首页 小编推荐 正文
  • 本文约1731字,阅读需9分钟
  • 104222
  • 45

wordpress配置https

温馨提示:本文最后更新于2025年11月12日 00:30,若内容或图片失效,请在下方留言或联系博主。
摘要
  1. 获取SSL证书

    • 选择SSL证书提供商(如Let's Encrypt、Cloudflare、GoDaddy等)
    • 根据域名申请免费或付费SSL证书
    • 获取证书文件(通常包含.crt或.pem文件和私钥文件.key)
  2. 将SSL证书上传到服务器

    • 通过F...
  1. 获取SSL证书

    • 选择SSL证书提供商(如Let's Encrypt、Cloudflare、GoDaddy等)
    • 根据域名申请免费或付费SSL证书
    • 获取证书文件(通常包含.crt或.pem文件和私钥文件.key)
  2. 将SSL证书上传到服务器

    • 通过FTP、SFTP或服务器控制面板(如cPanel、Plesk)将证书文件上传至服务器指定路径(如/etc/ssl/certs/)
    • 确保文件权限设置正确(例如:chmod 600)
  3. 配置Web服务器(Apache或Nginx)

    • Apache:
    • 编辑虚拟主机配置文件(如/etc/apache2/sites-available/yourdomain.conf)
    • 添加以下内容:
      <VirtualHost *:443>
      ServerName yourdomain.com
      DocumentRoot /var/www/html
      SSLEngine on
      SSLCertificateFile "/etc/ssl/certs/yourdomain.crt"
      SSLCertificateKeyFile "/etc/ssl/private/yourdomain.key"
      SSLCertificateChainFile "/etc/ssl/certs/chain.pem"
      </VirtualHost>
    • 启用SSL模块:a2enmod ssl
    • 重启Apache服务:systemctl restart apache2
  • Nginx:

    • 编辑站点配置文件(如/etc/nginx/sites-available/yourdomain.conf)
    • 添加以下内容:

      server {
      listen 443 ssl;
      server_name yourdomain.com;
      root /var/www/html;
      index index.php index.html index.htm;
      
      ssl_certificate /etc/ssl/certs/yourdomain.crt;
      ssl_certificate_key /etc/ssl/private/yourdomain.key;
      ssl_trusted_certificate /etc/ssl/certs/chain.pem;
      }
    • 测试配置:nginx -t
    • 重启Nginx服务:systemctl restart nginx
  1. 强制WordPress使用HTTPS

    • 在WordPress后台:
    • 登录到WordPress管理后台
    • 进入“设置” > “常规”
    • 将“WordPress地址(URL)”和“站点地址(URL)”修改为https://yourdomain.com
    • 或在wp-config.php中添加:
      define('FORCE_SSL_ADMIN', true);
      define('FORCE_SSL_LOGIN', true);
  2. 更新数据库中的URL

    • 使用PHPMyAdmin或命令行工具(如mysql)登录数据库
    • 执行SQL语句更新wp_options表中的siteurl和home字段:
      UPDATE wp_options SET option_value = 'https://yourdomain.com' WHERE option_name = 'siteurl' OR option_name = 'home';
    • 如果使用多站点(Multisite),还需更新wp_blogs和wp_site表
  3. 配置WordPress的HTTPS插件(可选)

    • 安装并激活插件如“Really Simple SSL”或“SSL Insecure Content Fixer”
    • 按照插件说明完成配置,确保所有资源加载为HTTPS
  4. 测试HTTPS配置

    • 访问https://yourdomain.com确认网站正常加载
    • 使用在线工具(如SSL Labs的SSL Test)检测SSL配置安全性
    • 检查浏览器是否显示安全锁图标
  5. 配置HTTP重定向到HTTPS(可选)

    • Apache:在非HTTPS的虚拟主机中添加:
      RewriteEngine On
      RewriteCond %{HTTPS} off
      RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    • Nginx:在非HTTPS的server块中添加:
      if ($scheme = http) {
      return 301 https://$host$request_uri;
      }
48434 人点赞
评论