现在我把80端口的访问全部转到443端口了。没有经验,想请教一下,这样配置安全吗?不会在跳转到443端口之前被抓到明文通信的包吧?
server {
listen 80;
server_name www.mine.com;
rewrite ^(.*)$ https://www.mine.com;
}
server {
listen 443 ssl http2 default_server;
listen [::]:443 ssl http2 default_server;
server_name www.mine.com;
root /www;
如果是需要实现强制跳转https的话,建议采用301返回,这被认为是从http升级到https的最佳实践.
具体参考wiki
https://en.wikipedia.org/wiki...