ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ื”ืจื‘ื” ื–ืžืŸ ืจืฆื™ืชื™ "ืœื’ืขืช ื‘ื™ื“ื™ื™ื ืฉืœื™" ื‘ืฉื™ืจื•ืชื™ ืื™ื ื˜ืจื ื˜ ืขืœ ื™ื“ื™ ื”ืงืžืช ืฉืจืช ืื™ื ื˜ืจื ื˜ ืžืืคืก ื•ืฉื—ืจื•ืจื• ืœืื™ื ื˜ืจื ื˜. ื‘ืžืืžืจ ื–ื” ืื ื™ ืจื•ืฆื” ืœื—ืœื•ืง ืืช ื”ื ื™ืกื™ื•ืŸ ืฉืœื™ ื‘ื”ืคื™ื›ืช ื ืชื‘ ื‘ื™ืชื™ ืžืžื›ืฉื™ืจ ืคื•ื ืงืฆื™ื•ื ืœื™ ื‘ื™ื•ืชืจ ืœืฉืจืช ื›ืžืขื˜ ืžืœื.

ื”ื›ืœ ื”ืชื—ื™ืœ ื‘ื›ืš ืฉื”ื ืชื‘ TP-Link TL-WR1043ND, ืฉืฉื™ืžืฉ ื ืืžื ื”, ื›ื‘ืจ ืœื ืขื ื” ืขืœ ื”ืฆืจื›ื™ื ืฉืœ ืจืฉืช ื‘ื™ืชื™ืช, ืจืฆื™ืชื™ ืคืก 5 ื’ื™ื’ื”-ื”ืจืฅ ื•ื’ื™ืฉื” ืžื”ื™ืจื” ืœืงื‘ืฆื™ื ื‘ื”ืชืงืŸ ืื—ืกื•ืŸ ื”ืžื—ื•ื‘ืจ ืœื ืชื‘ . ืœืื—ืจ ืขื™ื•ืŸ ื‘ืคื•ืจื•ืžื™ื ืžื™ื•ื—ื“ื™ื (4pda, ixbt), ืืชืจื™ื ืขื ื‘ื™ืงื•ืจื•ืช ื•ืขื™ื•ืŸ ื‘ืžื‘ื—ืจ ื”ื—ื ื•ื™ื•ืช ื”ืžืงื•ืžื™ื•ืช, ื”ื—ืœื˜ืชื™ ืœืจื›ื•ืฉ ืืช Keenetic Ultra.

ื‘ื™ืงื•ืจื•ืช ื˜ื•ื‘ื•ืช ืžื”ื‘ืขืœื™ื ืคืขืœื• ืœื˜ื•ื‘ืช ื”ืžื›ืฉื™ืจ ื”ืžืกื•ื™ื ื”ื–ื”:

  • ืื™ืŸ ื‘ืขื™ื•ืช ืขื ื”ืชื—ืžืžื•ืช ื™ืชืจ (ื›ืืŸ ื ืืœืฆื ื• ืœื ื˜ื•ืฉ ืืช ืžื•ืฆืจื™ Asus);
  • ืืžื™ื ื•ืช ืชืคืขื•ืœื™ืช (ื›ืืŸ ื—ืฆื™ืชื™ ืืช TP-Link);
  • ืงืœ ืœื”ื’ื“ืจื” (ืคื—ื“ืชื™ ืฉืื ื™ ืœื ื™ื›ื•ืœ ืœื”ืชืžื•ื“ื“ ืขื ื–ื” ื•ื”ืžื—ืงืชื™ ืืช Microtik).

ื”ื™ื™ืชื™ ืฆืจื™ืš ืœื”ืฉืœื™ื ืขื ื”ื—ืกืจื•ื ื•ืช:

  • ืื™ืŸ WiFi6, ืจืฆื™ืชื™ ืœืงื—ืช ืฆื™ื•ื“ ืขื ืจื–ืจื‘ื” ืœืขืชื™ื“;
  • 4 ื™ืฆื™ืื•ืช LAN, ืจืฆื™ืชื™ ื™ื•ืชืจ, ืื‘ืœ ื–ื• ื›ื‘ืจ ืœื ืงื˜ื’ื•ืจื™ื” ื‘ื™ืชื™ืช.

