惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
云风的 BLOG
云风的 BLOG
G
Google Developers Blog
S
SegmentFault 最新的问题
罗磊的独立博客
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
爱范儿
爱范儿
博客园 - 三生石上(FineUI控件)
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
DataBreaches.Net
F
Fortinet All Blogs
TaoSecurity Blog
TaoSecurity Blog
D
Docker
C
Cybersecurity and Infrastructure Security Agency CISA
K
Kaspersky official blog
宝玉的分享
宝玉的分享
腾讯CDC
Google Online Security Blog
Google Online Security Blog
Recorded Future
Recorded Future
T
The Exploit Database - CXSecurity.com
T
The Blog of Author Tim Ferriss
V
V2EX
S
Securelist
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
C
CERT Recently Published Vulnerability Notes
A
Arctic Wolf
Scott Helme
Scott Helme
L
LINUX DO - 热门话题
Y
Y Combinator Blog
P
Proofpoint News Feed
T
Tor Project blog
AWS News Blog
AWS News Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
The Last Watchdog
The Last Watchdog
博客园 - 聂微东
T
Threat Research - Cisco Blogs
B
Blog
Attack and Defense Labs
Attack and Defense Labs
L
Lohrmann on Cybersecurity
C
CXSECURITY Database RSS Feed - CXSecurity.com
阮一峰的网络日志
阮一峰的网络日志
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
IT之家
IT之家
N
News and Events Feed by Topic
博客园 - 司徒正美
H
Help Net Security
C
Cisco Blogs
C
Check Point Blog
S
Secure Thoughts

博客园 - bluce chen

swif debounce实现 oculus quest2的思考 博文阅读密码验证 - 博客园 用户中心 - 博客园 Share架构的一些心得 flutter输入颜色枚举卡顿假死 n2n网络环境搭建 p2p技术之n2n源码核心简单分析一 分享一个14年写的用户管理类-swift版 MIUI通过xposed自动设置root权限 基于xposed实现android注册系统服务,解决跨进程共享数据问题 2017 UICollectionView swift2模版 angularjs 分页精华代码 Reveal分析IOS界面,plist文件读取 php嵌套数组递归搜索返回数组key 结合阿里云服务器,设置家中jetson tk1随时远程登陆 sqlite3 根据实体自动生成建表语句 prism4 StockTrader RI 项目分析一些体会2
https点对点转发响应示意图
bluce chen · 2019-12-04 · via 博客园 - bluce chen
	curl 			nginx(proxy_connect)			nginx(NAS)
	 |  					  |							  |
	 |  					  |							  |
(1)	 |-- CONNECT 443 -> 	  |							  |
	 |  					  |							  |
	 |						  |---- [ TCP connection ]--->|
	 |  					  |							  |
	 |  					  |							  |
(2)  |<- HTTP/1.1 200 --------|							  |
	 |  					  |							  |
	 | 建立连接成功 |							  |
	 |  					  							  |
	   ========= 内网隧道通讯(依赖组件,我这里使用n2n) =======
	 |  					    						  |
	 |  					  							  |
	 |  					  |							  |
	 |   [ SSL stream  ]      |							  |
(3)  |---[ GET / HTTP/1.1] -->|     [ SSL stream ]  	  |
	 |   [ Host: xxxx.com]    |---  [ GET / HTTP/1.1 ] -->.
	 |  					  |		[ Host: xxxx.com ]	  |
	 |  					  |							  |
	 |  					  |							  |
	 |  					  |							  |
	 |  					  |							  |
	 |  					  |		[ SSL stream ]		  |
	 |  [ SSL stream ]	  	  |	<--[ HTTP/1.1 200 OK  ]---'
	 |<--[ HTTP/1.1 200 OK ]--|		[ < html page >    ]  |
	 |  [ < html page > ]     |							  |
	 |  					  |							  |
	 |  					  |							  |

 nginx转发配置参考,注意该nginx服务器需要配置hosts指向

server {
    listen       80;
    server_name  xxx.com www.xxx.com;
    return       301 https://www.xxx.com$request_uri;
}

server {
    listen      443 ssl;
    server_name  xxx.com;
    return       301 https://www.xxx.com$request_uri;

    ssl on;
    ssl_session_cache    shared:SSL:1m;
    ssl_session_timeout  5m;

    ssl_ciphers  HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers  on;
    ssl_certificate /usr/local/nginx/conf/keys/xxx.com.pem;
    ssl_certificate_key /usr/local/nginx/conf/xxx.com.key;
}

server {
    listen      443 ssl;
    server_name  www.xxx.com;
    charset utf-8;

    error_log /var/log/nginx/xxx.com.error_log info;
    access_log /var/log/nginx/xxx.com.access_log json_log;

    allow  all;
    autoindex off;
    concat on;
    concat_max_files 40;

    ssl on;
    ssl_session_cache    shared:SSL:1m;
    ssl_session_timeout  5m;

    ssl_ciphers  HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers  on;
    ssl_certificate /usr/local/nginx/conf/keys/xxx.com.pem;
    ssl_certificate_key /usr/local/nginx/conf/keys/xxx.com.key;
    location / {
        proxy_pass https://www.xxx.com:443;
    }
}