无CA签名 生成证书 1 2 3 4 5 6 openssl req -x509 -nodes -days 3650 -newkey rsa:2048 -keyout domain.key -out domain.crt \ -addext "subjectAltName=DNS:www.mkl.io,DNS:*.mkl.io" \ -subj '/C=CN/ST=Guangdong/L=Shenzhen/O=mkl/OU=IT/CN=mkl.io' # 查看证书 openssl x509 -in domain.crt -noout -text nginx配置参考 ssl_certificate /path/domain.crt; ssl_certificate_key /path/domain.key; CA签名 生成证书签发机构证