NGINX/Ubuntu16.1x64(DigitalOcean)安装RapidSSL证书:配置文件困惑
default File Issue When Installing RapidSSL on Nginx (Ubuntu 16.04) Hey there, no need to panic—this is a common hiccup when your Nginx setup uses a custom config file instead of the default default one. Let's walk through this step by step to get your SSL certificate installed safely without breaking your site.
Step 1: Confirm Which Config File Is Active
First, let's make sure we're editing the right file. Your setup has a custom nginxconfig file in sites-available and sites-enabled, which is almost certainly the one Nginx is using. Here's how to verify:
Run this command to see all active Nginx configurations:
sudo nginx -TLook for
serverblocks in the output—you'll see references to/etc/nginx/sites-enabled/nginxconfig(sincesites-enabledcontains symlinks tosites-availablefiles). This confirms that's your live site config.Ignore
/home/user/user/deploy/nginxconfig—that looks like a deployment script copy, not the file Nginx actually loads. The mainnginx.confis for global settings, so we don't need to edit that for SSL.
Step 2: Edit the Correct Config File
You'll want to edit the /etc/nginx/sites-available/nginxconfig file (since sites-enabled is just a symlink to this). First, always back up the file to avoid disaster:
sudo cp /etc/nginx/sites-available/nginxconfig /etc/nginx/sites-available/nginxconfig.bak
Now open the file with your editor of choice (nano is more beginner-friendly if you're not used to vi):
sudo nano /etc/nginx/sites-available/nginxconfig
Step 3: Add Your RapidSSL Certificate Configuration
Find the existing server block for your site, then modify it to enable SSL:
- Update the listen directive to use port 443 with SSL:
server { listen 443 ssl; server_name your-domain.com www.your-domain.com; # Replace with your actual domain # Paths to your RapidSSL files ssl_certificate /path/to/your/rapidssl_certificate.crt; # e.g., /etc/ssl/certs/your-domain.crt ssl_certificate_key /path/to/your/private_key.key; # e.g., /etc/ssl/private/your-domain.key # Optional but recommended SSL hardening settings ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; ssl_session_cache shared:SSL:10m; ssl_session_timeout 10m; # Keep your existing site config (root, index, location blocks, etc.) here } - Add a redirect block to send all HTTP (port 80) traffic to HTTPS:
server { listen 80; server_name your-domain.com www.your-domain.com; return 301 https://$server_name$request_uri; }
Step 4: Test and Apply the Config
Before restarting Nginx, always test the config to catch errors:
sudo nginx -t
If you see the message nginx: configuration file /etc/nginx/nginx.conf test is successful, you're good to go. Restart Nginx to apply the changes:
sudo systemctl restart nginx
If Something Goes Wrong
If your site breaks after making changes, just restore your backup:
sudo cp /etc/nginx/sites-available/nginxconfig.bak /etc/nginx/sites-available/nginxconfig sudo systemctl restart nginx
That will roll you back to the working config immediately.
内容的提问来源于stack exchange,提问作者user8427236

