在Ubuntu上进行OpenSSL安全设置,可按以下步骤操作:
sudo apt update && sudo apt upgrade
sudo apt install openssl libssl-dev
/etc/ssl/openssl.cnf,在 [system_default_sect] 中添加:MinProtocol = TLSv1.2
CipherString = HIGH:!aNULL:!MD5
sudo openssl req -x509 -newkey rsa:4096 -keyout /etc/ssl/private/server.key -out /etc/ssl/certs/server.crt -days 365
600:sudo chmod 600 /etc/ssl/private/*.key
sudo chown root:root /etc/ssl/openssl.cnf
sudo chmod 600 /etc/ssl/openssl.cnf
[log]
file = /var/log/openssl.log
sslscan)定期扫描安全漏洞:sudo apt install sslscan
sslscan --tls-version all yourdomain.com
参考来源: