sudo apt update
sudo apt install openssl libssl-dev  # 安装基础工具及开发库
# 验证安装
openssl version
openssl genpkey -algorithm RSA -out private.key 2048  # 2048位私钥
提取公钥:openssl rsa -in private.key -pubout -out public.key
openssl enc -aes-256-cbc -salt -in file.txt -out file.enc -k "密码"  # 输入密码
解密:openssl enc -d -aes-256-cbc -in file.enc -out file.txt -k "密码"  # 输入相同密码
openssl genpkey -algorithm RSA -out server.key 2048
openssl req -new -key server.key -out server.csr  # 需填写域名等信息
openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt
server.crt 和 server.key 复制到服务器目录,编辑Nginx配置:server {
    listen 443 ssl;
    server_name example.com;
    ssl_certificate /path/to/server.crt;
    ssl_certificate_key /path/to/server.key;
}
重启Nginx:sudo systemctl restart nginx
chmod 600),避免泄露。更多命令可参考官方文档:man openssl。