ื›ืชื•ืฆืื” ืžื›ืš, ืงื™ื‘ืœื ื• ืืช ื”"ืฉืจืช" ื”ื–ื”:

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

  • ืžืฉืžืืœ ื ืžืฆื ื”ืžืกื•ืฃ ื”ืื•ืคื˜ื™ ืฉืœ Rostelecom;
  • ื‘ืฆื“ ื™ืžื™ืŸ ื ืžืฆื ื”ื ืชื‘ ื”ื ื™ืกื™ื•ื ื™ ืฉืœื ื•;
  • SSD 2 GB m.128 ืฉื•ื›ื‘ ืžืกื‘ื™ื‘, ืžืžื•ืงื ื‘ืงื•ืคืกืช USB3 ืž- Aliexpress, ืžื—ื•ื‘ืจ ืœื ืชื‘ ืขื ื—ื•ื˜, ื›ืขืช ื”ื•ื ืžื•ืชืงืŸ ื‘ืฆื•ืจื” ืžืกื•ื“ืจืช ืขืœ ื”ืงื™ืจ;
  • ื‘ื—ื–ื™ืช ื”ื•ื ื›ื‘ืœ ืžืืจื™ืš ืขื ืฉืงืขื™ื ืžื ื•ืชืงื™ื ื‘ืื•ืคืŸ ืขืฆืžืื™, ื”ื—ื•ื˜ ืžืžื ื• ืขื•ื‘ืจ ืœ-UPS ืœื ื™ืงืจ;
  • ื‘ืจืงืข ื™ืฉ ืฆืจื•ืจ ื›ื‘ืœื™ื ืžืขื•ื•ืชื™ื - ื‘ืฉืœื‘ ืฉื™ืคื•ืฅ ื”ื“ื™ืจื” ืชื™ื›ื ื ืชื™ ืžื™ื“ ืฉืงืขื™ RJ45 ื‘ืžืงื•ืžื•ืช ืฉื‘ื”ื ื”ืฆื™ื•ื“ ื”ื™ื” ืืžื•ืจ ืœื”ื™ื•ืช ืžืžื•ืงื, ื›ื“ื™ ืœื ืœื”ื™ื•ืช ืชืœื•ื™ ื‘-WiFi ืฉื™ืชืœื›ืœืš.

ืื–, ื™ืฉ ืœื ื• ืืช ื”ืฆื™ื•ื“, ืื ื—ื ื• ืฆืจื™ื›ื™ื ืœื”ื’ื“ื™ืจ ืื•ืชื•:

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

  • ื”ื”ื’ื“ืจื” ื”ืจืืฉื•ื ื™ืช ืฉืœ ื”ื ืชื‘ ืื•ืจื›ืช ื›-2 ื“ืงื•ืช, ืื ื• ืžืฆื™ื™ื ื™ื ืœืกืคืง ืืช ืคืจืžื˜ืจื™ ื”ื—ื™ื‘ื•ืจ (ื”ื˜ืจืžื™ื ืœ ื”ืื•ืคื˜ื™ ืฉืœื™ ืขื•ื‘ืจ ืœืžืฆื‘ ื’ืฉืจ, ื—ื™ื‘ื•ืจ PPPoE ืžืจื™ื ืืช ื”ื ืชื‘), ืฉื ืจืฉืช ื”-WiFi ื•ื”ืกื™ืกืžื” - ื‘ืขืฆื ื–ื”ื• , ื”ื ืชื‘ ืžื•ืคืขืœ ื•ืขื•ื‘ื“.

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ื”ื’ื“ืจื ื• ื”ืขื‘ืจื” ืฉืœ ื™ืฆื™ืื•ืช ื—ื™ืฆื•ื ื™ื•ืช ืœื™ืฆื™ืื•ืช ืฉืœ ื”ื ืชื‘ ืขืฆืžื• ื‘ืกืขื™ืฃ "ื›ืœืœื™ ืจืฉืช - ื”ืขื‘ืจื”":

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ืขื›ืฉื™ื• ืื ื—ื ื• ื™ื›ื•ืœื™ื ืœืขื‘ื•ืจ ืœื—ืœืง ื”"ืžืชืงื“ื", ืžื” ืฉืจืฆื™ืชื™ ืžื”ื ืชื‘:

  1. ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ NAS ืงื˜ืŸ ืขื‘ื•ืจ ืจืฉืช ื‘ื™ืชื™ืช;
  2. ื‘ื™ืฆื•ืข ืคื•ื ืงืฆื™ื•ืช ืฉืจืช ืื™ื ื˜ืจื ื˜ ืขื‘ื•ืจ ืžืกืคืจ ื“ืคื™ื ืคืจื˜ื™ื™ื;
  3. ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืขื ืŸ ืื™ืฉื™ืช ืœื’ื™ืฉื” ืœื ืชื•ื ื™ื ืื™ืฉื™ื™ื ืžื›ืœ ืžืงื•ื ื‘ืขื•ืœื.

ื”ืจืืฉื•ืŸ ืžื™ื•ืฉื ื‘ืืžืฆืขื•ืช ื›ืœื™ื ืžื•ื‘ื ื™ื, ืœืœื ืฆื•ืจืš ื‘ืžืืžืฅ ืจื‘:

  • ืื ื• ืœื•ืงื—ื™ื ื›ื•ื ืŸ ื”ืžื™ื•ืขื“ ืœืชืคืงื™ื“ ื–ื” (ื›ื•ื ืŸ ืคืœืืฉ, ื›ืจื˜ื™ืก ื–ื™ื›ืจื•ืŸ ื‘ืงื•ืจื ื›ืจื˜ื™ืกื™ื, ื›ื•ื ืŸ ืงืฉื™ื— ืื• SSD ื‘ืงื•ืคืกื” ื—ื™ืฆื•ื ื™ืช ื•ืžืคืจืžื˜ื™ื ืื•ืชื• ืœ-Ext4 ื‘ืืžืฆืขื•ืช ื”ืžื”ื“ื•ืจื” ื”ื—ื™ื ืžื™ืช ืฉืœ ืืฉืฃ ื”ืžื—ื™ืฆื•ืช (ืื™ืŸ ืœื™ ืžื—ืฉื‘ ืขื ืœื™ื ื•ืงืก ื‘ื”ื™ืฉื’ ื™ื“, ื–ื” ืืคืฉืจื™ ืขื ื›ืœื™ื ืžื•ื‘ื ื™ื). ืœืคื™ ื”ื‘ื ืชื™, ื‘ื–ืžืŸ ื”ืคืขื•ืœื” ื”ืžืขืจื›ืช ื›ื•ืชื‘ืช ืจืง ืœื•ื’ื™ื ืœื›ื•ื ืŸ ื”ื‘ื–ืง, ื›ืš ืฉืื ืชื’ื‘ื™ืœ ืื•ืชื ืœืื—ืจ ื”ื’ื“ืจืช ื”ืžืขืจื›ืช, ืชื•ื›ืœ ืœื”ืฉืชืžืฉ ื’ื ื‘ื›ืจื˜ื™ืกื™ ื–ื™ื›ืจื•ืŸ ืื ืืชื” ืžืชื›ื•ื•ืŸ ืœื›ืชื•ื‘ ื”ืจื‘ื” ื•ืœืขืชื™ื ืงืจื•ื‘ื•ืช ืœื›ื•ื ืŸ - SSD ืื• HDD ื˜ื•ื‘ ื™ื•ืชืจ.

