How I moved to https 1. I registered at startssl.com, passed the domain 2 check. The Certificate Wizard came in, poked DV SSL Certificate, entered the domain and subdomains. 3. Poked to generate independently, downloaded and opened StartComTool.exe, clicked generate CSR. Saved key. 4. The site entered received CSR. Poke a button to pass. Tyknul certificate sheet 5. Tyknul get and downloaded. I threw the key from point 3 and the CSR from the archive I just received from the nginxserver folder onto the server. 6. Fixed the working nginx config on the following and it became not working:

server { listen 80; server_name ***; location / { root /usr/html/***; index index.html index.htm; } return 301 https://***$request_uri; } server { listen 433 ssl; server_name ***; ssl_certificate /etc/ssl/nginx/***.pem; ssl_certificate_key /etc/ssl/nginx/***.key; location / { root /usr/html/***; index index.html index.htm; } } 

When I try to log in, it writes ERR_CONNECTION_REFUSED. What am I doing wrong?

  • 1. opennet.ru/opennews/art.shtml?num=45405 2. the last but one line makes any sense? 3. configtest successful? 4. no errors in the logs? - aleksandr barakin
  • @alexanderbarakin 1. If so, I would receive a warning. 2. Without the last line the same, it does not carry much meaning. Yes, and she can not break anything, she says that the server would return the answer via https, something like this ... 3.configtest goes bang and everything works except this site. 4.In the error logs are not written. - Geri4
  • > I threw the key from point 3 and the CSR from the archive onto the server ... And for the HTTPS operation on the web server, no CSR is needed. - AntonioK
  • @AntonioK as I understood from the manuals, you also need to download the certificate Class 1 Intermediate Server CA, merge it with the certificate that came in one cat ***. Crt file sub.class1.server.ca.pem> ***. Pem or do it not necessary? - Geri4
  • nginx -t in the console will tell you which line nginx is plugged in - etki

1 answer 1

listen 443 ssl; Port number 443, not 433