## https * [1.httpsç访é®è¿ç¨](#1httpsç访é®è¿ç¨) * [详ç»è§£éï¼](#详ç»è§£é) * [2.httpsçä¼ç¼ºç¹ï¼](#2httpsçä¼ç¼ºç¹) * [1. ä¼ç¹](#1-ä¼ç¹) * [2ã缺ç¹](#2缺ç¹) * [3.httpså¦ä½è¿è¡æ§è½ä¼åï¼](#3httpså¦ä½è¿è¡æ§è½ä¼å) * [1.https访é®é度ä¼å](#1https访é®é度ä¼å) * [2.httpsè®¡ç®æ§è½ä¼å](#2httpsè®¡ç®æ§è½ä¼å) * [4.httpåhttps](#4httpåhttps) * [5.HTTPS为ä»ä¹æ¯å®å ¨çï¼](#5https为ä»ä¹æ¯å®å ¨ç) * [6.HTTPSç¸å¯¹äºHTTPç缺é·ï¼](#6httpsç¸å¯¹äºhttpç缺é·) * [7.为ä»ä¹éè¦è¯ä¹¦?](#7为ä»ä¹éè¦è¯ä¹¦) * [8.æä¹é²æ¢ç篡æ¹?](#8æä¹é²æ¢ç篡æ¹) ### 1.httpsç访é®è¿ç¨ 1.客æ·ä½¿ç¨httpsçURL访é®Webæå¡å¨ï¼è¦æ±ä¸Webæå¡å¨å»ºç«SSLè¿æ¥ã 2.Webæå¡å¨æ¶å°å®¢æ·ç«¯è¯·æ±åï¼ä¼å°ç½ç«çè¯ä¹¦ä¿¡æ¯ï¼è¯ä¹¦ä¸å å«å ¬é¥ï¼ä¼ éä¸ä»½ç»å®¢æ·ç«¯ã 3.客æ·ç«¯çæµè§å¨ä¸Webæå¡å¨å¼å§ååSSLè¿æ¥çå®å ¨ç级ï¼ä¹å°±æ¯ä¿¡æ¯å å¯çç级ã 4.客æ·ç«¯çæµè§å¨æ ¹æ®åæ¹åæçå®å ¨ç级ï¼å»ºç«ä¼è¯å¯é¥ï¼ç¶åå©ç¨ç½ç«çå ¬é¥å°ä¼è¯å¯é¥å å¯ï¼å¹¶ä¼ éç»ç½ç«ã 5.Webæå¡å¨å©ç¨èªå·±çç§é¥è§£å¯åºä¼è¯å¯é¥ã 6.Webæå¡å¨å©ç¨ä¼è¯å¯é¥å å¯ä¸å®¢æ·ç«¯ä¹é´çéä¿¡ã  #### 详ç»è§£éï¼ 1. 客æ·ç«¯åèµ·HTTPSè¯·æ± ç¨æ·å¨æµè§å¨éè¾å ¥ä¸ä¸ªhttpsç½åï¼ç¶åè¿æ¥å°serverç443端å£ã 2.æå¡ç«¯çé ç½® å°±æ¯æä¸è¿°æå°çæ°åè¯ä¹¦ï¼ 3.ä¼ éè¯ä¹¦ Webæå¡å¨æ¶å°å®¢æ·ç«¯è¯·æ±åï¼ä¼å°ç½ç«çè¯ä¹¦ä¿¡æ¯ï¼è¯ä¹¦ä¸å å«å ¬é¥ï¼ä¼ éä¸ä»½ç»å®¢æ·ç«¯ã 4.客æ·ç«¯è§£æè¯ä¹¦ 客æ·ç«¯ä¼å¯¹è¯ä¹¦è¿è¡å¤æï¼éªè¯å ¬é¥æ¯å¦ææï¼åå¨é®é¢å¼¹åºä¼è¦åï¼è¥æ²¡æé®é¢ï¼çæä¸ä¸ªéæºå¼ï¼ç§é¥ï¼ï¼ç¶åç¨è¯ä¹¦ç»§ç»è¿è¡å å¯ï¼ 5.ä¼ éå å¯ä¿¡æ¯ 客æ·ç«¯å°ä¸å å¯åçéæºå¼ï¼ç§é¥ï¼æä¾ç»æå¡ç«¯ï¼æå¡ç«¯ä¼å¯¹å ¶è¿è¡è§£å¯ï¼ 6.æå¡ç«¯è§£å¯ä¿¡æ¯ æå¡ç«¯è§£å¯åå¾å°éæºå¼ï¼ç§é¥ï¼ï¼ç¶åæå 容éè¿è¯¥å¼è¿è¡å¯¹ç§°å å¯ã对称å å¯å°±æ¯ææè¦è¿åçä¿¡æ¯åéæºå¼ï¼ç§é¥ï¼æ··åå å¯ï¼è¿æ ·é¤éç¥ééæºå¼ï¼ç§é¥ï¼ï¼ä¸ç¶æ æ³è·åæ°æ®ã 7.ä¼ è¾å å¯åçä¿¡æ¯ ç»§ç»å°å å¯åçä¿¡æ¯ä¼ éç»å®¢æ·ç«¯ï¼ 8.客æ·ç«¯è§£å¯ä¿¡æ¯ 客æ·ç«¯ç¨ä¹åçæçç§é¥ï¼éæºå¼ï¼è§£å¯æå¡ç«¯ä¼ è¿æ¥çä¿¡æ¯ï¼äºæ¯è·åäºè§£å¯åçå 容ã ### 2.httpsçä¼ç¼ºç¹ï¼ #### 1. ä¼ç¹ 1.æ£ç¡®åéæ°æ®å°å®¢æ·ç«¯ 使ç¨HTTPSåè®®å¯è®¤è¯ç¨æ·åæå¡å¨ï¼ç¡®ä¿æ°æ®åéå°æ£ç¡®çå®¢æ·æºåæå¡å¨ 2.æ´å®å ¨ HTTPSåè®®æ¯ç±SSL+HTTPåè®®æå»ºçå¯è¿è¡å å¯ä¼ è¾ã身份认è¯çç½ç»åè®®ï¼è¦æ¯httpåè®®å®å ¨ï¼å¯é²æ¢æ°æ®å¨ä¼ è¾è¿ç¨ä¸ä¸è¢«çªåãæ¹åï¼ç¡®ä¿æ°æ®ç宿´æ§ 3.å¢å ä¸é´äººæ»å»çææ¬ HTTPSæ¯ç°è¡æ¶æä¸æå®å ¨çè§£å³æ¹æ¡ï¼è½ç¶ä¸æ¯ç»å¯¹å®å ¨ï¼ä½å®å¤§å¹ å¢å äºä¸é´äººæ»å»çææ¬ã 4.æç´¢æåæ´é« è°·æå¨2014跳转æç´¢ç®æ³ï¼éç¨HTTPSå å¯çç½ç«å¨æç´¢ç»æä¸çæåå°ä¼æ´é« ç¾åº¦ä¹å¨2018å¹´åå¸ç¾åº¦å¯¹HTTPSç«ç¹çæ¶ææåº¦ï¼è¡¨æHTTPSå°ä½ä¸ºä¼è´¨ç¹å¾ä¹ä¸å½±åæç´¢æåºã #### 2ãç¼ºç¹ 1.页颿¸²ææ´èæ¶é´ å 为SSLçç¼æ ï¼HTTPSåè®®æ¡æé¶æ®µæ¯è¾è´¹æ¶ï¼ä¼ä½¿é¡µé¢çå è½½æ¶é´å»¶é¿è¿50%ï¼ 2.ææ¬å¢å SSLè¯ä¹¦éè¦è±é±ï¼åè½è¶å¼ºå¤§çè¯ä¹¦è´¹ç¨è¶é«ï¼ 3.HTTPSè¿æ¥ç¼åä¸å¦HTTP髿 HTTPSè¿æ¥ç¼åä¸å¦HTTP髿ï¼ä¼å¢å æ°æ®å¼éååèï¼çè³å·²æçå®å ¨æªæ½ä¹ä¼å æ¤èåå°å½±åï¼ 4.SSLè¯ä¹¦é常éè¦ç»å®IP SSLè¯ä¹¦é常éè¦ç»å®IPï¼ä¸è½å¨åä¸IPä¸ç»å®å¤ä¸ªååï¼IPv4èµæºä¸å¯è½æ¯æè¿ä¸ªæ¶èã 5.æå±éæ§ HTTPSåè®®çå å¯èå´ä¹æ¯è¾æéï¼å¨é»å®¢æ»å»ãæç»æå¡æ»å»ãæå¡å¨å«æçæ¹é¢å ä¹èµ·ä¸å°ä»ä¹ä½ç¨ãæå ³é®çï¼SSLè¯ä¹¦çä¿¡ç¨é¾ä½ç³»å¹¶ä¸å®å ¨ï¼ç¹å«æ¯å¨æäºå½å®¶å¯ä»¥æ§å¶CAæ ¹è¯ä¹¦çæ åµä¸ï¼ä¸é´äººæ»å»ä¸æ ·å¯è¡ã #### 3.httpså¦ä½è¿è¡æ§è½ä¼åï¼ ##### 1.https访é®é度ä¼å 1.设置HSTS æå¡ç«¯è¿åä¸ä¸ª HSTS ç http headerï¼æµè§å¨è·åå° HSTS 头é¨ä¹åï¼å¨ä¸æ®µæ¶é´å ï¼ä¸ç®¡ç¨æ·è¾å ¥www.baidu.comè¿æ¯http://www.baidu.comï¼é½ä¼é»è®¤å°è¯·æ±å é¨è·³è½¬æhttps://www.baidu.comã 2.Session resume Session Resume 顾åæä¹å°±æ¯å¤ç¨ Sessionï¼å®ç°ç®åæ¡æã ``` #### 1.httpsç访é®è¿ç¨ 1.客æ·ä½¿ç¨httpsçURL访é®Webæå¡å¨ï¼è¦æ±ä¸Webæå¡å¨å»ºç«SSLè¿æ¥ã 2.Webæå¡å¨æ¶å°å®¢æ·ç«¯è¯·æ±åï¼ä¼å°ç½ç«çè¯ä¹¦ä¿¡æ¯ï¼è¯ä¹¦ä¸å å«å ¬é¥ï¼ä¼ éä¸ä»½ç»å®¢æ·ç«¯ã 3.客æ·ç«¯çæµè§å¨ä¸Webæå¡å¨å¼å§ååSSLè¿æ¥çå®å ¨ç级ï¼ä¹å°±æ¯ä¿¡æ¯å å¯çç级ã 4.客æ·ç«¯çæµè§å¨æ ¹æ®åæ¹åæçå®å ¨ç级ï¼å»ºç«ä¼è¯å¯é¥ï¼ç¶åå©ç¨ç½ç«çå ¬é¥å°ä¼è¯å¯é¥å å¯ï¼å¹¶ä¼ éç»ç½ç«ã 5.Webæå¡å¨å©ç¨èªå·±çç§é¥è§£å¯åºä¼è¯å¯é¥ã 6.Webæå¡å¨å©ç¨ä¼è¯å¯é¥å å¯ä¸å®¢æ·ç«¯ä¹é´çéä¿¡ã  ##### 详ç»è§£éï¼ 1. 客æ·ç«¯åèµ·HTTPSè¯·æ± ç¨æ·å¨æµè§å¨éè¾å ¥ä¸ä¸ªhttpsç½åï¼ç¶åè¿æ¥å°serverç443端å£ã 2.æå¡ç«¯çé ç½® å°±æ¯æä¸è¿°æå°çæ°åè¯ä¹¦ï¼ 3.ä¼ éè¯ä¹¦ Webæå¡å¨æ¶å°å®¢æ·ç«¯è¯·æ±åï¼ä¼å°ç½ç«çè¯ä¹¦ä¿¡æ¯ï¼è¯ä¹¦ä¸å å«å ¬é¥ï¼ä¼ éä¸ä»½ç»å®¢æ·ç«¯ã 4.客æ·ç«¯è§£æè¯ä¹¦ 客æ·ç«¯ä¼å¯¹è¯ä¹¦è¿è¡å¤æï¼éªè¯å ¬é¥æ¯å¦ææï¼åå¨é®é¢å¼¹åºä¼è¦åï¼è¥æ²¡æé®é¢ï¼çæä¸ä¸ªéæºå¼ï¼ç§é¥ï¼ï¼ç¶åç¨è¯ä¹¦ç»§ç»è¿è¡å å¯ï¼ 5.ä¼ éå å¯ä¿¡æ¯ 客æ·ç«¯å°ä¸å å¯åçéæºå¼ï¼ç§é¥ï¼æä¾ç»æå¡ç«¯ï¼æå¡ç«¯ä¼å¯¹å ¶è¿è¡è§£å¯ï¼ 6.æå¡ç«¯è§£å¯ä¿¡æ¯ æå¡ç«¯è§£å¯åå¾å°éæºå¼ï¼ç§é¥ï¼ï¼ç¶åæå 容éè¿è¯¥å¼è¿è¡å¯¹ç§°å å¯ã对称å å¯å°±æ¯ææè¦è¿åçä¿¡æ¯åéæºå¼ï¼ç§é¥ï¼æ··åå å¯ï¼è¿æ ·é¤éç¥ééæºå¼ï¼ç§é¥ï¼ï¼ä¸ç¶æ æ³è·åæ°æ®ã 7.ä¼ è¾å å¯åçä¿¡æ¯ ç»§ç»å°å å¯åçä¿¡æ¯ä¼ éç»å®¢æ·ç«¯ï¼ 8.客æ·ç«¯è§£å¯ä¿¡æ¯ 客æ·ç«¯ç¨ä¹åçæçç§é¥ï¼éæºå¼ï¼è§£å¯æå¡ç«¯ä¼ è¿æ¥çä¿¡æ¯ï¼äºæ¯è·åäºè§£å¯åçå 容ã ### 2.httpsçä¼ç¼ºç¹ï¼ #### 1. ä¼ç¹ 1.æ£ç¡®åéæ°æ®å°å®¢æ·ç«¯ 使ç¨HTTPSåè®®å¯è®¤è¯ç¨æ·åæå¡å¨ï¼ç¡®ä¿æ°æ®åéå°æ£ç¡®çå®¢æ·æºåæå¡å¨ 2.æ´å®å ¨ HTTPSåè®®æ¯ç±SSL+HTTPåè®®æå»ºçå¯è¿è¡å å¯ä¼ è¾ã身份认è¯çç½ç»åè®®ï¼è¦æ¯httpåè®®å®å ¨ï¼å¯é²æ¢æ°æ®å¨ä¼ è¾è¿ç¨ä¸ä¸è¢«çªåãæ¹åï¼ç¡®ä¿æ°æ®ç宿´æ§ 3.å¢å ä¸é´äººæ»å»çææ¬ HTTPSæ¯ç°è¡æ¶æä¸æå®å ¨çè§£å³æ¹æ¡ï¼è½ç¶ä¸æ¯ç»å¯¹å®å ¨ï¼ä½å®å¤§å¹ å¢å äºä¸é´äººæ»å»çææ¬ã 4.æç´¢æåæ´é« è°·æå¨2014跳转æç´¢ç®æ³ï¼éç¨HTTPSå å¯çç½ç«å¨æç´¢ç»æä¸çæåå°ä¼æ´é« ç¾åº¦ä¹å¨2018å¹´åå¸ç¾åº¦å¯¹HTTPSç«ç¹çæ¶ææåº¦ï¼è¡¨æHTTPSå°ä½ä¸ºä¼è´¨ç¹å¾ä¹ä¸å½±åæç´¢æåºã #### 2ãç¼ºç¹ 1.页颿¸²ææ´èæ¶é´ å 为SSLçç¼æ ï¼HTTPSåè®®æ¡æé¶æ®µæ¯è¾è´¹æ¶ï¼ä¼ä½¿é¡µé¢çå è½½æ¶é´å»¶é¿è¿50%ï¼ 2.ææ¬å¢å SSLè¯ä¹¦éè¦è±é±ï¼åè½è¶å¼ºå¤§çè¯ä¹¦è´¹ç¨è¶é«ï¼ 3.HTTPSè¿æ¥ç¼åä¸å¦HTTP髿 HTTPSè¿æ¥ç¼åä¸å¦HTTP髿ï¼ä¼å¢å æ°æ®å¼éååèï¼çè³å·²æçå®å ¨æªæ½ä¹ä¼å æ¤èåå°å½±åï¼ 4.SSLè¯ä¹¦é常éè¦ç»å®IP SSLè¯ä¹¦é常éè¦ç»å®IPï¼ä¸è½å¨åä¸IPä¸ç»å®å¤ä¸ªååï¼IPv4èµæºä¸å¯è½æ¯æè¿ä¸ªæ¶èã 5.æå±éæ§ HTTPSåè®®çå å¯èå´ä¹æ¯è¾æéï¼å¨é»å®¢æ»å»ãæç»æå¡æ»å»ãæå¡å¨å«æçæ¹é¢å ä¹èµ·ä¸å°ä»ä¹ä½ç¨ãæå ³é®çï¼SSLè¯ä¹¦çä¿¡ç¨é¾ä½ç³»å¹¶ä¸å®å ¨ï¼ç¹å«æ¯å¨æäºå½å®¶å¯ä»¥æ§å¶CAæ ¹è¯ä¹¦çæ åµä¸ï¼ä¸é´äººæ»å»ä¸æ ·å¯è¡ã #### 3.httpså¦ä½è¿è¡æ§è½ä¼åï¼ ##### 1.https访é®é度ä¼å 1.设置HSTS æå¡ç«¯è¿åä¸ä¸ª HSTS ç http headerï¼æµè§å¨è·åå° HSTS 头é¨ä¹åï¼å¨ä¸æ®µæ¶é´å ï¼ä¸ç®¡ç¨æ·è¾å ¥www.baidu.comè¿æ¯http://www.baidu.comï¼é½ä¼é»è®¤å°è¯·æ±å é¨è·³è½¬æhttps://www.baidu.comã 2.Session resume Session Resume 顾åæä¹å°±æ¯å¤ç¨ Sessionï¼å®ç°ç®åæ¡æã â``` 1. åå°äº CPU æ¶èï¼å 为ä¸éè¦è¿è¡é对称å¯é¥äº¤æ¢ç计ç®ã 2. æå访é®é度ï¼ä¸éè¦è¿è¡å®å ¨æ¡æé¶æ®µäºï¼èçäºä¸ä¸ª RTT å计ç®èæ¶ã â``` 3.Nginx设置Ocsp stapling OSCP Stapling å·¥ä½åçç®åæ¥è¯´å°±æ¯æµè§å¨åèµ· Client Hello æ¶ä¼æºå¸¦ä¸ä¸ª certificate status request çæ©å±ï¼æå¡ç«¯çå°è¿ä¸ªæ©å±åå° OCSP å å®¹ç´æ¥è¿åç»æµè§å¨ï¼å®æè¯ä¹¦ç¶ææ£æ¥ãç±äºæµè§å¨ä¸éè¦ç´æ¥å CA ç«ç¹æ¥è¯¢è¯ä¹¦ç¶æï¼è¿ä¸ªåè½å¯¹è®¿é®é度çæåéå¸¸ææ¾ã 4.ä½¿ç¨ SPDY æè HTTP2 SPDY æå¤§çç¹æ§å°±æ¯å¤è·¯å¤ç¨ï¼è½å°å¤ä¸ª HTTP 请æ±å¨åä¸ä¸ªè¿æ¥ä¸ä¸èµ·ååºå»ï¼ä¸åç®åç HTTP åè®®ä¸æ ·ï¼åªè½ä¸²è¡å°é个åé请æ±ã HTTP2æ¯æå¤è·¯å¤ç¨ï¼æåæ ·çææã â``` 1. SPDY å HTTP2 ç®åçå®ç°é»è®¤ä½¿ç¨ HTTPS åè®®ã 2. SPDY å HTTP2 齿¯æç°æç HTTP è¯ä¹å APIï¼å¯¹ WEB åºç¨å 乿¯éæçã â``` 5.False start ç®åæ¦æ¬ False Start çåçå°±æ¯å¨ client_key_exchange ååºæ¶å°åºç¨å±æ°æ®ä¸èµ·ååºæ¥ï¼è½å¤èçä¸ä¸ª RTTã ##### 2.httpsè®¡ç®æ§è½ä¼å 1. ä¼å ä½¿ç¨ ECCæ¤åå å¯ç®æ¯ã ECC æ¤åå å¯ç®æ¯ç¸æ¯æ®éç离æ£å¯¹æ°è®¡ç®é度æ§è½è¦å¼ºå¾å¤ã  2.ä½¿ç¨ææ°çç opensslã ä¸è¬æ¥è®²ï¼æ°çç OpenSSL ç¸æ¯èçç计ç®é度åå®å ¨æ§é½ä¼ææåã 3.硬件å éæ¹æ¡ã - SSL ä¸ç¨å éå¡ã - GPUSSL å éã 4.TLS è¿ç¨ä»£çè®¡ç® #### 4.httpåhttps HTTPï¼(HyperText Transfer Protocol)è¶ ææ¬ä¼ è¾åè®® HTTPSï¼(Hypertext Transfer Protocol Secure)è¶ ææ¬ä¼ è¾å®å ¨åè®® HTTPåHTTPSåè®®ç主è¦åºå«å¦ä¸ï¼ HTTPSåè®®éè¦CAè¯ä¹¦ï¼è´¹ç¨è¾é«ï¼HTTPåè®®ä¸éè¦ HTTPåè®®æ¯è¶ ææ¬ä¼ è¾åè®®ï¼ä¿¡æ¯æ¯ææä¼ è¾çï¼HTTPSåæ¯å ·æå®å ¨æ§çSSLå å¯ä¼ è¾åè®® 使ç¨ä¸åçè¿æ¥æ¹å¼ï¼ç«¯å£ä¹ä¸åï¼HTTPåè®®ç«¯å£æ¯80ï¼HTTPSçåè®®ç«¯å£æ¯443 HTTPåè®®è¿æ¥å¾ç®åï¼æ¯æ ç¶æçï¼HTTPSåè®®æ¯æSSLåHTTPåè®®æå»ºçå¯è¿è¡å å¯ä¼ è¾ã身份认è¯çç½ç»åè®®ï¼æ¯HTTPæ´å å®å ¨ #### 5.HTTPS为ä»ä¹æ¯å®å ¨çï¼ HTTPSç¸å¯¹äºHTTPåè®®ï¼å å ¥äºTLS/SSLï¼å®çå ¨ç§°ä¸ºå®å ¨ä¼ è¾å±åè®®ï¼æ¯ä»äºTCPåHTTPä¹é´çä¸å±å®å ¨åè®®ã TLS/SSLçåè½å®ç°ä¸»è¦ä¾èµä¸ç±»åºæ¬ç®æ³ï¼æ£å彿°hashã对称å å¯ãé对称å å¯ãè¿ä¸ç±»ç®æ³çä½ç¨å¦ä¸ï¼ åºäºæ£å彿°éªè¯ä¿¡æ¯ç宿´æ§ 对称å å¯ç®æ³éç¨ååçç§é¥å¯¹æ°æ®å å¯ é对称å å¯å®ç°èº«ä»½è®¤è¯åç§é¥åå  #### 6.HTTPSç¸å¯¹äºHTTPç缺é·ï¼ - HTTPSéè¦åæå¡å¨å客æ·ç«¯åæ¹çå å¯ä¸ªè§£å¯å¤çï¼èè´¹æ´å¤æå¡å¨èµæºï¼è¿ç¨å¤æ - HTTPSåè®®æ¡æé¶æ®µæ¯è¾è´¹æ¶ï¼å¢å 页é¢çå è½½æ¶é´ - SSLè¯ä¹¦æ¯æ¶è´¹çï¼åè½è¶å¼ºå¤§çè¯ä¹¦è´¹ç¨è¶é« - HTTPSè¿æ¥æå¡å¨ç«¯èµæºå ç¨é«å¾å¤ï¼æ¯æè®¿å®¢ç¨å¤çç½ç«éè¦æå ¥æ´å¤§çææ¬ #### 7.为ä»ä¹éè¦è¯ä¹¦? 鲿¢ä¸é´äººæ»å»,éªè¯æå¡å¨èº«ä»½ #### 8.æä¹é²æ¢ç篡æ¹? è¯ä¹¦æ¯å ¬å¼ç,è½ç¶ä¸é´äººå¯ä»¥æ¿å°è¯ä¹¦,ä½ç§é¥æ æ³è·å,å ¬é¥æ æ³æ¨æåºç§é¥,æä»¥ç¯¡æ¹åä¸è½ç¨ç§é¥å å¯,强è¡å å¯å®¢æ·ä¹æ æ³è§£å¯,强è¡ä¿®æ¹å 容,ä¼å¯¼è´è¯ä¹¦å 容ä¸ç¾åä¸çæçº¹ä¸å¹é #### åè龿¥ https://blog.csdn.net/qq_42033567/article/details/107902340 https://www.cnblogs.com/Duikerdd/p/12030955.html ``` 3.Nginx设置Ocsp stapling OSCP Stapling å·¥ä½åçç®åæ¥è¯´å°±æ¯æµè§å¨åèµ· Client Hello æ¶ä¼æºå¸¦ä¸ä¸ª certificate status request çæ©å±ï¼æå¡ç«¯çå°è¿ä¸ªæ©å±åå° OCSP å å®¹ç´æ¥è¿åç»æµè§å¨ï¼å®æè¯ä¹¦ç¶ææ£æ¥ãç±äºæµè§å¨ä¸éè¦ç´æ¥å CA ç«ç¹æ¥è¯¢è¯ä¹¦ç¶æï¼è¿ä¸ªåè½å¯¹è®¿é®é度çæåéå¸¸ææ¾ã 4.ä½¿ç¨ SPDY æè HTTP2 SPDY æå¤§çç¹æ§å°±æ¯å¤è·¯å¤ç¨ï¼è½å°å¤ä¸ª HTTP 请æ±å¨åä¸ä¸ªè¿æ¥ä¸ä¸èµ·ååºå»ï¼ä¸åç®åç HTTP åè®®ä¸æ ·ï¼åªè½ä¸²è¡å°é个åé请æ±ã HTTP2æ¯æå¤è·¯å¤ç¨ï¼æåæ ·çææã ``` 1. SPDY å HTTP2 ç®åçå®ç°é»è®¤ä½¿ç¨ HTTPS åè®®ã 2. SPDY å HTTP2 齿¯æç°æç HTTP è¯ä¹å APIï¼å¯¹ WEB åºç¨å 乿¯éæçã ``` 5.False start ç®åæ¦æ¬ False Start çåçå°±æ¯å¨ client_key_exchange ååºæ¶å°åºç¨å±æ°æ®ä¸èµ·ååºæ¥ï¼è½å¤èçä¸ä¸ª RTTã #### 2.httpsè®¡ç®æ§è½ä¼å 1. ä¼å ä½¿ç¨ ECCæ¤åå å¯ç®æ¯ã ECC æ¤åå å¯ç®æ¯ç¸æ¯æ®éç离æ£å¯¹æ°è®¡ç®é度æ§è½è¦å¼ºå¾å¤ã  2.ä½¿ç¨ææ°çç opensslã ä¸è¬æ¥è®²ï¼æ°çç OpenSSL ç¸æ¯èçç计ç®é度åå®å ¨æ§é½ä¼ææåã 3.硬件å éæ¹æ¡ã - SSL ä¸ç¨å éå¡ã - GPUSSL å éã 4.TLS è¿ç¨ä»£çè®¡ç® #### 4.httpåhttps HTTPï¼(HyperText Transfer Protocol)è¶ ææ¬ä¼ è¾åè®® HTTPSï¼(Hypertext Transfer Protocol Secure)è¶ ææ¬ä¼ è¾å®å ¨åè®® HTTPåHTTPSåè®®ç主è¦åºå«å¦ä¸ï¼ HTTPSåè®®éè¦CAè¯ä¹¦ï¼è´¹ç¨è¾é«ï¼HTTPåè®®ä¸éè¦ HTTPåè®®æ¯è¶ ææ¬ä¼ è¾åè®®ï¼ä¿¡æ¯æ¯ææä¼ è¾çï¼HTTPSåæ¯å ·æå®å ¨æ§çSSLå å¯ä¼ è¾åè®® 使ç¨ä¸åçè¿æ¥æ¹å¼ï¼ç«¯å£ä¹ä¸åï¼HTTPåè®®ç«¯å£æ¯80ï¼HTTPSçåè®®ç«¯å£æ¯443 HTTPåè®®è¿æ¥å¾ç®åï¼æ¯æ ç¶æçï¼HTTPSåè®®æ¯æSSLåHTTPåè®®æå»ºçå¯è¿è¡å å¯ä¼ è¾ã身份认è¯çç½ç»åè®®ï¼æ¯HTTPæ´å å®å ¨ #### 5.HTTPS为ä»ä¹æ¯å®å ¨çï¼ HTTPSç¸å¯¹äºHTTPåè®®ï¼å å ¥äºTLS/SSLï¼å®çå ¨ç§°ä¸ºå®å ¨ä¼ è¾å±åè®®ï¼æ¯ä»äºTCPåHTTPä¹é´çä¸å±å®å ¨åè®®ã TLS/SSLçåè½å®ç°ä¸»è¦ä¾èµä¸ç±»åºæ¬ç®æ³ï¼æ£å彿°hashã对称å å¯ãé对称å å¯ãè¿ä¸ç±»ç®æ³çä½ç¨å¦ä¸ï¼ åºäºæ£å彿°éªè¯ä¿¡æ¯ç宿´æ§ 对称å å¯ç®æ³éç¨ååçç§é¥å¯¹æ°æ®å å¯ é对称å å¯å®ç°èº«ä»½è®¤è¯åç§é¥åå  #### 6.HTTPSç¸å¯¹äºHTTPç缺é·ï¼ - HTTPSéè¦åæå¡å¨å客æ·ç«¯åæ¹çå å¯ä¸ªè§£å¯å¤çï¼èè´¹æ´å¤æå¡å¨èµæºï¼è¿ç¨å¤æ - HTTPSåè®®æ¡æé¶æ®µæ¯è¾è´¹æ¶ï¼å¢å 页é¢çå è½½æ¶é´ - SSLè¯ä¹¦æ¯æ¶è´¹çï¼åè½è¶å¼ºå¤§çè¯ä¹¦è´¹ç¨è¶é« - HTTPSè¿æ¥æå¡å¨ç«¯èµæºå ç¨é«å¾å¤ï¼æ¯æè®¿å®¢ç¨å¤çç½ç«éè¦æå ¥æ´å¤§çææ¬ #### 7.为ä»ä¹éè¦è¯ä¹¦? 鲿¢ä¸é´äººæ»å»,éªè¯æå¡å¨èº«ä»½ #### 8.æä¹é²æ¢ç篡æ¹? è¯ä¹¦æ¯å ¬å¼ç,è½ç¶ä¸é´äººå¯ä»¥æ¿å°è¯ä¹¦,ä½ç§é¥æ æ³è·å,å ¬é¥æ æ³æ¨æåºç§é¥,æä»¥ç¯¡æ¹åä¸è½ç¨ç§é¥å å¯,强è¡å å¯å®¢æ·ä¹æ æ³è§£å¯,强è¡ä¿®æ¹å 容,ä¼å¯¼è´è¯ä¹¦å 容ä¸ç¾åä¸çæçº¹ä¸å¹é #### åè龿¥ https://blog.csdn.net/qq_42033567/article/details/107902340 https://www.cnblogs.com/Duikerdd/p/12030955.html