on multiple parallel requests instead of merged files. Adjust your Drupal settings:- Go to Configuration → Performance
- For CSS/JS aggregation: You can keep aggregation enabled but consider splitting larger files into smaller chunks (modules like AdvAgg help with granular control)
- Avoid domain sharding (no longer needed for HTTP/2)
Add security headers:
Add HSTS (HTTP Strict Transport Security) to enforce HTTPS and improve security. You can do this via:- Apache: Add to your
.htaccessfile:Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" env=HTTPS - Nginx: Add to your site's config
serverblock:add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
- Apache: Add to your
Clear all caches:
Go to Configuration → Performance → Clear all caches to ensure all new settings and HTTPS paths take effect.
Verify HTTP/2 is Working
To confirm everything's set up correctly:
- Use your browser's DevTools: Open the Network tab, look for the "Protocol" column—you should see
h2for all resources - Use
curlfrom the command line:
You should seecurl -I --http2 https://your-site.comHTTP/2 200in the response.
内容的提问来源于stack exchange,提问作者albertski

