ืžื”ื“ื•ืจืช nginx 1.16.0

ืœืื—ืจ ืฉื ื” ืฉืœ ืคื™ืชื•ื— ืžื™ื•ืฆื’ ืขืœ ื™ื“ื™ ืขื ืฃ ื™ืฆื™ื‘ ื—ื“ืฉ ืฉืœ ืฉืจืช HTTP ื‘ืขืœ ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื ื•ืฉืจืช ืคืจื•ืงืกื™ ืžืจื•ื‘ื” ืคืจื•ื˜ื•ืงื•ืœื™ื 1.16.0, ืฉืงืœื˜ื” ืืช ื”ืฉื™ื ื•ื™ื™ื ืฉื”ืฆื˜ื‘ืจื• ื‘ืชื•ืš ื”ืขื ืฃ ื”ืจืืฉื™ 1.15.x. ื‘ืขืชื™ื“, ื›ืœ ื”ืฉื™ื ื•ื™ื™ื ื‘ืขื ืฃ ื”ื™ืฆื™ื‘ 1.16 ื™ื”ื™ื• ืงืฉื•ืจื™ื ืœื‘ื™ื˜ื•ืœ ืฉื’ื™ืื•ืช ื•ืคื’ื™ืขื•ื™ื•ืช ื—ืžื•ืจื•ืช. ื‘ืงืจื•ื‘ ื™ื•ื•ืฆืจ ื”ืกื ื™ืฃ ื”ืจืืฉื™ ืฉืœ nginx 1.17, ืฉื‘ืชื•ื›ื• ื™ืžืฉืš ื”ืคื™ืชื•ื— ืฉืœ ืชื›ื•ื ื•ืช ื—ื“ืฉื•ืช. ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ืจื’ื™ืœื™ื ืฉืื™ืŸ ืœื”ื ืืช ื”ืžืฉื™ืžื” ืœื”ื‘ื˜ื™ื— ืชืื™ืžื•ืช ืขื ืžื•ื“ื•ืœื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™, ืžื•ืžืœืฅ ื”ืฉืชืžืฉ ื‘ืกื ื™ืฃ ื”ืจืืฉื™, ืฉืขืœ ื‘ืกื™ืกื• ื ื•ืฆืจื•ืช ืžื”ื“ื•ืจื•ืช ืฉืœ ื”ืžื•ืฆืจ ื”ืžืกื—ืจื™ Nginx Plus ื›ืœ ืฉืœื•ืฉื” ื—ื•ื“ืฉื™ื.

ื”ืฉื™ืคื•ืจื™ื ื”ื‘ื•ืœื˜ื™ื ื‘ื™ื•ืชืจ ืฉื ื•ืกืคื• ื‘ืžื”ืœืš ื”ืคื™ืชื•ื— ืฉืœ ืขื ืฃ 1.15.x ื‘ืžืขืœื” ื”ื–ืจื:

  • ื ื•ืกืคื” ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืžืฉืชื ื™ื ื‘ื”ื ื—ื™ื•ืช 'ssl_certificate'ื™'ssl_certificate_key', ืฉื‘ื• ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื›ื“ื™ ืœื˜ืขื•ืŸ ื‘ืื•ืคืŸ ื“ื™ื ืžื™ ืื™ืฉื•ืจื™ื;
  • ื ื•ืกืคื” ื”ื™ื›ื•ืœืช ืœื˜ืขื•ืŸ ืชืขื•ื“ื•ืช SSL ื•ืžืคืชื—ื•ืช ืกื•ื“ื™ื™ื ืžืžืฉืชื ื™ื ืœืœื ืฉื™ืžื•ืฉ ื‘ืงื‘ืฆื™ ื‘ื™ื ื™ื™ื;
  • ื‘ื‘ืœื•ืง"ื‘ึผึฐืžึทืขึฒืœึถื” ื”ึทื–ึถืจึถืยป ื”ื•ืจืื” ื—ื“ืฉื” ื™ื•ืฉืžื” ยซืืงืจืื™", ื‘ืขื–ืจืชื• ื ื™ืชืŸ ืœืืจื’ืŸ ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ืขื ื‘ื—ื™ืจื” ืืงืจืื™ืช ืฉืœ ืฉืจืช ืœื”ืขื‘ืจืช ื”ื—ื™ื‘ื•ืจ;
  • ื‘ืžื•ื“ื•ืœ ngx_stream_ssl_preread ืžืฉืชื ื” ืžื™ื•ืฉื $ssl_preread_protocol,
    ืืฉืจ ืžืฆื™ื™ื ืช ืืช ื”ื’ืจืกื” ื”ื’ื‘ื•ื”ื” ื‘ื™ื•ืชืจ ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ SSL/TLS ืฉื”ืœืงื•ื— ืชื•ืžืš ื‘ื•. ื”ืžืฉืชื ื” ืžืืคืฉืจ ืœื™ืฆื•ืจ ืชืฆื•ืจื•ืช ืœื’ื™ืฉื” ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœื™ื ืฉื•ื ื™ื ืขื ื•ื‘ืœื™ SSL ื“ืจืš ื™ืฆื™ืืช ืจืฉืช ืื—ืช ื‘ืขืช ื”ืขื‘ืจืช ืชืขื‘ื•ืจื” ื‘ืืžืฆืขื•ืช ืคืจื•ืงืกื™ ื‘ืืžืฆืขื•ืช ืžื•ื“ื•ืœื™ http ื•-stream. ืœื“ื•ื’ืžื”, ื›ื“ื™ ืœืืจื’ืŸ ื’ื™ืฉื” ื‘ืืžืฆืขื•ืช SSH ื•-HTTPS ื“ืจืš ื™ืฆื™ืื” ืื—ืช, ื ื™ืชืŸ ืœื”ืขื‘ื™ืจ ืืช ื™ืฆื™ืื” 443 ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืœ-SSH, ืืš ืื ื’ืจืกืช ื”-SSL ืžื•ื’ื“ืจืช, ื”ืขื‘ืจ ืœ-HTTPS.

  • ืžืฉืชื ื” ื—ื“ืฉ ื ื•ืกืฃ ืœืžื•ื“ื•ืœ ื‘ืžืขืœื” ื”ื–ืจื "$upstream_bytes_sent", ื”ืžืฆื™ื’ ืืช ืžืกืคืจ ื”ื‘ืชื™ื ืฉื”ื•ืขื‘ืจื• ืœืฉืจืช ื”ืงื‘ื•ืฆื”;
  • ืœืžื•ื“ื•ืœ ื–ืจื ื‘ืชื•ืš ื”ืคืขืœื” ืื—ืช, ื ื•ืกืคื” ื”ื™ื›ื•ืœืช ืœืขื‘ื“ ืžืกืคืจ ื“ื’ื™ืžื•ืช UDP ื ื›ื ืกื•ืช ืžื”ืœืงื•ื—;
  • ื”ื”ื ื—ื™ื”"proxy_requests", ืžืฆื™ื™ืŸ ืืช ืžืกืคืจ ื“ื’ืžื™ ื”ื ืชื•ื ื™ื ืฉื”ืชืงื‘ืœื• ืžื”ืœืงื•ื—, ื›ืืฉืจ ืžื’ื™ืขื™ื ืืœื™ื”ื ืชื•ืกืจ ื”ืงื™ืฉื•ืจ ื‘ื™ืŸ ื”ืœืงื•ื— ืœืกืฉืŸ UDP ื”ืงื™ื™ื. ืœืื—ืจ ืงื‘ืœืช ื”ืžืกืคืจ ืฉืฆื•ื™ืŸ ืฉืœ ื’ืจื ื ืชื•ื ื™ื, ื’ืจื ื”ื ืชื•ื ื™ื ื”ื‘ื ื”ืžืชืงื‘ืœ ืžืื•ืชื• ืœืงื•ื— ืžืชื—ื™ืœ ื”ืคืขืœื” ื—ื“ืฉื”;
  • ืœื”ื•ืจืืช ื”ื”ืื–ื ื” ื™ืฉ ื›ืขืช ืืช ื”ื™ื›ื•ืœืช ืœืฆื™ื™ืŸ ื˜ื•ื•ื—ื™ ื™ืฆื™ืื•ืช;
  • ื ื•ืกืคื” ื”ื ื—ื™ื”"ssl_early_dataยป ื›ื“ื™ ืœื”ืคืขื™ืœ ืืช ื”ืžืฆื‘ 0-RTT ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-TLSv1.3, ื”ืžืืคืฉืจ ืœืš ืœืฉืžื•ืจ ืคืจืžื˜ืจื™ื ืฉืœ ื—ื™ื‘ื•ืจ TLS ืฉื ืงื‘ืขื• ื‘ืขื‘ืจ ื•ืœื”ืคื—ื™ืช ืืช ืžืกืคืจ ื”-RTTs ืœ-2 ื‘ืขืช ื—ื™ื“ื•ืฉ ื—ื™ื‘ื•ืจ ืฉื ื•ืฆืจ ื‘ืขื‘ืจ;
  • ื”ื ื—ื™ื•ืช ื—ื“ืฉื•ืช ื ื•ืกืคื• ืœื”ื’ื“ืจืช Keepalive ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ื™ื•ืฆืื™ื (ื”ืคืขืœื” ืื• ื”ืฉื‘ืชื” ืฉืœ ืืคืฉืจื•ืช SO_KEEPALIVE ืขื‘ื•ืจ ืฉืงืขื™ื):

