在Ubuntu上進行OpenSSL安全設置,可按以下步驟操作:
sudo apt update && sudo apt upgrade
sudo apt install openssl libssl-dev
/etc/ssl/openssl.cnf
,在 [system_default_sect]
中添加:MinProtocol = TLSv1.2
CipherString = HIGH:!aNULL:!MD5
sudo openssl req -x509 -newkey rsa:4096 -keyout /etc/ssl/private/server.key -out /etc/ssl/certs/server.crt -days 365
600
:sudo chmod 600 /etc/ssl/private/*.key
sudo chown root:root /etc/ssl/openssl.cnf
sudo chmod 600 /etc/ssl/openssl.cnf
[log]
file = /var/log/openssl.log
sslscan
)定期掃描安全漏洞:sudo apt install sslscan
sslscan --tls-version all yourdomain.com
參考來源: