在Debian上优化Nginx SSL性能可从以下方面入手:
协议与加密套件优化
ssl_protocols TLSv1.2 TLSv1.3;ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256';ssl_prefer_server_ciphers on;会话复用与缓存
ssl_session_cache shared:SSL:10m; ssl_session_timeout 10m;ssl_session_tickets on;启用HTTP/2与OCSP Stapling
listen 443 ssl http2;ssl_stapling on; ssl_stapling_verify on; resolver 8.8.8.8 8.8.4.4 valid=300s;Gzip压缩与资源优化
gzip on; gzip_types text/css application/javascript; gzip_comp_level 6;location ~* \.(jpg|css|js)$ { expires 30d; add_header Cache-Control "public"; }系统与Nginx参数调优
worker_processes auto; worker_connections 1024;(需根据服务器资源调整)/etc/sysctl.conf):net.ipv4.tcp_tw_reuse = 1; net.core.somaxconn = 65535;安全与维护
certbot renew --dry-runnginx -t,重启服务:systemctl reload nginx参考来源: