{"id":845,"date":"2026-05-22T07:09:32","date_gmt":"2026-05-21T23:09:32","guid":{"rendered":"https:\/\/www.loongdi.net\/blog\/?p=845"},"modified":"2026-05-22T07:09:32","modified_gmt":"2026-05-21T23:09:32","slug":"pem%e6%96%87%e4%bb%b6%e7%94%a8%e4%ba%8e%e5%8a%a0%e5%af%86%e9%80%9a%e4%bf%a1%e7%9a%84x-509%e6%95%b0%e5%ad%97%e8%af%81%e4%b9%a6%ef%bc%8c%e5%9c%a8%e5%93%aa%e9%87%8c%e5%8f%af%e4%bb%a5%e7%94%9f%e6%88%90","status":"publish","type":"post","link":"https:\/\/www.loongdi.net\/blog\/845.html","title":{"rendered":"PEM\u6587\u4ef6\u7528\u4e8e\u52a0\u5bc6\u901a\u4fe1\u7684X.509\u6570\u5b57\u8bc1\u4e66\uff0c\u5728\u54ea\u91cc\u53ef\u4ee5\u751f\u6210\u5e76\u914d\u7f6eSSL\uff0fTLS\u52a0\u5bc6\u7684\u670d\u52a1\u5668\uff1f"},"content":{"rendered":"<p><p>PEM\u6587\u4ef6\u662f\u7528\u4e8e\u52a0\u5bc6\u901a\u4fe1\u7684X.509\u6570\u5b57\u8bc1\u4e66\u7684\u6587\u4ef6\u683c\u5f0f\uff0c\u5e38\u7528\u4e8eSSL\/TLS\u52a0\u5bc6\u7684\u7f51\u7ad9\u548c\u670d\u52a1\u5668\u3002\u672c\u6587\u5c06\u8be6\u7ec6\u4ecb\u7ecd\u5982\u4f55\u751f\u6210PEM\u6587\u4ef6\uff0c\u5e76\u5c06\u5176\u7528\u4e8e\u914d\u7f6eSSL\/TLS\u52a0\u5bc6\u7684\u670d\u52a1\u5668\u3002<\/p>\n<\/p>\n<p><h2>\u64cd\u4f5c\u524d\u7684\u51c6\u5907<\/h2>\n<\/p>\n<p><p>\u5728\u5f00\u59cb\u4e4b\u524d\uff0c\u8bf7\u786e\u4fdd\u60a8\u5df2\u7ecf\u5b89\u88c5\u4e86OpenSSL\u5de5\u5177\u3002\u5927\u591a\u6570Linux\u53d1\u884c\u7248\u90fd\u9884\u88c5\u4e86OpenSSL\uff0c\u5982\u679c\u6ca1\u6709\uff0c\u53ef\u4ee5\u4f7f\u7528\u5305\u7ba1\u7406\u5668\u8fdb\u884c\u5b89\u88c5\u3002\u4ee5\u4e0b\u662f\u5728Ubuntu\u548cCentOS\u7cfb\u7edf\u4e0a\u5b89\u88c5OpenSSL\u7684\u793a\u4f8b\u547d\u4ee4\uff1a<\/p>\n<\/p>\n<p><pre><code>sudo apt-get install openssl -y   Ubuntu<\/p>\r\n<p>sudo yum install openssl -y        CentOS<\/code><\/pre>\n<\/p>\n<p><h2>\u751f\u6210PEM\u6587\u4ef6<\/h2>\n<\/p>\n<p><h3>1. \u521b\u5efa\u79c1\u94a5<\/h3>\n<\/p>\n<p><p>\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u521b\u5efa\u4e00\u4e2a\u79c1\u94a5\u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u5728\u63d0\u793a\u65f6\u8f93\u5165\u4e00\u4e2a\u5f3a\u5bc6\u7801\u3002<\/p>\n<\/p>\n<p><pre><code>openssl genpkey -algorithm RSA -out private.key -pkeyopt rsa_keygen_bits:2048<\/code><\/pre>\n<\/p>\n<p><h3>2. \u521b\u5efa\u8bc1\u4e66\u8bf7\u6c42<\/h3>\n<\/p>\n<p><p>\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u521b\u5efa\u4e00\u4e2a\u8bc1\u4e66\u8bf7\u6c42\u6587\u4ef6\u3002\u60a8\u9700\u8981\u586b\u5199\u4e00\u4e9b\u4fe1\u606f\uff0c\u5305\u62ec\u7ec4\u7ec7\u540d\u79f0\u3001\u56fd\u5bb6\u4ee3\u7801\u7b49\u3002<\/p>\n<\/p>\n<p><pre><code>openssl req -new -key private.key -out certificate.csr<\/code><\/pre>\n<\/p>\n<p><p>\u5728\u63d0\u793a\u65f6\uff0c\u8f93\u5165\u4ee5\u4e0b\u4fe1\u606f\uff1a<\/p>\n<\/p>\n<ul>\n<li>Country Name (2 letter code): <strong>\u56fd\u5bb6\u4ee3\u7801<\/strong><\/li>\n<li>State or Province Name (full name): <strong>\u7701\u4efd\u540d\u79f0<\/strong><\/li>\n<li>Locality Name (city): <strong>\u57ce\u5e02\u540d\u79f0<\/strong><\/li>\n<li>Organization Name (company): <strong>\u7ec4\u7ec7\u540d\u79f0<\/strong><\/li>\n<li>Organizational Unit Name (department): <strong>\u90e8\u95e8\u540d\u79f0<\/strong><\/li>\n<li>Common Name (CN): <strong>\u60a8\u7684\u57df\u540d<\/strong><\/li>\n<li>Email Address: <strong>\u60a8\u7684\u7535\u5b50\u90ae\u4ef6\u5730\u5740<\/strong><\/li>\n<\/ul>\n<p><h3>3. \u751f\u6210\u81ea\u7b7e\u540d\u8bc1\u4e66<\/h3>\n<\/p>\n<p><p>\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u751f\u6210\u4e00\u4e2a\u81ea\u7b7e\u540d\u8bc1\u4e66\uff0c\u8be5\u8bc1\u4e66\u5c06\u7528\u4e8e\u6d4b\u8bd5\u76ee\u7684\u3002<\/p>\n<\/p>\n<p><pre><code>openssl x509 -req -days 365 -in certificate.csr -signkey private.key -out certificate.crt<\/code><\/pre>\n<\/p>\n<p><h2>\u914d\u7f6eSSL\/TLS\u52a0\u5bc6\u7684\u670d\u52a1\u5668<\/h2>\n<\/p>\n<p><h3>1. Apache\u670d\u52a1\u5668\u914d\u7f6e<\/h3>\n<\/p>\n<p><p>\u7f16\u8f91Apache\u914d\u7f6e\u6587\u4ef6\uff0c\u901a\u5e38\u4f4d\u4e8e`\/etc\/apache2\/sites-available\/`\u76ee\u5f55\u4e0b\u3002\u4ee5\u4e0b\u662f\u4e00\u4e2a\u793a\u4f8b\u914d\u7f6e\u7247\u6bb5\uff1a<\/p>\n<\/p>\n<p><pre><code>&lt;VirtualHost :443&gt;<\/p>\r\n<p>    ServerName yourdomain.com<\/p>\r\n<p>    DocumentRoot \/var\/www\/yourdomain.com<\/p>\r\n\r\n<p>    SSLEngine on<\/p>\r\n<p>    SSLCertificateFile \/path\/to\/certificate.crt<\/p>\r\n<p>    SSLCertificateKeyFile \/path\/to\/private.key<\/p>\r\n<p>    SSLCertificateChainFile \/path\/to\/ca_bundle.crt<\/p>\r\n<p>&lt;\/VirtualHost&gt;<\/code><\/pre>\n<\/p>\n<p><p>\u8bf7\u786e\u4fdd\u66ff\u6362`yourdomain.com`\u3001`\/path\/to\/certificate.crt`\u3001`\/path\/to\/private.key`\u548c`\/path\/to\/ca_bundle.crt`\u4e3a\u60a8\u7684\u5b9e\u9645\u57df\u540d\u548c\u6587\u4ef6\u8def\u5f84\u3002<\/p>\n<\/p>\n<p><h3>2. Nginx\u670d\u52a1\u5668\u914d\u7f6e<\/h3>\n<\/p>\n<p><p>\u7f16\u8f91Nginx\u914d\u7f6e\u6587\u4ef6\uff0c\u901a\u5e38\u4f4d\u4e8e`\/etc\/nginx\/sites-available\/`\u76ee\u5f55\u4e0b\u3002\u4ee5\u4e0b\u662f\u4e00\u4e2a\u793a\u4f8b\u914d\u7f6e\u7247\u6bb5\uff1a<\/p>\n<\/p>\n<p><pre><code>server {<\/p>\r\n<p>    listen 443 ssl;<\/p>\r\n<p>    server_name yourdomain.com;<\/p>\r\n\r\n<p>    ssl_certificate \/path\/to\/certificate.crt;<\/p>\r\n<p>    ssl_certificate_key \/path\/to\/private.key;<\/p>\r\n<p>    ssl_session_timeout 1d;<\/p>\r\n<p>    ssl_session_cache shared:SSL:50m;<\/p>\r\n<p>    ssl_session_tickets off;<\/p>\r\n\r\n<p>    ssl_protocols TLSv1.2 TLSv1.3;<\/p>\r\n<p>    ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256...';<\/p>\r\n<p>    ssl_prefer_server_ciphers on;<\/p>\r\n\r\n<p>    location \/ {<\/p>\r\n<p>        root \/var\/www\/yourdomain.com;<\/p>\r\n<p>        index index.html index.htm;<\/p>\r\n<p>    }<\/p>\r\n<p>}<\/p>\r\n<p><\/code><\/pre>\n<\/p>\n<p><p>\u8bf7\u786e\u4fdd\u66ff\u6362`yourdomain.com`\u3001`\/path\/to\/certificate.crt`\u548c`\/path\/to\/private.key`\u4e3a\u60a8\u7684\u5b9e\u9645\u57df\u540d\u548c\u6587\u4ef6\u8def\u5f84\u3002<\/p>\n<\/p>\n<p><h2>\u64cd\u4f5c\u8fc7\u7a0b\u4e2d\u53ef\u80fd\u9047\u5230\u7684\u95ee\u9898\u548c\u6ce8\u610f\u4e8b\u9879<\/h2>\n<\/p>\n<ul>\n<li><strong>\u95ee\u9898\uff1a<\/strong>\u79c1\u94a5\u6587\u4ef6\u4e22\u5931\u5bfc\u81f4\u65e0\u6cd5\u91cd\u65b0\u751f\u6210\u8bc1\u4e66\u3002<\/li>\n<li><strong>\u89e3\u51b3\u65b9\u6848\uff1a<\/strong>\u5982\u679c\u60a8\u6709\u5907\u4efd\uff0c\u53ef\u4ee5\u4ece\u5907\u4efd\u4e2d\u6062\u590d\u79c1\u94a5\u3002\u5982\u679c\u6ca1\u6709\u5907\u4efd\uff0c\u60a8\u5c06\u9700\u8981\u91cd\u65b0\u521b\u5efa\u8bc1\u4e66\u548c\u79c1\u94a5\u3002<\/li>\n<li><strong>\u95ee\u9898\uff1a<\/strong>\u914d\u7f6e\u6587\u4ef6\u4e2d\u7684\u8def\u5f84\u4e0d\u6b63\u786e\u3002<\/li>\n<li><strong>\u89e3\u51b3\u65b9\u6848\uff1a<\/strong>\u68c0\u67e5\u6587\u4ef6\u8def\u5f84\u662f\u5426\u6b63\u786e\uff0c\u5e76\u786e\u4fdd\u6587\u4ef6\u5177\u6709\u6b63\u786e\u7684\u6743\u9650\u3002<\/li>\n<li><strong>\u95ee\u9898\uff1a<\/strong>SSL\/TLS\u8bc1\u4e66\u65e0\u6cd5\u9a8c\u8bc1\u3002<\/li>\n<li><strong>\u89e3\u51b3\u65b9\u6848\uff1a<\/strong>\u786e\u4fdd\u60a8\u7684\u8bc1\u4e66\u662f\u7531\u53d7\u4fe1\u4efb\u7684\u8bc1\u4e66\u9881\u53d1\u673a\u6784\u7b7e\u53d1\u7684\uff0c\u6216\u8005\u60a8\u5df2\u7ecf\u6b63\u786e\u914d\u7f6e\u4e86\u81ea\u7b7e\u540d\u8bc1\u4e66\u3002<\/li>\n<\/ul>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"https:\/\/www.loongdi.net\/blog\/wp-content\/uploads\/2026\/03\/K323Sk4y.jpg\" alt=\"PEM\u6587\u4ef6\u7528\u4e8e\u52a0\u5bc6\u901a\u4fe1\u7684X.509\u6570\u5b57\u8bc1\u4e66\uff0c\u5728\u54ea\u91cc\u53ef\u4ee5\u751f\u6210\u5e76\u914d\u7f6eSSL\uff0fTLS\u52a0\u5bc6\u7684\u670d\u52a1\u5668\uff1f\" title=\"PEM\u6587\u4ef6\u7528\u4e8e\u52a0\u5bc6\u901a\u4fe1\u7684X.509\u6570\u5b57\u8bc1\u4e66\uff0c\u5728\u54ea\u91cc\u53ef\u4ee5\u751f\u6210\u5e76\u914d\u7f6eSSL\uff0fTLS\u52a0\u5bc6\u7684\u670d\u52a1\u5668\uff1f\"><\/p>\n<p><p>\u901a\u8fc7\u4ee5\u4e0a\u6b65\u9aa4\uff0c\u60a8\u5e94\u8be5\u80fd\u591f\u6210\u529f\u751f\u6210PEM\u6587\u4ef6\uff0c\u5e76\u5c06\u5176\u7528\u4e8e\u914d\u7f6eSSL\/TLS\u52a0\u5bc6\u7684\u670d\u52a1\u5668\u3002\u795d\u60a8\u64cd\u4f5c\u987a\u5229\uff01<\/p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PEM\u6587\u4ef6\u662f\u7528\u4e8e\u52a0\u5bc6\u901a\u4fe1\u7684X.509\u6570\u5b57\u8bc1\u4e66\u7684\u6587\u4ef6\u683c\u5f0f\uff0c\u5e38\u7528\u4e8eSSL\/TLS\u52a0\u5bc6\u7684\u7f51\u7ad9\u548c\u670d\u52a1\u5668\u3002\u672c\u6587\u5c06\u8be6\u7ec6\u4ecb\u7ecd\u5982\u4f55\u751f\u6210PEM\u6587\u4ef6\uff0c\u5e76\u5c06\u5176\u7528\u4e8e\u914d\u7f6eSSL\/TLS\u52a0\u5bc6\u7684\u670d\u52a1\u5668\u3002 \u64cd\u4f5c\u524d\u7684\u51c6\u5907 \u5728\u5f00\u59cb\u4e4b\u524d\uff0c\u8bf7\u786e\u4fdd\u60a8\u5df2\u7ecf\u5b89\u88c5\u4e86OpenSSL\u5de5\u5177\u3002\u5927&#8230;<\/p>\n","protected":false},"author":1,"featured_media":163,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"topic":[],"class_list":["post-845","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hw"],"_links":{"self":[{"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/posts\/845","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/comments?post=845"}],"version-history":[{"count":1,"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/posts\/845\/revisions"}],"predecessor-version":[{"id":846,"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/posts\/845\/revisions\/846"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/media\/163"}],"wp:attachment":[{"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/media?parent=845"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/categories?post=845"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/tags?post=845"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.loongdi.net\/blog\/wp-json\/wp\/v2\/topic?post=845"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}