欢迎来到小七猫的博客~!
品种:银渐层-银点
爱好:睡觉、吃饭
被揍频率:2/day
我喜欢的东西:
- 猫:4 年养猫经验
- 编程:6 年编程经验
- 吉他:13 年吉他演奏经验
品种:银渐层-银点
爱好:睡觉、吃饭
被揍频率:2/day
_lan(443 HTTPS 站点)、_redirect2ssl(80 强制跳转 HTTPS),全部删除彻底禁用 HTTPSroot@IWrt:~# uci show nginx
nginx.global=main
nginx.global.uci_enable='true'
nginx._lan=server
nginx._lan.listen='443 ssl default_server' '[::]:443 ssl default_server'
nginx._lan.server_name='_lan'
nginx._lan.include='restrict_locally' 'conf.d/*.locations'
nginx._lan.uci_manage_ssl='self-signed'
nginx._lan.ssl_certificate='/etc/nginx/conf.d/_lan.crt'
nginx._lan.ssl_certificate_key='/etc/nginx/conf.d/_lan.key'
nginx._lan.ssl_session_cache='shared:SSL:32k'
nginx._lan.ssl_session_timeout='64m'
nginx._lan.access_log='off; # logd openwrt'
nginx._redirect2ssl=server
nginx._redirect2ssl.listen='80' '[::]:80'
nginx._redirect2ssl.server_name='_redirect2ssl'
nginx._redirect2ssl.return='302 https://hostrequest_uri'
http_luci 站点仅监听 IPv4/IPv6 80 端口,无 443 端口 https 监听restrict_locally 仅允许内网访问 LuCI 后台,外网拦截# 1. 删除原生HTTPS站点、80转HTTPS跳转站点,彻底清除443与强制跳转
uci delete nginx._lan # 如果需要 https,可以不删除 _lan_
uci delete nginx._redirect2ssl
#!/bin/bash
# 1. 创建命名server段 https_lan
uci set nginx._lan=server
# 2. 监听443 SSL IPv4 + IPv6
uci set nginx._lan.listen='443 ssl default_server'
uci add_list nginx._lan.listen='[::]:443 ssl default_server'
# 3. 站点标识
uci set nginx._lan.server_name='_lan'
# 4. 内网限制 + LuCI路由转发(和原生_lan一致)
uci set nginx._lan.include='restrict_locally'
uci add_list nginx._lan.include='conf.d/*.locations'
# 5. 自动生成自签SSL证书
uci set nginx._lan.uci_manage_ssl='self-signed'
# 6. 证书路径(uci会自动生成,无需手动改)
uci set nginx._lan.ssl_certificate='/etc/nginx/conf.d/_lan.crt'
uci set nginx._lan.ssl_certificate_key='/etc/nginx/conf.d/_lan.key'
# 7. SSL会话缓存配置
uci set nginx._lan.ssl_session_cache='shared:SSL:32k'
uci set nginx._lan.ssl_session_timeout='64m'
# 8. 关闭访问日志
uci set nginx._lan.access_log='off; # logd openwrt'
# 保存uci配置
uci commit nginx
# 重启nginx,自动生成证书并加载HTTPS站点
service nginx restart
# 校验配置
uci show nginx.https_lan
nginx -T -c /etc/nginx/uci.conf
#!/bin/sh
# 1. 创建http_only服务段(类型server)
uci set nginx.http_only=server
# 2. 配置监听端口:IPv4 80 + IPv6 [::]:80,仅HTTP无SSL
uci set nginx.http_only.listen='80'
uci add_list nginx.http_only.listen='[::]:80'
# 3. 自定义站点标识server_name
uci set nginx.http_only.server_name='http_only'
# 4. 引入内网IP限制规则(仅局域网能访问路由器后台)
# 引入LuCI页面必需的location转发规则,缺失会404无法打开后台
uci set nginx.http_only.include='restrict_locally'
uci add_list nginx.http_only.include='conf.d/*.locations'
# 5. 当前站点关闭访问日志
uci set nginx.http_only.access_log='off'
# 6. 全局关闭Nginx访问日志(双重关闭,彻底不生成日志)
uci set nginx.global.access_log='off'
# 7. 保存所有UCI配置写入数据库
uci commit nginx
# 8. 重启Nginx重载配置生成新 /etc/nginx/uci.conf
service nginx restart
# 9. 校验最终uci配置(可选,查看是否写入成功)
uci show nginx
# 10. 校验Nginx配置语法(可选,排查报错)
nginx -T -c /etc/nginx/uci.conf
nginx.global=main
nginx.global.uci_enable='true'
nginx.global.access_log='off'
### https 看情况
nginx._lan=server
nginx._lan.listen='443 ssl default_server' '[::]:443 ssl default_server'
nginx._lan.server_name='_lan'
nginx._lan.include='restrict_locally' 'conf.d/*.locations'
nginx._lan.uci_manage_ssl='self-signed'
nginx._lan.ssl_certificate='/etc/nginx/conf.d/_lan.crt'
nginx._lan.ssl_certificate_key='/etc/nginx/conf.d/_lan.key'
nginx._lan.ssl_session_cache='shared:SSL:32k'
nginx._lan.ssl_session_timeout='64m'
nginx._lan.access_log='off; # logd openwrt'
### https 看情况
nginx.http_only=server
nginx.http_only.listen='80' '[::]:80'
nginx.http_only.server_name='http_only'
nginx.http_only.include='restrict_locally' 'conf.d/*.locations'
nginx.http_only.access_log='off'
listen6:OpenWrt Nginx UCI 无 listen6,IPv6 端口统一用 listen '[::]:80',使用 listen6 会报 nginx 语法错误enabled='0' 无效:Nginx 不识别 enabled 指令,直接 uci delete 删除 HTTPS 段是唯一彻底禁用方案uci add nginx server http_luci,不能颠倒参数顺序add_listservice nginx restart,才会重新渲染 /etc/nginx/uci.conf 生效