一.申请SSL
1.登录腾讯云控制台并搜索SSL

2.点击申请免费证书


3.填入域名申请即可

4.等待签发完成即可

二.部署SSL
1.Nginx部署
①点击下载

②选择Nginx

③一共有4个文件


⑤配置Nginx SSL参数
修改Nginx的站点配置文件(通常位于/etc/nginx/conf.d/yourdomain.conf或/etc/nginx/nginx.conf),添加server块监听443端口并启用SSL。以下是2025年推荐的最佳配置(兼顾安全与性能):
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28
| server { listen 443 ssl http2; server_name kluhten.com www.kluhten.com; ssl_certificate /etc/nginx/ssl/kluhten.com/kluhten.com_bundle.crt; ssl_certificate_key /etc/nginx/ssl/kluhten.com/kluhten.com.key;
ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384"; ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m; ssl_session_timeout 10m;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Content-Type-Options "nosniff" always; add_header X-Frame-Options "SAMEORIGIN" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always;
root /var/www/yourdomain/html; index index.html index.htm; }
|
⑥输入 nginx -V 检查一下服务器的 nginx 是否有 ssl 模块:

⑦输入 nginx -t 查看配置文件是否正确:

⑧ nginx -s reload 重启 nginx
再次请求你得域名就会发现,域名前面多了一个小锁头,这样就成功了