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ืœืื—ืจ ืžื›ืŸ, ืื ื• ืžื—ื‘ืจื™ื ืืช ื”ื›ื•ื ืŸ ืœื ืชื‘ ื•ืฆื•ืคื™ื ื‘ื• ื‘ืžืกืš ืฆื’ ื”ืžืขืจื›ืช

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ืœื—ืฅ ืขืœ "ื›ื•ื ื ื™ USB ื•ืžื“ืคืกื•ืช" ืœืงื˜ืข "ื™ื™ืฉื•ืžื™ื" ื•ื”ื’ื“ืจ ืืช ื”ืฉื™ืชื•ืฃ ื‘ืงื˜ืข "ืจืฉืช Windows":

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ื•ื™ืฉ ืœื ื• ืžืฉืื‘ ืจืฉืช ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ืžืžื—ืฉื‘ื™ Windows, ืœื”ืชื—ื‘ืจ ื›ื“ื™ืกืง ื‘ืžื™ื“ืช ื”ืฆื•ืจืš: ื ื˜ื• ื”ืฉืชืžืฉ ื‘-y: \192.168.1.1SSD /persistent:yes

ื”ืžื”ื™ืจื•ืช ืฉืœ NAS ืžืื•ืœืชืจ ืฉื›ื–ื” ืžืกืคื™ืงื” ืœืžื“ื™ ืœืฉื™ืžื•ืฉ ื‘ื™ืชื™; ืขืœ ื—ื•ื˜ ื”ื•ื ืžืฉืชืžืฉ ื‘ื›ืœ ื”ื’ื™ื’ื”-ื‘ื™ื˜, ื‘-WiFi ื”ืžื”ื™ืจื•ืช ื”ื™ื ื‘ืขืจืš 400-500 ืžื’ื”-ื‘ื™ื˜.

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ื”ื’ื“ืจืช ืื—ืกื•ืŸ ื”ื™ื ืื—ื“ ื”ืฉืœื‘ื™ื ื”ื“ืจื•ืฉื™ื ืœื”ื’ื“ืจืช ื”ืฉืจืช, ืื– ืื ื—ื ื• ืฆืจื™ื›ื™ื:
- ืœืงื ื•ืช ื“ื•ืžื™ื™ืŸ ื•ื›ืชื•ื‘ืช IP ืกื˜ื˜ื™ืช (ืืชื” ื™ื›ื•ืœ ืœื”ืกืชื“ืจ ื‘ืœื™ ื–ื” ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ื‘-DNS ื“ื™ื ืžื™, ืื‘ืœ ื›ื‘ืจ ื”ื™ื” ืœื™ IP ืกื˜ื˜ื™, ืื– ื”ืชื‘ืจืจ ืฉื–ื” ืงืœ ื™ื•ืชืจ ืœืฉื™ืžื•ืฉ ืฉื™ืจื•ืชื™ Yandex ื‘ื—ื™ื ื - ืขืœ ื™ื“ื™ ื”ืืฆืœืช ื”ื“ื•ืžื™ื™ืŸ ืœืฉื, ืื ื• ืžืงื‘ืœื™ื ืื™ืจื•ื— DNS ื•ื“ื•ืืจ ื‘ื“ื•ืžื™ื™ืŸ ืฉืœื ื•);

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

- ืœื”ื’ื“ื™ืจ ืฉืจืชื™ DNS ื•ื”ื•ืกืฃ ืจืฉื•ืžื•ืช A ื”ืžืฆื‘ื™ืขื•ืช ืขืœ ื”-IP ืฉืœืš:

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ืœื•ืงื— ืžืกืคืจ ืฉืขื•ืช ืขื“ ืฉื”ื’ื“ืจื•ืช ื”ืืฆืœืช ื”ื“ื•ืžื™ื™ืŸ ื•ื”-DNS ื™ื™ื›ื ืกื• ืœืชื•ืงืฃ, ื•ืœื›ืŸ ืื ื• ืžื’ื“ื™ืจื™ื ื‘ื•-ื–ืžื ื™ืช ืืช ื”ื ืชื‘.