    • ยซproxy_socket_keepalive" - ืžื’ื“ื™ืจ ืืช ื”ืชื ื”ื’ื•ืช "TCP keepalive" ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ื™ื•ืฆืื™ื ืœืฉืจืช ื”-proxy;
    • ยซfastcgi_socket_keepalive" - ืžื’ื“ื™ืจ ืืช ื”ืชื ื”ื’ื•ืช "TCP keepalive" ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ื™ื•ืฆืื™ื ืœืฉืจืช FastCGI;
    • ยซgrpc_socket_keepalive" - ืžื’ื“ื™ืจ ืืช ื”ืชื ื”ื’ื•ืช "TCP keepalive" ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ื™ื•ืฆืื™ื ืœืฉืจืช gRPC;
    • ยซmemcached_socket_keepalive" - ืžื’ื“ื™ืจ ืืช ื”ืชื ื”ื’ื•ืช "TCP keepalive" ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ื™ื•ืฆืื™ื ืœืฉืจืช ื”-memcached;
    • ยซscgi_socket_keepalive" - ืžื’ื“ื™ืจ ืืช ื”ืชื ื”ื’ื•ืช "TCP keepalive" ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ื™ื•ืฆืื™ื ืœืฉืจืช SCGI;
    • ยซuwsgi_socket_keepalive" - ืžื’ื“ื™ืจ ืืช ื”ืชื ื”ื’ื•ืช "TCP keepalive" ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ื ื™ื•ืฆืื™ื ืœืฉืจืช uwsgi.
  • ื‘ื”ื ื—ื™ื”"limit_req" ื”ื•ืกื™ืฃ ืคืจืžื˜ืจ ื—ื“ืฉ "ืขื™ื›ื•ื‘", ืฉืงื•ื‘ืข ื’ื‘ื•ืœ ืฉืื—ืจื™ื• ื‘ืงืฉื•ืช ืžื™ื•ืชืจื•ืช ืžืชืขื›ื‘ื•ืช;
  • ื”ื ื—ื™ื•ืช ื—ื“ืฉื•ืช "keepalive_timeout" ื•-"keepalive_requests" ื ื•ืกืคื• ืœื‘ืœื•ืง "upstream" ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืžื’ื‘ืœื•ืช ืขื‘ื•ืจ Keepalive;
  • ื”ื”ื ื—ื™ื” "ssl" ื”ื•ืฆืื” ืžืฉื™ืžื•ืฉ, ื•ื”ื•ื—ืœืฃ ื‘ืคืจืžื˜ืจ "ssl" ื‘ื”ื ื—ื™ื™ืช "ื”ืื–ื ื”". ืื™ืฉื•ืจื™ SSL ื—ืกืจื™ื ืžื–ื•ื”ื™ื ื›ืขืช ื‘ืฉืœื‘ ื‘ื“ื™ืงืช ื”ืชืฆื•ืจื” ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ื”ื ื—ื™ื™ืช "ื”ืื–ื ื”" ืขื ื”ืคืจืžื˜ืจ "ssl" ื‘ื”ื’ื“ืจื•ืช;
  • ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ื”ื ื—ื™ื™ืช reset_timedout_connection, ื”ื—ื™ื‘ื•ืจื™ื ื ืกื’ืจื™ื ื›ืขืช ืขื ืงื•ื“ 444 ื›ืืฉืจ ื”ื–ืžืŸ ื”ืงืฆื•ื‘ ื™ืคื•ื’;
  • ืฉื’ื™ืื•ืช SSL "http request", "https proxy request", "ืคืจื•ื˜ื•ืงื•ืœ ืœื ื ืชืžืš" ื•-"ื’ืจืกื” ื ืžื•ื›ื” ืžื“ื™" ืžื•ืฆื’ื•ืช ื›ืขืช ื‘ื™ื•ืžืŸ ืขื ื”ืจืžื” "info" ื‘ืžืงื•ื "crit";
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืฉื™ื˜ืช ื”ืกืงืจ ื‘ืžืขืจื›ื•ืช Windows ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-Windows Vista ื•ืื™ืœืš;
  • ืืคืฉืจื•ืช ืฉื™ืžื•ืฉ TLSv1.3 ื›ืืฉืจ ื‘ื•ื ื™ื ืขื ืกืคืจื™ื™ืช BoringSSL, ืœื ืจืง ืขื OpenSSL.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”