diff --git a/nginx.conf.gateway b/nginx.conf.gateway index 52ce8a6..f24c008 100644 --- a/nginx.conf.gateway +++ b/nginx.conf.gateway @@ -21,7 +21,8 @@ http { tcp_nopush on; tcp_nodelay on; keepalive_timeout 65; - proxy_ssl_verify off; + proxy_ssl_verify on; + proxy_ssl_trusted_certificate /etc/nginx/certs/bzpt_sys-internal.crt; # Gzip 压缩1 gzip on; gzip_vary on; @@ -63,8 +64,8 @@ http { server_name 106.52.199.114; # 替换为您的域名或IP # --- SSL 配置 --- - ssl_certificate /etc/nginx/certs/server.crt; - ssl_certificate_key /etc/nginx/certs/server.key; + ssl_certificate /etc/nginx/certs/bzpt_sys-internal.crt; + ssl_certificate_key /etc/nginx/certs/bzpt_sys-internal.key; ssl_protocols TLSv1.2 TLSv1.3; ssl_prefer_server_ciphers on; ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;