ืจืืฉื™ืช, ืขืœื™ื ื• ืœื”ืชืงื™ืŸ ืืช ืžืื’ืจ Entware, ืžืžื ื• ื ื•ื›ืœ ืœื”ืชืงื™ืŸ ืืช ื”ื—ื‘ื™ืœื•ืช ื”ื“ืจื•ืฉื•ืช ืขืœ ื”ื ืชื‘. ื ื™ืฆืœืชื™ ืขื ื”ื•ืจืื” ื–ื•, ืคืฉื•ื˜ ืœื ื”ืขืœื” ืืช ื—ื‘ื™ืœืช ื”ื”ืชืงื ื” ื“ืจืš FTP, ืืœื ื™ืฆืจ ืชื™ืงื™ื” ื™ืฉื™ืจื•ืช ื‘ื›ื•ื ืŸ ื”ืจืฉืช ื”ืžื—ื•ื‘ืจ ื‘ืขื‘ืจ ื•ื”ืขืชื™ืง ืœืฉื ืืช ื”ืงื•ื‘ืฅ ื‘ื“ืจืš ื”ืจื’ื™ืœื”.

ืœืื—ืจ ืฉื”ืฉื’ืช ื’ื™ืฉื” ื“ืจืš SSH, ืฉื ื” ืืช ื”ืกื™ืกืžื” ืขื ื”ืคืงื•ื“ื” passwd ื•ื”ืชืงืŸ ืืช ื›ืœ ื”ื—ื‘ื™ืœื•ืช ื”ื“ืจื•ืฉื•ืช ืขื ื”ืคืงื•ื“ื” opkg install [package names]:

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ื‘ืžื”ืœืš ื”ื”ื’ื“ืจื”, ื”ื—ื‘ื™ืœื•ืช ื”ื‘ืื•ืช ื”ื•ืชืงื ื• ื‘ื ืชื‘ (ื”ืคืœื˜ ืฉืœ ื”ืคืงื•ื“ื” opkg list-installed):

ืจืฉื™ืžืช ื—ื‘ื™ืœื•ืช
bash - 5.0-3
busybox - 1.31.1-1
ca-bundle - 20190110-2
ca-certificates - 20190110-2
coreutils - 8.31-1
coreutils-mktemp - 8.31-1
cron - 4.1-3
ืชืœืชืœ - 7.69.0-1
diffutils - 3.7-2
dropbear - 2019.78-3
entware-release - 1.0-2
findutils - 4.7.0-1
glib2 - 2.58.3-5
grep - 3.4-1
ldconfig - 2.27-9
libattr - 2.4.48-2
libblkid - 2.35.1-1
libc - 2.27-9
libcurl - 7.69.0-1
libffi - 3.2.1-4
libgcc - 8.3.0-9
libiconv-full - 1.11.1-4
libintl-full - 0.19.8.1-2
liblua - 5.1.5-7
libmbedtls - 2.16.5-1
libmount - 2.35.1-1
libncurses - 6.2-1
libncursesw - 6.2-1
libndm - 1.1.10-1a
libopenssl - 1.1.1d-2
libopenssl-conf - 1.1.1d-2
libpcap - 1.9.1-2
libpcre - 8.43-2
libpcre2 - 10.34-1
libpthread - 2.27-9
libreadline - 8.0-1a
librt - 2.27-9
libslang2 - 2.3.2-4
libssh2 - 1.9.0-2
libssp - 8.3.0-9
libstdcpp - 8.3.0-9
libuid - 2.35.1-1
libxml2 - 2.9.10-1
ืžืงื•ืžื•ืช - 2.27-9
mc - 4.8.23-2
ndmq - 1.0.2-5a
nginx - 1.17.8-1
openssl-util - 1.1.1d-2
opkg โ€” 2019-06-14-dcbc142e-2
opt-ndmsv2 - 1.0-12
php7 - 7.4.3-1
php7-mod-openssl - 7.4.3-1
poorbox - 1.31.1-2
terminfo - 6.2-1
zlib - 1.2.11-3
zoneinfo-asia - 2019c-1
zoneinfo-europe - 2019c-1

ืื•ืœื™ ื”ื™ื” ื›ืืŸ ืžืฉื”ื• ืžื™ื•ืชืจ, ืื‘ืœ ื”ื™ื” ื”ืจื‘ื” ืžืงื•ื ื‘ื›ื•ื ืŸ, ืื– ืœื ื˜ืจื—ืชื™ ืœื‘ื“ื•ืง ืืช ื–ื”.

ืœืื—ืจ ื”ืชืงื ืช ื”ื—ื‘ื™ืœื•ืช, ื”ื’ื“ืจื ื• ืืช nginx, ื ื™ืกื™ืชื™ ืืช ื–ื” ืขื ืฉื ื™ ื“ื•ืžื™ื™ื ื™ื - ื”ืฉื ื™ ืžื•ื’ื“ืจ ืขื https, ื•ืœืขืช ืขืชื” ื™ืฉ ื‘ื“ืœ. ื™ืฆื™ืื•ืช ืคื ื™ืžื™ื•ืช 81 ื•-433 ืžืฉืžืฉื•ืช ื‘ืžืงื•ื 80 ื•-443, ืžื›ื™ื•ื•ืŸ ืฉืคืื ืœ ื”ื ื™ื”ื•ืœ ืฉืœ ื”ื ืชื‘ ืชืœื•ื™ ื‘ื™ืฆื™ืื•ืช ืจื’ื™ืœื•ืช.

etc/nginx/nginx.conf

user  nobody;
worker_processes  1;
#error_log  /opt/var/log/nginx/error.log;
#error_log  /opt/var/log/nginx/error.log  notice;
#error_log  /opt/var/log/nginx/error.log  info;
#pid        /opt/var/run/nginx.pid;

events {
    worker_connections  64;
}

http {
    include       mime.types;
    default_type  application/octet-stream;
    #log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
    #                  '$status $body_bytes_sent "$http_referer" '
    #                  '"$http_user_agent" "$http_x_forwarded_for"';
    #access_log  /opt/var/log/nginx/access.log main;
    sendfile        on;
    #tcp_nopush     on;
    #keepalive_timeout  0;
    keepalive_timeout  65;
    #gzip  on;

server {
    listen 81;
    server_name milkov.su www.milkov.su;
    return 301 https://milkov.su$request_uri;
}

server {
        listen 433 ssl;
        server_name milkov.su;
        #SSL support
        include ssl.conf;
        location / {
            root   /opt/share/nginx/html;
            index  index.html index.htm;
        error_page   500 502 503 504  /50x.html;
        location = /50x.html {
            root   html;
            }
        }
}
</spoiler>
<spoiler title="etc/nginx/ssl.conf">
ssl_certificate /opt/etc/nginx/certs/milkov.su/fullchain.pem;
ssl_certificate_key /opt/etc/nginx/certs/milkov.su/privkey.pem;
ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA';
ssl_prefer_server_ciphers on;
ssl_dhparam /opt/etc/nginx/dhparams.pem;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 5m;
ssl_stapling on;

ื›ื“ื™ ืฉื”ืืชืจ ื™ืขื‘ื•ื“ ื“ืจืš https, ื”ืฉืชืžืฉืชื™ ื‘ืกืงืจื™ืคื˜ ืžื™ื•ื‘ืฉ ื”ื™ื“ื•ืข, ื”ืชืงื ืชื™ ืื•ืชื• ื‘ืืžืฆืขื•ืช ื”ื•ืจืื” ื–ื•. ืชื”ืœื™ืš ื–ื” ืœื ื’ืจื ืœืงืฉื™ื™ื, ืจืง ืžืขื“ืชื™ ืขืœ ื”ืขื•ื‘ื“ื” ืฉื‘ื˜ืงืกื˜ ืฉืœ ื”ืชืกืจื™ื˜ ืœืขื‘ื•ื“ื” ืขืœ ื”ื ืชื‘ ืฉืœื™ ืืชื” ืฆืจื™ืš ืœื”ืขื™ืจ ืืช ื”ืฉื•ืจื” ื‘ืงื•ื‘ืฅ /opt/etc/ssl/openssl.cnf:

[openssl_conf]
#engines=engines

ื•ืื ื™ ืžืฆื™ื™ืŸ ืฉื™ืฆื™ืจืช dhparams.pem ืขื ื”ืคืงื•ื“ื” "openssl dhparam -out dhparams.pem 2048" ื‘ื ืชื‘ ืฉืœื™ ืœื•ืงื— ื™ื•ืชืจ ืžืฉืขืชื™ื™ื, ืืœืžืœื ืžื—ื•ื•ืŸ ื”ื”ืชืงื“ืžื•ืช, ื”ื™ื™ืชื™ ืžืื‘ื“ ืืช ื”ืกื‘ืœื ื•ืช ื•ืžืคืขื™ืœ ืžื—ื“ืฉ.

ืœืื—ืจ ืงื‘ืœืช ื”ืื™ืฉื•ืจื™ื, ื”ืคืขืœ ืžื—ื“ืฉ ืืช nginx ืขื ื”ืคืงื•ื“ื” "/opt/etc/init.d/S80nginx restart". ื‘ืื•ืคืŸ ืขืงืจื•ื ื™, ื”ื”ื’ื“ืจื” ื”ื•ืฉืœืžื”, ืื‘ืœ ืื™ืŸ ืขื“ื™ื™ืŸ ืืชืจ - ืื ื ื›ื ื™ืก ืืช ื”ืงื•ื‘ืฅ index.html ืœืกืคืจื™ื™ืช /share/nginx/html, ื ืจืื” ืกื˜ืื‘.

index.html

<!DOCTYPE html>
<html>
<head>
<title>ะขะตัั‚ะพะฒะฐั ัั‚ั€ะฐะฝะธั‡ะบะฐ!</title>
<style>
    body {
        width: 35em;
        margin: 0 auto;
        font-family: Tahoma, Verdana, Arial, sans-serif;
    }
</style>
</head>
<body>
<h1>ะขะตัั‚ะพะฒะฐั ัั‚ั€ะฐะฝะธั‡ะบะฐ!</h1>
<p>ะญั‚ะพ ะฟั€ะพัั‚ะฐั ัั‚ะฐั‚ะธั‡ะตัะบะฐั ั‚ะตัั‚ะพะฒะฐั ัั‚ั€ะฐะฝะธั‡ะบะฐ, ะฐะฑัะพะปัŽั‚ะฝะพ ะฝะธั‡ะตะณะพ ะธะฝั‚ะตั€ะตัะฝะพะณะพ.</p>
</body>
</html>

ื›ื“ื™ ืœืžืงื ืžื™ื“ืข ื‘ืฆื•ืจื” ื™ืคื”, ืงืœ ื™ื•ืชืจ ืœืžื™ ืฉืื™ื ื• ืžืงืฆื•ืขืŸ ื›ืžื•ื ื™ ืœื”ืฉืชืžืฉ ื‘ืชื‘ื ื™ื•ืช ืžื•ื›ื ื•ืช; ืœืื—ืจ ื—ื™ืคื•ืฉ ืืจื•ืš ื‘ืงื˜ืœื•ื’ื™ื ืฉื•ื ื™ื, ืžืฆืืชื™ templatemo.com - ื™ืฉ ืžื‘ื—ืจ ื˜ื•ื‘ ืฉืœ ืชื‘ื ื™ื•ืช ื—ื™ื ืžื™ื•ืช ืฉืื™ื ืŸ ื“ื•ืจืฉื•ืช ื™ื™ื—ื•ืก (ื“ื‘ืจ ื ื“ื™ืจ ื‘ืื™ื ื˜ืจื ื˜; ืจื•ื‘ ื”ืชื‘ื ื™ื•ืช ื‘ืจื™ืฉื™ื•ืŸ ืžื—ื™ื™ื‘ื•ืช ืœืฉืžื•ืจ ืงื™ืฉื•ืจ ืœืžืฉืื‘ ืžืžื ื• ื”ื•ืฉื’ื•).

ืื ื• ื‘ื•ื—ืจื™ื ืชื‘ื ื™ืช ืžืชืื™ืžื” - ื™ืฉ ื›ืืœื” ืœืžื’ื•ื•ืŸ ืžืงืจื™ื, ื”ื•ืจื™ื“ื• ืืช ื”ืืจื›ื™ื•ืŸ ื•ืคื•ืจืงื• ืื•ืชื• ืœืกืคืจื™ื™ืช /share/nginx/html, ืชื•ื›ืœื• ืœืขืฉื•ืช ื–ืืช ืžื”ืžื—ืฉื‘, ื•ืื– ืœืขืจื•ืš ืืช ื”ืชื‘ื ื™ืช (ื›ืืŸ ืชืฆื˜ืจื›ื• ื™ื“ืข ืžื™ื ื™ืžืœื™ ืฉืœ HTML ื›ื“ื™ ืœื ืœืฉื‘ื•ืจ ืืช ื”ืžื‘ื ื”) ื•ืœื”ื—ืœื™ืฃ ืืช ื”ื’ืจืคื™ืงื” ื›ืคื™ ืฉืžื•ืฆื’ ื‘ืื™ื•ืจ ืœืžื˜ื”.

ืื™ืจื•ื— ืืชืจ ื‘ืจืื•ื˜ืจ ื”ื‘ื™ืชื™ ืฉืœืš

ืชืงืฆื™ืจ: ื”ื ืชื‘ ื“ื™ ืžืชืื™ื ืœืื™ืจื•ื— ืืชืจ ืงืœ ื‘ื•, ื‘ืื•ืคืŸ ืขืงืจื•ื ื™ - ืื ืืชื” ืœื ืžืฆืคื” ืœืขื•ืžืก ื’ื“ื•ืœ, ืืชื” ื™ื›ื•ืœ ื”ืชืงื ื” ื•-php, ื•ืœื”ืชื ืกื•ืช ื‘ืคืจื•ื™ืงื˜ื™ื ืžื•ืจื›ื‘ื™ื ื™ื•ืชืจ (ืื ื™ ืžืกืชื›ืœ ืขืœ nextcloud/owncloud, ื ืจืื” ืฉื™ืฉ ื”ืชืงื ื•ืช ืžื•ืฆืœื—ื•ืช ืขืœ ื—ื•ืžืจื” ื›ื–ื•). ื”ื™ื›ื•ืœืช ืœื”ืชืงื™ืŸ ื—ื‘ื™ืœื•ืช ืžื’ื“ื™ืœื” ืืช ื”ืชื•ืขืœืช ืฉืœื” - ืœืžืฉืœ, ื›ืฉื”ื™ื” ืฆื•ืจืš ืœื”ื’ืŸ ืขืœ ื™ืฆื™ืืช ื”-RDP ืฉืœ PC ื‘ืจืฉืช ืžืงื•ืžื™ืช, ื”ืชืงื ืชื™ knockd ืขืœ ื”ื ืชื‘ - ื•ื”ืขื‘ืจืช ืคื•ืจื˜ื™ื ืœืžื—ืฉื‘ ื ืคืชื—ื” ืจืง ืœืื—ืจ ื“ืคื™ืงืช ืคื•ืจื˜.

ืœืžื” ืจืื•ื˜ืจ ื•ืœื ืžื—ืฉื‘ ืจื’ื™ืœ? ื ืชื‘ ื”ื•ื ืื—ื“ ืžื—ืœืงื™ ื”ื—ื•ืžืจื” ื”ื‘ื•ื“ื“ื™ื ืฉืœ ื”ืžื—ืฉื‘ ืฉืขื•ื‘ื“ื™ื ืžืกื‘ื™ื‘ ืœืฉืขื•ืŸ ื‘ื“ื™ืจื•ืช ืจื‘ื•ืช; ื ืชื‘ ื‘ื™ืชื™ ื‘ื“ืจืš ื›ืœืœ ืฉืงื˜ ืœื—ืœื•ื˜ื™ืŸ ื•ืืชืจ ืงืœ ืขื ืคื—ื•ืช ืžืžืื” ื‘ื™ืงื•ืจื™ื ื‘ื™ื•ื ืœื ื™ืคืจื™ืข ืœื• ื›ืœืœ.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”