必须在源码编译阶段启用--with-http_ssl_module模块,且需安装OpenSSL开发包、正确执行configure命令,并通过nginx -V验证内建;缺一不可。

要让 Nginx 支持 HTTPS,必须在源码编译阶段启用 http_ssl_module,这不是安装后能动态加载的功能。
确认系统已装 OpenSSL 开发包
SSL 模块依赖 OpenSSL 的头文件和库。缺失会导致 configure 报错(如 SSL module requires the OpenSSL library):
-
CentOS/RHEL:运行
yum install openssl-devel -
Ubuntu/Debian:运行
apt-get install libssl-dev
编译时显式添加 --with-http_ssl_module
该参数默认不启用,必须手动加入。同时建议保留原有模块,避免功能丢失:
- 进入 Nginx 源码目录(如
/home/soft/nginx) - 执行 configure 命令,例如:
./configure --prefix=/usr/local/nginx \<br> --with-http_ssl_module \<br> --with-http_stub_status_module \<br> --with-pcre \<br> --with-zlib - 运行
make(注意:不要执行make install,以免覆盖现有配置和二进制)
替换 nginx 二进制文件
编译完成后,新二进制位于 objs/nginx:
- 先停止服务:
/usr/local/nginx/sbin/nginx -s stop - 备份原文件:
cp /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.bak - 覆盖二进制:
cp ./objs/nginx /usr/local/nginx/sbin/ - 验证是否生效:
/usr/local/nginx/sbin/nginx -V 2>&1 | grep -i ssl,输出中应含--with-http_ssl_module
权限与路径注意事项
即使编译成功,后续配置仍可能失败。关键点包括:
- 证书和私钥建议放在明确路径,如
/etc/nginx/ssl/或/usr/local/nginx/conf/cert/ - 私钥文件必须设为
600权限:chmod 600 /path/to/your.key - 属主应为 Nginx 运行用户(CentOS 通常为
nginx,Ubuntu 为www-data):chown nginx:nginx /path/to/your.key - 检查私钥是否被密码加密:
head -n 1 your.key,若含DEK-Info:,需先用openssl rsa -in server.key -out server.key去密


















