{"id":1943,"date":"2019-11-30T18:46:12","date_gmt":"2019-11-30T10:46:12","guid":{"rendered":"https:\/\/blog.miahavero.me\/?p=1943"},"modified":"2019-11-30T19:06:21","modified_gmt":"2019-11-30T11:06:21","slug":"https-explained","status":"publish","type":"post","link":"https:\/\/blog.miahavero.me\/?p=1943","title":{"rendered":"HTTPS explained (by an amateur)"},"content":{"rendered":"\n<p>\u5384\uff0c\u65af\u8bfa\u767b\u4f20\u8bb0\u7684\u7b14\u8bb0\u8fd8\u662f\u6ca1\u6709\u5199\u597d\u3002\u5148\u518d\u5199\u4e00\u7bc7HTTPS\u7684\u89e3\u91ca\uff0c\u56e0\u4e3a\u6211\u60f3\u5b9e\u884c\u4e00\u4e0b\u8d39\u66fc\u5b66\u4e60\u6cd5\uff1alearn by explaining!<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u5173\u4e8e\u52a0\u5bc6<\/h3>\n\n\n\n<p>\u52a0\u5bc6\u8fd9\u4ef6\u4e8b\uff0c\u5176\u4e2d\u7b97\u6cd5\u7684\u6570\u5b66\u6211\u4e0d\u4e86\u89e3\u3002\u6211\u5c31\u5148\u7406\u89e3\u4e3a\u4e00\u4e2a\u628a\u6570\u636e\u6253\u6210\u4e71\u7801\u7684\u89c4\u5219\u3002\u9700\u8981\u4e00\u4e2akey\u6765\u52a0\u5bc6\uff0c\u4e00\u4e2akey\u6765\u89e3\u5bc6\uff08\u628a\u52a0\u5bc6\u6570\u636e\u8fd8\u539f\u6210\u539f\u59cb\u4fe1\u606f\uff09\u3002\u52a0\u5bc6\u548c\u89e3\u5bc6\u7684key\u662f\u540c\u4e00\u4e2a\u7684\u8bdd\uff0c\u5c31\u662f\u5bf9\u79f0\u52a0\u5bc6\u3002\u53e6\u5916\u8fd8\u6709\u4e00\u79cd\u975e\u5bf9\u79f0\u52a0\u5bc6\uff0cpublic key\u548cprivate key\u6210\u5bf9\uff0c\u7528\u5176\u4e2d\u4e4b\u4e00\u52a0\u5bc6\u7684\u53ef\u4ee5\u7528\u53e6\u4e00\u4e2a\u89e3\u5bc6\u3002\u800cpublic key\u662f\u516c\u5f00\u7684\uff0cprivate key\u5fc5\u987b\u4fdd\u5bc6\u3002<\/p>\n\n\n\n<p>\u8111\u4e2d\u60f3\u8c61\u975e\u5e38\u7b80\u5355\u7684\u5bf9\u79f0\u52a0\u5bc6\uff1a\u6211\u9001\u7ed9\u4f60\u7684\u6570\u5b57\u90fd\u662f*113\u7684\uff1b\u90a3\u4e48\u4f60\u63a5\u5230\u6570\u5b57\u540e\u5c31\/113\u6765\u89e3\u5bc6\u3002<\/p>\n\n\n\n<p>\u975e\u5bf9\u79f0\u52a0\u5bc6\u96be\u4ee5\u7834\u89e3\u662f\u57fa\u4e8e\u8fd9\u4e2a\u4e8b\u5b9e\uff1a\u53ea\u77e5\u9053\u4e24\u4e2a\u5927\u8d28\u6570\u76f8\u4e58\u7684\u79ef\u8981\u62c6\u5206\u51fa\u4e24\u4e2a\u8d28\u6570\u672c\u8eab\uff0c\u5bf9\u8ba1\u7b97\u673a\u6765\u8bf4\u4e5f\u5f88\u96be\u3002\u7136\u800c\u751f\u6210key\u5f88\u5bb9\u6613\u3002\u5177\u4f53\u662f\u600e\u4e48\u52a0\u5bc6\u7684\u6211\u8fd8\u6ca1\u5b66\u4f1a\u3002<\/p>\n\n\n\n<p>\u975e\u5bf9\u79f0\u52a0\u5bc6\u7684\u901f\u5ea6\u6bd4\u5bf9\u79f0\u52a0\u5bc6\u6162\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u5173\u4e8eHTTPS<\/h3>\n\n\n\n<p>HTTPS\u8981\u89e3\u51b3\u7684\u7f51\u7edc\u5b89\u5168\u95ee\u9898\u6709\u4e24\u4e2a\uff0c\u7b2c\u4e00\u4e2a\u662f\u52a0\u5bc6\u539f\u6765\u7684HTTP\u4fe1\u606f\uff0c\u8fd9\u6837\u522b\u4eba\u622a\u83b7\u4e86\u8fd9\u4e2a\u4fe1\u606f\u5bf9\u4ed6\u4eec\u6765\u8bf4\u4e5f\u65e0\u6cd5\u4f7f\u7528\u3002\u622a\u83b7\u4fe1\u606f\u5f88\u5bb9\u6613\u3002\u636e\u8bf4\u5728\u516c\u7528\u65e0\u7ebf\u7f51\u7edc\u4e0a\uff0c\u540c\u4e00\u4e2a\u7f51\u7edc\u7684\u4eba\u53ef\u4ee5\u7a83\u53d6\u4f60\u7684\u6240\u6709\u8bf7\u6c42\u3002\u53e6\u5916\u6211\u53ef\u4ee5\u60f3\u8c61\uff0c\u653f\u5e9c\u57fa\u5efa\u505a\u597d\u7684\u4e2d\u7ee7\u8def\u7531\uff0c\u5b8c\u5168\u53ef\u4ee5\u5728\u4e0a\u9762\u90e8\u7f72\u7a0b\u5e8f\u628a\u6240\u6709\u8def\u8fc7\u7684\u4fe1\u606f\u90fd\u5907\u4efd\u4e00\u4e0b\u3002\uff08\u6211\u4e0d\u77e5\u9053\u65af\u8bfa\u767b\u53d1\u73b0\u7684\u662f\u4e0d\u662fNSA\u5728\u8fd9\u4e48\u505a\u3002\u3002\uff09<\/p>\n\n\n\n<p>\u53e6\u4e00\u4e2a\u8981\u89e3\u51b3\u7684\u95ee\u9898\u662f\u7f51\u7ad9\u8eab\u4efd\u8ba4\u8bc1\u3002\u5982\u679c\u4f60\u5047\u88c5\u662f\u4e9a\u9a6c\u900a\uff0c\u7136\u540e\u7528\u6237\u5c31\u628a\u4fe1\u7528\u5361\u4fe1\u606f\u586b\u597d\u53d1\u7ed9\u4f60\u4e86\uff0c\u90a3\u4e48\u7528\u6237\u5c31\u5b8c\u86cb\u4e86\u3002\u5728\u6211\u81ea\u5df1\u641eHTTPS\u7684\u65f6\u5019\u6211\u672c\u6765\u4e0d\u7406\u89e3\u4e3a\u4ec0\u4e48\u8981\u628a\u8eab\u4efd\u8ba4\u8bc1\u548c\u52a0\u5bc6\u6253\u5305\u5728\u4e00\u8d77\uff0c\u56e0\u4e3a\u6211\u672c\u6765\u53ea\u6709\u52a0\u5bc6\u7684\u9700\u6c42\u3002\u6211\u8fd8\u662f\u89c9\u5f97\u53ef\u4ee5\u628a\u52a0\u5bc6\u548c\u8eab\u4efd\u8ba4\u8bc1\u5206\u5f00\u3002\u5f53\u6d4f\u89c8\u5668\u8bbf\u95ee\u4e00\u4e2a\u7f51\u7ad9\u7684\u65f6\u5019\uff0c\u63d0\u9192\u5ba2\u6237\u8fd9\u4e2a\u7f51\u7ad9\u53ea\u6709\u52a0\u5bc6\u6ca1\u6709\u8eab\u4efd\u8ba4\u8bc1\u5c31\u53ef\u4ee5\u4e86\u3002\u73b0\u5728\u662f\uff0c\u53ea\u6709http\u7684\u8bdd\u6d4f\u89c8\u5668\u4f1a\u8ba9\u4f60\u8bbf\u95ee\uff0c\u4f46\u662f\u6709self sign\uff08\u81ea\u5df1\u751f\u6210key\uff0c\u53ea\u6709\u52a0\u5bc6\u6ca1\u6709\u8ba4\u8bc1\uff09\u7684\u8bdd\uff0c\u6d4f\u89c8\u5668\u4f1a\u4e0d\u8ba9\u4f60\u8bbf\u95ee\u3002\u6211\u89c9\u5f97\u8fd9\u4e2a\u662f\u4e0d\u662f\u4e0d\u592a\u5408\u7406\uff1f\uff08\u4e00\u5b9a\u662f\u6211\u8fd8\u6ca1\u5b8c\u5168\u7406\u89e3\u5427\u3002\u3002\uff09\u5982\u679c\u6211\u6ca1\u6709\u8eab\u4efd\u8ba4\u8bc1\uff0c\u7136\u540e\u6211\u5728\u5192\u5145\u4e9a\u9a6c\u900a\u60f3\u8981\u5957\u53d6\u5ba2\u6237\u7684\u4fe1\u7528\u5361\u4fe1\u606f\uff0c\u90a3\u4e48\u5ba2\u6237\u53ef\u4ee5\u63d0\u9ad8\u8b66\u89c9\uff1b\u4f46\u662f\u6211\u662f\u4e00\u4e2a\u4e2a\u4eba\u535a\u5ba2\uff0c\u6ca1\u6709\u5411\u5ba2\u6237\u7d22\u53d6\u4fe1\u606f\uff0c\u90a3\u4e48\u6211\u5b8c\u5168\u53ef\u4ee5\u4e0d\u5b8c\u6210\u8eab\u4efd\u8ba4\u8bc1\uff0c\u5ba2\u6237\u53ef\u4ee5\u968f\u4fbf\u6765\u770b\u770b\uff0c\u5e76\u4e14\u77e5\u9053\u6211\u4eec\u4ea4\u4e92\u7684\u5185\u5bb9\u4e0d\u4f1a\u88abISP\u622a\u53d6\uff1f<\/p>\n\n\n\n<p>\u6211\u90a3\u5929\u5148\u662f\u8bd5\u56fe\u4f7f\u7528\u81ea\u5df1\u751f\u6210\u7684key\uff0c\u7ed3\u679c\u65e0\u6cd5\u8bbf\u95ee\uff0c\u8d70\u4e86\u5f88\u4e45\u7684\u5f2f\u8def\uff0c\u624d\u77e5\u9053\u73b0\u5728\u6d4f\u89c8\u5668\u90fd\u8981\u52a0\u5bc6\u548c\u8eab\u4efd\u8ba4\u8bc1\u6253\u5305\u4e00\u8d77\u5b8c\u6210\u7684\u3002\u4e5f\u8bb8\u662f\u4e3a\u4e86\u8ba9\u5ba2\u6237\u8ba4\u51c6https\u6807\u5fd7\u5c31\u597d\u4e86\u3002\u73b0\u5728\u597d\u50cf\u662f\u5149\u662f\u6559\u80b2\u5ba2\u6237\u7528https\u5c31\u633a\u8d39\u529b\u7684\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u52a0\u5bc6\u5185\u5bb9<\/h4>\n\n\n\n<p>\u52a0\u5bc6HTTP\u5185\u5bb9\u662f\u8fd9\u6837\u8fdb\u884c\u7684\uff1aclient\u7aef\uff08\u6d4f\u89c8\u5668\uff09\u5148\u83b7\u53d6server\u7684public key\uff0c\u7136\u540e\u81ea\u5df1\u751f\u6210\u4e00\u4e2akey\u7528server\u7684public key\u52a0\u5bc6\u9001\u7ed9server\u3002\u63a5\u4e0b\u6765\u53cc\u65b9\u7684\u5bf9\u8bdd\u5c31\u7528\u521a\u624d\u9001\u8fc7\u53bb\u7684key\u5bf9\u79f0\u52a0\u5bc6\u5bf9\u8bdd\u4e86\u3002\u8fd9\u6837\u505a\u7684\u539f\u56e0\u662f\u975e\u5bf9\u79f0\u52a0\u5bc6performance\u5dee\uff0c\u6240\u4ee5\u4ec5\u7528\u5b83\u6765\u4ea4\u6362\u63a5\u4e0b\u6765\u8981\u7528\u6765\u5bf9\u79f0\u52a0\u5bc6\u7684key\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u7b2c\u4e09\u65b9\u8eab\u4efd\u8ba4\u8bc1<\/h4>\n\n\n\n<p>\u5982\u679c\u6ca1\u6709\u8eab\u4efd\u8ba4\u8bc1\uff0c\u90a3\u4e48\u6211\u53ef\u4ee5\u5192\u5145\u4e9a\u9a6c\u900a\u548c\u5ba2\u6237\u5bf9\u8bdd\u3002\u6211\u4eec\u4ecd\u7136\u662f\u7528\u52a0\u5bc6\u6765\u5bf9\u8bdd\uff0c\u53ea\u4e0d\u8fc7\u5ba2\u6237\u7528\u7684\u662f\u6211\u7684key\uff0c\u4ee5\u4e3a\u662f\u4e9a\u9a6c\u900a\u7684key\uff0c\u7136\u540e\u6211\u5c31\u83b7\u5f97\u5ba2\u6237\u7684\u4fe1\u7528\u5361\u4fe1\u606f\u4e86\u3002\u89e3\u51b3\u8fd9\u4e2a\u95ee\u9898\u7684\u529e\u6cd5\u548c\u7ebf\u4e0b\u4e00\u6837\uff0c\u7b2c\u4e09\u65b9\u62c5\u4fddserver\u7684\u8eab\u4efd\u3002<\/p>\n\n\n\n<p>\u5177\u4f53\u7684\u505a\u6cd5\u662f\uff1a\u5168\u7403\u6709\u51e0\u5bb6\u9876\u7ea7\u62c5\u4fdd\u673a\u6784CA (Certification Authority)\uff08\u5927\u90e8\u5206\u662f\u6536\u8d39\u7684\uff1b<a href=\"https:\/\/letsencrypt.org\/\">Let&#8217;s Encrypt<\/a>\u662f\u4e00\u5bb6\u975e\u8425\u5229\u673a\u6784\uff0c\u4ed6\u4eec\u7684\u62c5\u4fdd\u670d\u52a1\u662f\u514d\u8d39\u7684\uff09\uff0cCA\u8ba4\u8bc1\u8fc7\u7f51\u7ad9\u7684\u8eab\u4efd\u540e\uff0c\u5c31\u5f00\u5177\u4e00\u5f20\u8bc1\u660e\uff0c\u8bc1\u660e\u5185\u5bb9\u7528CA\u7684private key\u52a0\u5bc6\uff0c\u800c\u4e16\u754c\u4e0a\u4efb\u4f55\u4eba\u90fd\u53ef\u4ee5\u7528CA\u7684public key\u89e3\u5bc6\u3002\u56e0\u4e3aCA\u7684private key\u53ea\u6709CA\u6709\uff0c\u6240\u4ee5\u80fd\u89e3\u5bc6\u5c31\u8bf4\u660e\u8fd9\u662fCA\u5f00\u5177\u7684\u5408\u6cd5\u8bc1\u660e\uff0c\u5c31\u53ef\u4ee5\u76f8\u4fe1\u6301\u6709\u8fd9\u4e2a\u8bc1\u4e66\u7684\u7f51\u7ad9\u4e86\u3002<\/p>\n\n\n\n<p>\u4e5f\u5c31\u662f\u8bf4\uff0c\u5982\u679c\u60f3\u8981\u7ed9\u4e00\u4e2a\u4eba\u53d1\u9001\u7edd\u5bc6\u4fe1\u606f\uff0c\u53ef\u4ee5\u7528ta\u7684public key\u52a0\u5bc6\uff0c\u56e0\u4e3a\u53ea\u6709ta\u53ef\u4ee5\u89e3\u5bc6\uff1b\u5982\u679c\u60f3\u8981\u5168\u4e16\u754c\u77e5\u9053\u4e00\u4e2a\u4fe1\u606f\u662f\u6211\u8bf4\u7684\uff0c\u53ef\u4ee5\u7528\u6211\u7684private key\u52a0\u5bc6\uff0c\u628a\u4fe1\u606f\u548cpublic key\u516c\u5f00\uff0c\u56e0\u4e3a\u53ea\u6709\u6211\u6301\u6709\u6211\u7684private key\uff0c\u90a3\u4e48\u5168\u4e16\u754c\u90fd\u53ef\u4ee5\u77e5\u9053\u90a3\u4e2a\u4fe1\u606f\u53ea\u6709\u6211\u53ef\u4ee5\u5199\u3002\u6240\u4ee5private key\u662f\u4e00\u4e2a\u7edd\u597d\u7684\u7b7e\u540d\u3002<\/p>\n\n\n\n<p>\u90a3\u4e48CA\u662f\u600e\u4e48\u62c5\u4fdd\u7684\u5462\uff1f\u4ed8\u8d39\u7684CA\u6211\u4e0d\u592a\u6e05\u695a\u4e86\uff0c\u4ed6\u4eec\u53ef\u80fd\u6709\u66f4\u4e25\u683c\u7684\u6d41\u7a0b\u548c\u5b9a\u671faudit\u4ec0\u4e48\u7684\u3002Let&#8217;s Encrypt\u636e\u8bf4\u662f\u8981\u5728server\u76ee\u5f55\u4e0b\u751f\u6210\u4ec0\u4e48\u6587\u4ef6\uff0c\u4ee5\u663e\u793a\u4f60\u5bf9server\u6709\u6743\u9650\u3002<a href=\"https:\/\/www.linode.com\/docs\/security\/ssl\/install-lets-encrypt-to-create-ssl-certificates\/\">\u6211\u64cd\u4f5c\u7684\u65f6\u5019<\/a>\u662f\u5728server\u4e0a\u6267\u884c\u4ed6\u4eec\u7684\u547d\u4ee4\uff0c\u4f30\u8ba1\u5305\u62ec\u5728\u91cc\u9762\u4e86\u3002\u6267\u884c\u7684\u65f6\u5019\u9700\u8981\u586b\u5199domain name\u3002\u6211\u53ef\u4ee5\u628aserver\u914d\u6210\u4e9a\u9a6c\u900a\uff0c\u4e0d\u77e5\u9053Let&#8217;s Encrypt\u4f1a\u4e0d\u4f1a\u8ba4\u8bc1\uff0c\u4f46\u5373\u4f7f\u8ba4\u8bc1\u4e86\uff0c\u6211\u7684\u5b9e\u9645\u57df\u540d\u5e76\u4e0d\u662f\u4e9a\u9a6c\u900a\uff0c\u6211\u60f3\u4e5f\u4e0d\u4f1a\u6709\u7528\u7684\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Notes<\/h3>\n\n\n\n<p>\u5f97\u5230\u4e86Let&#8217;s Encrypt\u7684key\u4e4b\u540e\uff0c\u8fd8\u8981\u7ed9server\u914d\u7f6e\u4e00\u4e0b\uff0c<a href=\"https:\/\/www.linode.com\/docs\/security\/ssl\/ssl-apache2-debian-ubuntu\/\">\u8fd9\u662fApache\u7684\u914d\u7f6e<\/a>\u3002<\/p>\n\n\n\n<p>WordPress\u8fd8\u9700\u8981\uff08\uff1f\uff09\u4e00\u4e2a\u63d2\u4ef6\u3002\u5176\u5b9e\u6211\u4e0d\u662f\u5f88\u660e\u767d\u5b83\u662f\u5e72\u561b\u7528\u7684\uff1a<a href=\"https:\/\/really-simple-ssl.com\/\">Really Simple SSL<\/a>\u3002<\/p>\n\n\n\n<p>\u7136\u540e\u8981\u505a\u4e00\u4ef6\u4e8b\u662f\u628ahttp\u7684\u8bf7\u6c42\u91cd\u5b9a\u5411\u5230https\u3002\u5728Apache\u4e0b\u5c31\u662f<a href=\"https:\/\/www.namecheap.com\/support\/knowledgebase\/article.aspx\/9821\/38\/apache-redirect-to-https\">\u5728config\u91cc\u52a0\u4e00\u4e0b\u914d\u7f6e<\/a>\u3002\u8fd9\u91cc\u6211\u5e76\u4e0d\u660e\u767d80\u7aef\u53e3\u548c443\u7aef\u53e3\u4e00\u4e2a\u7ed9http\u4e00\u4e2a\u7ed9https\u8fd9\u4e2a\u662f\u4e0d\u662f\u7ea6\u5b9a\u4fd7\u6210\u53ef\u4ee5\u968f\u4fbf\u6539\u7684\u3002\uff08\u4f60\u4e3a\u4ec0\u4e48\u4e0d\u53bb\u8bd5\u4e00\u8bd5\u3002\uff09<\/p>\n\n\n\n<p>\u5728\u7814\u7a76\u8fd9\u4e2a\u95ee\u9898\u7684\u65f6\u5019\u770b\u5230\u4e86\u4e00\u4e2a\u535a\u5ba2\u6211\u89c9\u5f97\u5199\u5f97\u5f88\u597d\u3002<a href=\"https:\/\/robertheaton.com\/2014\/03\/27\/how-does-https-actually-work\/\">How does HTTPS actually work<\/a> \u548c <a href=\"https:\/\/robertheaton.com\/2018\/11\/28\/https-in-the-real-world\/\">HTTPS in the real world<\/a> \u8fd9\u4e24\u7bc7\u6587\u7ae0\u5199\u5f97\u5f88\u597d\uff08\u4e2a\u4eba\u535a\u5ba2\u6bd4\u7ef4\u57fa\u597d\u770b\u591a\u4e86\uff09\u3002\u6211\u7279\u522b\u559c\u6b22\u4ed6\u8bf4\uff0cIn cryptography, trust is mathematically provable. Everything else is just faith. \u7136\u540e\u770b\u4e86\u4ed6\u63cf\u8ff0\u7684revoke key\u7684\u95ee\u9898\u6211\u610f\u8bc6\u5230\uff0crevoke\u8fd9\u4ef6\u4e8b\u6ca1\u6709\u4e00\u4e2amathematical solution\uff0c\u6240\u4ee5\u6bd4\u8f83\u9ebb\u70e6\u3002\uff08\u8fd9\u4e2a\u95ee\u9898\u662f\uff0cCA\u7ed9\u4e86\u4f60\u8bc1\u4e66\uff0c\u7136\u540e\uff0c\u4f60\u7684private key\u88ab\u4eba\u76d7\u53d6\u4e86\u3002CA\u8bc1\u4e66\u548cpublic key\u662f\u4e00\u8d77\u53d1\u7ed9\u5ba2\u6237\u7aef\u7684\uff0c\u8c01\u90fd\u53ef\u4ee5\u622a\u53d6\u3002\u90a3\u4e48\u76d7\u53d6\u4f60private key\u7684\u4eba\u5c31\u53ef\u4ee5\u62ff\u7740\u8bc1\u4e66\u548cprivate key\u5192\u5145\u4f60\u4e86\uff0c\u5b9e\u9645\u4e0a\u5ba2\u6237\u4e0d\u8be5\u518d\u76f8\u4fe1\u8fd9\u5f20\u8bc1\u4e66\u3002\u7136\u800c\u56e0\u4e3a\u8bc1\u4e66\u53ef\u4ee5\u7528CA\u7684pub key\u89e3\u5bc6\u9a8c\u8bc1\u7684\uff0c\u8fd9\u5c31\u6ca1\u529e\u6cd5\u6536\u56de\u4e86\u3002\u73b0\u884csolution\u5728\u6587\u7ae0\u4e2d\u6709\uff0c\u5c31\u662f\u52a0\u5165\u4e86revocation list\u548c\u63d0\u4f9b\u8fd9\u4e2alist\u7684\u670d\u52a1\u5668\u3002\uff08\u771f\u7684\u6ca1\u6709\u66f4\u7b80\u5355\u7684\u529e\u6cd5\u4e86\u5417\uff1f\uff09<\/p>\n\n\n\n<p>\u53e6\u5916\u60f3\u8bf4\uff08\u6211\u4e5f\u77e5\u9053bash\u4e2d\u56fd\u793e\u4f1a\u6ca1\u610f\u4e49\uff0c\u4f46\u662f\u8fd8\u662f\u60f3\u8bf4\uff09\uff0c\u56e0\u4e3a\u6709\u65af\u8bfa\u767b\u548c\u522b\u7684\u4e00\u4e9b\u4eba\uff0c\u7136\u540e\u6709\u4e86\u80a1\u6c9f\u8fd9\u6837\u7684\u5927\u516c\u53f8\u53d1\u529b\uff0c\u6211\u4eec\u624d\u6709\u8fd9\u4e2a\u67b6\u6784\u7684\uff0c\u73b0\u5728\u662f\u76f8\u5bf9\u6709\u70b9\u5b89\u5168\u3002\u60f3\u60f3\u5982\u679c\u771f\u7684\u5b8c\u5168\u662f\u5c40\u57df\u7f51\uff0c\u5982\u679c\u6211\u4eec\u7684\u5b89\u5168\u5168\u90fd\u4ea4\u7ed9\u56fd\u5185\u7684\u5439\u54e8\u4eba\uff08\u4e0d\u5b58\u5728\u6216\u8005\u53d1\u58f0\u540e\u88ab\u6574\u6cbb\uff0c\u89c1\u5199\u79d1\u666e\u6587\u8bf4\u836f\u9152\u6ca1\u6709\u6cbb\u75c5\u529f\u80fd\u7684\u4eba\uff09\uff0c\u6216\u8005\u56fd\u5185\u7684\u5927\u4f01\u4e1a\uff08\u4ed6\u4eec\u4e0d\u5199\u6d41\u6c13\u8f6f\u4ef6\u5df2\u7ecf\u8c22\u5929\u8c22\u5730\u4e86\uff0c\u6211\u7ecf\u5e38\u505a\u7684\u4e8b\u60c5\u662f\u5e2e\u6211\u5988\u5378\u8f7d360\uff0c\u800c\u963f\u91cc\u817e\u8baf\u4ec0\u4e48\u7684\uff0c\u5982\u679c\u4e0d\u662f\u6709\u56fd\u5916\u6295\u8d44\uff0c\u4ed6\u4eec\u51fa\u5356\u4fe1\u606f\u80af\u5b9a\u662f\u660e\u7740\u6765\u7684\u4e86\uff09\uff0c\u54e6\uff0c\u60f3\u60f3\u5c31\u6015\u3002\u554a\uff0c\u5e0c\u671b\u8d38\u6613\u6218\u4e0d\u8981\u7ee7\u7eed\u4e86\uff0c\u5546\u4e1a\u5de8\u5934\u4e11\u6076\uff0c\u4f46\u81f3\u5c11\u8fd8\u662f\u6211\u4eec\u548cliberal\u4e16\u754c\u7684\u6700\u540e\u4e00\u5c42\u8054\u7cfb\u3002\u3002\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5384\uff0c\u65af\u8bfa\u767b\u4f20\u8bb0\u7684\u7b14\u8bb0\u8fd8\u662f\u6ca1\u6709\u5199\u597d\u3002\u5148\u518d\u5199\u4e00\u7bc7HTTPS\u7684\u89e3\u91ca\uff0c\u56e0\u4e3a\u6211\u60f3\u5b9e\u884c\u4e00\u4e0b\u8d39\u66fc\u5b66\u4e60\u6cd5\uff1alearn by explaining! \u5173\u4e8e\u52a0\u5bc6 \u52a0\u5bc6\u8fd9\u4ef6\u4e8b\uff0c\u5176\u4e2d\u7b97\u6cd5\u7684\u6570\u5b66\u6211\u4e0d\u4e86\u89e3\u3002\u6211\u5c31\u5148\u7406\u89e3\u4e3a\u4e00\u4e2a\u628a\u6570\u636e\u6253\u6210\u4e71\u7801\u7684\u89c4\u5219\u3002\u9700\u8981\u4e00\u4e2akey\u6765\u52a0\u5bc6\uff0c\u4e00\u4e2akey\u6765\u89e3\u5bc6\uff08\u628a\u52a0\u5bc6\u6570\u636e\u8fd8\u539f\u6210\u539f\u59cb\u4fe1\u606f\uff09\u3002\u52a0\u5bc6\u548c\u89e3\u5bc6\u7684key\u662f\u540c\u4e00\u4e2a\u7684\u8bdd\uff0c\u5c31\u662f\u5bf9\u79f0\u52a0\u5bc6\u3002\u53e6\u5916\u8fd8\u6709\u4e00\u79cd\u975e\u5bf9\u79f0\u52a0\u5bc6\uff0cpublic key\u548cprivate key\u6210\u5bf9\uff0c\u7528\u5176\u4e2d\u4e4b\u4e00\u52a0\u5bc6\u7684\u53ef\u4ee5\u7528\u53e6\u4e00\u4e2a\u89e3\u5bc6\u3002\u800cpublic key\u662f\u516c\u5f00\u7684\uff0cprivate key\u5fc5\u987b\u4fdd\u5bc6\u3002 \u8111\u4e2d\u60f3\u8c61\u975e\u5e38\u7b80\u5355\u7684\u5bf9\u79f0\u52a0\u5bc6\uff1a\u6211\u9001\u7ed9\u4f60\u7684\u6570\u5b57\u90fd\u662f*113\u7684\uff1b\u90a3\u4e48\u4f60\u63a5\u5230\u6570\u5b57\u540e\u5c31\/113\u6765\u89e3\u5bc6\u3002 \u975e\u5bf9\u79f0\u52a0\u5bc6\u96be\u4ee5\u7834\u89e3\u662f\u57fa\u4e8e\u8fd9\u4e2a\u4e8b\u5b9e\uff1a\u53ea\u77e5\u9053\u4e24\u4e2a\u5927\u8d28\u6570\u76f8\u4e58\u7684\u79ef\u8981\u62c6\u5206\u51fa\u4e24\u4e2a\u8d28\u6570\u672c\u8eab\uff0c\u5bf9\u8ba1\u7b97\u673a\u6765\u8bf4\u4e5f\u5f88\u96be\u3002\u7136\u800c\u751f\u6210key\u5f88\u5bb9\u6613\u3002\u5177\u4f53\u662f\u600e\u4e48\u52a0\u5bc6\u7684\u6211\u8fd8\u6ca1\u5b66\u4f1a\u3002 \u975e\u5bf9\u79f0\u52a0\u5bc6\u7684\u901f\u5ea6\u6bd4\u5bf9\u79f0\u52a0\u5bc6\u6162\u3002 \u5173\u4e8eHTTPS HTTPS\u8981\u89e3\u51b3\u7684\u7f51\u7edc\u5b89\u5168\u95ee\u9898\u6709\u4e24\u4e2a\uff0c\u7b2c\u4e00\u4e2a\u662f\u52a0\u5bc6\u539f\u6765\u7684HTTP\u4fe1\u606f\uff0c\u8fd9\u6837\u522b\u4eba\u622a\u83b7\u4e86\u8fd9\u4e2a\u4fe1\u606f\u5bf9\u4ed6\u4eec\u6765\u8bf4\u4e5f\u65e0\u6cd5\u4f7f\u7528\u3002\u622a\u83b7\u4fe1\u606f\u5f88\u5bb9\u6613\u3002\u636e\u8bf4\u5728\u516c\u7528\u65e0\u7ebf\u7f51\u7edc\u4e0a\uff0c\u540c\u4e00\u4e2a\u7f51\u7edc\u7684\u4eba\u53ef\u4ee5\u7a83\u53d6\u4f60\u7684\u6240\u6709\u8bf7\u6c42\u3002\u53e6\u5916\u6211\u53ef\u4ee5\u60f3\u8c61\uff0c\u653f\u5e9c\u57fa\u5efa\u505a\u597d\u7684\u4e2d\u7ee7\u8def\u7531\uff0c\u5b8c\u5168\u53ef\u4ee5\u5728\u4e0a\u9762\u90e8\u7f72\u7a0b\u5e8f\u628a\u6240\u6709\u8def\u8fc7\u7684\u4fe1\u606f\u90fd\u5907\u4efd\u4e00\u4e0b\u3002\uff08\u6211\u4e0d\u77e5\u9053\u65af\u8bfa\u767b\u53d1\u73b0\u7684\u662f\u4e0d\u662fNSA\u5728\u8fd9\u4e48\u505a\u3002\u3002\uff09 \u53e6\u4e00\u4e2a\u8981\u89e3\u51b3\u7684\u95ee\u9898\u662f\u7f51\u7ad9\u8eab\u4efd\u8ba4\u8bc1\u3002\u5982\u679c\u4f60\u5047\u88c5\u662f\u4e9a\u9a6c\u900a\uff0c\u7136\u540e\u7528\u6237\u5c31\u628a\u4fe1\u7528\u5361\u4fe1\u606f\u586b\u597d\u53d1\u7ed9\u4f60\u4e86\uff0c\u90a3\u4e48\u7528\u6237\u5c31\u5b8c\u86cb\u4e86\u3002\u5728\u6211\u81ea\u5df1\u641eHTTPS\u7684\u65f6\u5019\u6211\u672c\u6765\u4e0d\u7406\u89e3\u4e3a\u4ec0\u4e48\u8981\u628a\u8eab\u4efd\u8ba4\u8bc1\u548c\u52a0\u5bc6\u6253\u5305\u5728\u4e00\u8d77\uff0c\u56e0\u4e3a\u6211\u672c\u6765\u53ea\u6709\u52a0\u5bc6\u7684\u9700\u6c42\u3002\u6211\u8fd8\u662f\u89c9\u5f97\u53ef\u4ee5\u628a\u52a0\u5bc6\u548c\u8eab\u4efd\u8ba4\u8bc1\u5206\u5f00\u3002\u5f53\u6d4f\u89c8\u5668\u8bbf\u95ee\u4e00\u4e2a\u7f51\u7ad9\u7684\u65f6\u5019\uff0c\u63d0\u9192\u5ba2\u6237\u8fd9\u4e2a\u7f51\u7ad9\u53ea\u6709\u52a0\u5bc6\u6ca1\u6709\u8eab\u4efd\u8ba4\u8bc1\u5c31\u53ef\u4ee5\u4e86\u3002\u73b0\u5728\u662f\uff0c\u53ea\u6709http\u7684\u8bdd\u6d4f\u89c8\u5668\u4f1a\u8ba9\u4f60\u8bbf\u95ee\uff0c\u4f46\u662f\u6709self sign\uff08\u81ea\u5df1\u751f\u6210key\uff0c\u53ea\u6709\u52a0\u5bc6\u6ca1\u6709\u8ba4\u8bc1\uff09\u7684\u8bdd\uff0c\u6d4f\u89c8\u5668\u4f1a\u4e0d\u8ba9\u4f60\u8bbf\u95ee\u3002\u6211\u89c9\u5f97\u8fd9\u4e2a\u662f\u4e0d\u662f\u4e0d\u592a\u5408\u7406\uff1f\uff08\u4e00\u5b9a\u662f\u6211\u8fd8\u6ca1\u5b8c\u5168\u7406\u89e3\u5427\u3002\u3002\uff09\u5982\u679c\u6211\u6ca1\u6709\u8eab\u4efd\u8ba4\u8bc1\uff0c\u7136\u540e\u6211\u5728\u5192\u5145\u4e9a\u9a6c\u900a\u60f3\u8981\u5957\u53d6\u5ba2\u6237\u7684\u4fe1\u7528\u5361\u4fe1\u606f\uff0c\u90a3\u4e48\u5ba2\u6237\u53ef\u4ee5\u63d0\u9ad8\u8b66\u89c9\uff1b\u4f46\u662f\u6211\u662f\u4e00\u4e2a\u4e2a\u4eba\u535a\u5ba2\uff0c\u6ca1\u6709\u5411\u5ba2\u6237\u7d22\u53d6\u4fe1\u606f\uff0c\u90a3\u4e48\u6211\u5b8c\u5168\u53ef\u4ee5\u4e0d\u5b8c\u6210\u8eab\u4efd\u8ba4\u8bc1\uff0c\u5ba2\u6237\u53ef\u4ee5\u968f\u4fbf\u6765\u770b\u770b\uff0c\u5e76\u4e14\u77e5\u9053\u6211\u4eec\u4ea4\u4e92\u7684\u5185\u5bb9\u4e0d\u4f1a\u88abISP\u622a\u53d6\uff1f \u6211\u90a3\u5929\u5148\u662f\u8bd5\u56fe\u4f7f\u7528\u81ea\u5df1\u751f\u6210\u7684key\uff0c\u7ed3\u679c\u65e0\u6cd5\u8bbf\u95ee\uff0c\u8d70\u4e86\u5f88\u4e45\u7684\u5f2f\u8def\uff0c\u624d\u77e5\u9053\u73b0\u5728\u6d4f\u89c8\u5668\u90fd\u8981\u52a0\u5bc6\u548c\u8eab\u4efd\u8ba4\u8bc1\u6253\u5305\u4e00\u8d77\u5b8c\u6210\u7684\u3002\u4e5f\u8bb8\u662f\u4e3a\u4e86\u8ba9\u5ba2\u6237\u8ba4\u51c6https\u6807\u5fd7\u5c31\u597d\u4e86\u3002\u73b0\u5728\u597d\u50cf\u662f\u5149\u662f\u6559\u80b2\u5ba2\u6237\u7528https\u5c31\u633a\u8d39\u529b\u7684\u3002 \u52a0\u5bc6\u5185\u5bb9 \u52a0\u5bc6HTTP\u5185\u5bb9\u662f\u8fd9\u6837\u8fdb\u884c\u7684\uff1aclient\u7aef\uff08\u6d4f\u89c8\u5668\uff09\u5148\u83b7\u53d6server\u7684public key\uff0c\u7136\u540e\u81ea\u5df1\u751f\u6210\u4e00\u4e2akey\u7528server\u7684public key\u52a0\u5bc6\u9001\u7ed9server\u3002\u63a5\u4e0b\u6765\u53cc\u65b9\u7684\u5bf9\u8bdd\u5c31\u7528\u521a\u624d\u9001\u8fc7\u53bb\u7684key\u5bf9\u79f0\u52a0\u5bc6\u5bf9\u8bdd\u4e86\u3002\u8fd9\u6837\u505a\u7684\u539f\u56e0\u662f\u975e\u5bf9\u79f0\u52a0\u5bc6performance\u5dee\uff0c\u6240\u4ee5\u4ec5\u7528\u5b83\u6765\u4ea4\u6362\u63a5\u4e0b\u6765\u8981\u7528\u6765\u5bf9\u79f0\u52a0\u5bc6\u7684key\u3002 \u7b2c\u4e09\u65b9\u8eab\u4efd\u8ba4\u8bc1 \u5982\u679c\u6ca1\u6709\u8eab\u4efd\u8ba4\u8bc1\uff0c\u90a3\u4e48\u6211\u53ef\u4ee5\u5192\u5145\u4e9a\u9a6c\u900a\u548c\u5ba2\u6237\u5bf9\u8bdd\u3002\u6211\u4eec\u4ecd\u7136\u662f\u7528\u52a0\u5bc6\u6765\u5bf9\u8bdd\uff0c\u53ea\u4e0d\u8fc7\u5ba2\u6237\u7528\u7684\u662f\u6211\u7684key\uff0c\u4ee5\u4e3a\u662f\u4e9a\u9a6c\u900a\u7684key\uff0c\u7136\u540e\u6211\u5c31\u83b7\u5f97\u5ba2\u6237\u7684\u4fe1\u7528\u5361\u4fe1\u606f\u4e86\u3002\u89e3\u51b3\u8fd9\u4e2a\u95ee\u9898\u7684\u529e\u6cd5\u548c\u7ebf\u4e0b\u4e00\u6837\uff0c\u7b2c\u4e09\u65b9\u62c5\u4fddserver\u7684\u8eab\u4efd\u3002 \u5177\u4f53\u7684\u505a\u6cd5\u662f\uff1a\u5168\u7403\u6709\u51e0\u5bb6\u9876\u7ea7\u62c5\u4fdd\u673a\u6784CA (Certification Authority)\uff08\u5927\u90e8\u5206\u662f\u6536\u8d39\u7684\uff1bLet&#8217;s Encrypt\u662f\u4e00\u5bb6\u975e\u8425\u5229\u673a\u6784\uff0c\u4ed6\u4eec\u7684\u62c5\u4fdd\u670d\u52a1\u662f\u514d\u8d39\u7684\uff09\uff0cCA\u8ba4\u8bc1\u8fc7\u7f51\u7ad9\u7684\u8eab\u4efd\u540e\uff0c\u5c31\u5f00\u5177\u4e00\u5f20\u8bc1\u660e\uff0c\u8bc1\u660e\u5185\u5bb9\u7528CA\u7684private key\u52a0\u5bc6\uff0c\u800c\u4e16\u754c\u4e0a\u4efb\u4f55\u4eba\u90fd\u53ef\u4ee5\u7528CA\u7684public key\u89e3\u5bc6\u3002\u56e0\u4e3aCA\u7684private key\u53ea\u6709CA\u6709\uff0c\u6240\u4ee5\u80fd\u89e3\u5bc6\u5c31\u8bf4\u660e\u8fd9\u662fCA\u5f00\u5177\u7684\u5408\u6cd5\u8bc1\u660e\uff0c\u5c31\u53ef\u4ee5\u76f8\u4fe1\u6301\u6709\u8fd9\u4e2a\u8bc1\u4e66\u7684\u7f51\u7ad9\u4e86\u3002 \u4e5f\u5c31\u662f\u8bf4\uff0c\u5982\u679c\u60f3\u8981\u7ed9\u4e00\u4e2a\u4eba\u53d1\u9001\u7edd\u5bc6\u4fe1\u606f\uff0c\u53ef\u4ee5\u7528ta\u7684public key\u52a0\u5bc6\uff0c\u56e0\u4e3a\u53ea\u6709ta\u53ef\u4ee5\u89e3\u5bc6\uff1b\u5982\u679c\u60f3\u8981\u5168\u4e16\u754c\u77e5\u9053\u4e00\u4e2a\u4fe1\u606f\u662f\u6211\u8bf4\u7684\uff0c\u53ef\u4ee5\u7528\u6211\u7684private key\u52a0\u5bc6\uff0c\u628a\u4fe1\u606f\u548cpublic key\u516c\u5f00\uff0c\u56e0\u4e3a\u53ea\u6709\u6211\u6301\u6709\u6211\u7684private key\uff0c\u90a3\u4e48\u5168\u4e16\u754c\u90fd\u53ef\u4ee5\u77e5\u9053\u90a3\u4e2a\u4fe1\u606f\u53ea\u6709\u6211\u53ef\u4ee5\u5199\u3002\u6240\u4ee5private key\u662f\u4e00\u4e2a\u7edd\u597d\u7684\u7b7e\u540d\u3002 \u90a3\u4e48CA\u662f\u600e\u4e48\u62c5\u4fdd\u7684\u5462\uff1f\u4ed8\u8d39\u7684CA\u6211\u4e0d\u592a\u6e05\u695a\u4e86\uff0c\u4ed6\u4eec\u53ef\u80fd\u6709\u66f4\u4e25\u683c\u7684\u6d41\u7a0b\u548c\u5b9a\u671faudit\u4ec0\u4e48\u7684\u3002Let&#8217;s Encrypt\u636e\u8bf4\u662f\u8981\u5728server\u76ee\u5f55\u4e0b\u751f\u6210\u4ec0\u4e48\u6587\u4ef6\uff0c\u4ee5\u663e\u793a\u4f60\u5bf9server\u6709\u6743\u9650\u3002\u6211\u64cd\u4f5c\u7684\u65f6\u5019\u662f\u5728server\u4e0a\u6267\u884c\u4ed6\u4eec\u7684\u547d\u4ee4\uff0c\u4f30\u8ba1\u5305\u62ec\u5728\u91cc\u9762\u4e86\u3002\u6267\u884c\u7684\u65f6\u5019\u9700\u8981\u586b\u5199domain name\u3002\u6211\u53ef\u4ee5\u628aserver\u914d\u6210\u4e9a\u9a6c\u900a\uff0c\u4e0d\u77e5\u9053Let&#8217;s Encrypt\u4f1a\u4e0d\u4f1a\u8ba4\u8bc1\uff0c\u4f46\u5373\u4f7f\u8ba4\u8bc1\u4e86\uff0c\u6211\u7684\u5b9e\u9645\u57df\u540d\u5e76\u4e0d\u662f\u4e9a\u9a6c\u900a\uff0c\u6211\u60f3\u4e5f\u4e0d\u4f1a\u6709\u7528\u7684\u3002 Notes \u5f97\u5230\u4e86Let&#8217;s Encrypt\u7684key\u4e4b\u540e\uff0c\u8fd8\u8981\u7ed9server\u914d\u7f6e\u4e00\u4e0b\uff0c\u8fd9\u662fApache\u7684\u914d\u7f6e\u3002 WordPress\u8fd8\u9700\u8981\uff08\uff1f\uff09\u4e00\u4e2a\u63d2\u4ef6\u3002\u5176\u5b9e\u6211\u4e0d\u662f\u5f88\u660e\u767d\u5b83\u662f\u5e72\u561b\u7528\u7684\uff1aReally Simple SSL\u3002 \u7136\u540e\u8981\u505a\u4e00\u4ef6\u4e8b\u662f\u628ahttp\u7684\u8bf7\u6c42\u91cd\u5b9a\u5411\u5230https\u3002\u5728Apache\u4e0b\u5c31\u662f\u5728config\u91cc\u52a0\u4e00\u4e0b\u914d\u7f6e\u3002\u8fd9\u91cc\u6211\u5e76\u4e0d\u660e\u767d80\u7aef\u53e3\u548c443\u7aef\u53e3\u4e00\u4e2a\u7ed9http\u4e00\u4e2a\u7ed9https\u8fd9\u4e2a\u662f\u4e0d\u662f\u7ea6\u5b9a\u4fd7\u6210\u53ef\u4ee5\u968f\u4fbf\u6539\u7684\u3002\uff08\u4f60\u4e3a\u4ec0\u4e48\u4e0d\u53bb\u8bd5\u4e00\u8bd5\u3002\uff09 \u5728\u7814\u7a76\u8fd9\u4e2a\u95ee\u9898\u7684\u65f6\u5019\u770b\u5230\u4e86\u4e00\u4e2a\u535a\u5ba2\u6211\u89c9\u5f97\u5199\u5f97\u5f88\u597d\u3002How does HTTPS actually work \u548c HTTPS in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[262,6,7],"tags":[269],"class_list":["post-1943","post","type-post","status-publish","format-standard","hentry","category-262","category-6","category-7","tag-security"],"_links":{"self":[{"href":"https:\/\/blog.miahavero.me\/index.php?rest_route=\/wp\/v2\/posts\/1943","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.miahavero.me\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.miahavero.me\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.miahavero.me\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.miahavero.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1943"}],"version-history":[{"count":4,"href":"https:\/\/blog.miahavero.me\/index.php?rest_route=\/wp\/v2\/posts\/1943\/revisions"}],"predecessor-version":[{"id":1948,"href":"https:\/\/blog.miahavero.me\/index.php?rest_route=\/wp\/v2\/posts\/1943\/revisions\/1948"}],"wp:attachment":[{"href":"https:\/\/blog.miahavero.me\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1943"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.miahavero.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1943"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.miahavero.me\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1943"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}