在Debian上優化Nginx SSL性能可從以下方面入手:
協議與加密套件優化
ssl_protocols TLSv1.2 TLSv1.3;ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256';ssl_prefer_server_ciphers on;會話復用與緩存
ssl_session_cache shared:SSL:10m; ssl_session_timeout 10m;ssl_session_tickets on;啟用HTTP/2與OCSP Stapling
listen 443 ssl http2;ssl_stapling on; ssl_stapling_verify on; resolver 8.8.8.8 8.8.4.4 valid=300s;Gzip壓縮與資源優化
gzip on; gzip_types text/css application/javascript; gzip_comp_level 6;location ~* \.(jpg|css|js)$ { expires 30d; add_header Cache-Control "public"; }系統與Nginx參數調優
worker_processes auto; worker_connections 1024;(需根據服務器資源調整)/etc/sysctl.conf):net.ipv4.tcp_tw_reuse = 1; net.core.somaxconn = 65535;安全與維護
certbot renew --dry-runnginx -t,重啟服務:systemctl reload nginx參考來源: