Daim ntawv pov thawj HTTPS pub dawb: cov lus qhia kom tau txais

Cov txheej txheem:

Daim ntawv pov thawj HTTPS pub dawb: cov lus qhia kom tau txais
Daim ntawv pov thawj HTTPS pub dawb: cov lus qhia kom tau txais
Anonim

Yog tias koj sau cov ntaub ntawv tseem ceeb ntawm koj lub vev xaib (xws li email thiab password), ces koj yuav tsum muaj kev nyab xeeb. Ib txoj hauv kev zoo tshaj plaws los ua kom koj tus kheej muaj kev nyab xeeb yog ua kom muaj daim ntawv pov thawj HTTPS, tseem hu ua SSL (Secure Sockets Layers), kom txhua cov ntaub ntawv mus thiab los ntawm koj lub server tau txais kev nkag mus. Daim ntawv pov thawj HTTPS tiv thaiv hackers los ntawm kev nyiag koj cov neeg siv cov ntaub ntawv tsis pub lwm tus paub thaum nws khaws cia hauv Is Taws Nem. Lawv yuav muaj kev nyab xeeb thaum lawv pom daim ntawv pov thawj HTTPS thaum nkag mus rau koj qhov chaw - paub tias nws tau tiv thaiv los ntawm daim ntawv pov thawj kev nyab xeeb.

Cov txiaj ntsig ntawm daim ntawv pov thawj

Qhov zoo tshaj plaws txog daim ntawv pov thawj SSL, ib yam li HTTPS, yog qhov yooj yim rau kev teeb tsa, thiab thaum ua tiav, koj yuav tsum tau coj cov neeg siv daim ntawv pov thawj HTTPS es tsis txhob HTTP. Yog tias koj sim nkag mus rau koj qhov chaw los ntawm kev tso https:// nyob rau hauv pem hauv ntej ntawm koj cov URLs tam sim no, koj yuav tau txais HTTPS daim ntawv pov thawj yuam kev. Qhov no yog vim koj tsis tau teeb tsa HTTPS SSL daim ntawv pov thawj. Tab sis tsis txhob txhawj, peb mam li teeb tsa tam sim ntawd!

Koj cov neeg tuaj saib yuav muaj kev nyab xeeb dua ntawm koj lub xaib thaum lawv pom daim ntawv pov thawj HTTPS thaum nkag mus rau koj lub xaib- paub tias nws muaj kev tiv thaiv los ntawm daim ntawv pov thawj kev ruaj ntseg.

HTTPS daim ntawv pov thawj
HTTPS daim ntawv pov thawj

HTTPS yog dab tsi?

HTTP lossis HTTPS tau tshwm sim thaum pib ntawm txhua lub vev xaib URL hauv lub vev xaib browser. HTTP stands rau Hypertext Transfer Protocol thiab S hauv HTTPS stands rau Secure. Feem ntau, qhov no piav qhia txog cov txheej txheem uas cov ntaub ntawv xa tuaj ntawm koj tus browser thiab lub vev xaib koj tab tom saib.

Daim ntawv pov thawj HTTPS kom ntseeg tau tias txhua qhov kev sib txuas lus ntawm koj tus browser thiab lub vev xaib koj saib yog encrypted. Qhov no txhais tau tias nws muaj kev nyab xeeb. Tsuas yog cov tau txais thiab xa cov khoos phis tawj tuaj yeem pom cov ntaub ntawv thaum cov ntaub ntawv raug xa mus (lwm tus tuaj yeem nkag mus tau, tab sis tsis tuaj yeem nyeem nws). Ntawm qhov chaw nyab xeeb, lub vev xaib browser nthuav tawm lub cim xauv hauv thaj chaw URL kom ceeb toom koj.

HTTPS yuav tsum nyob rau hauv ib lub vev xaib uas sau cov passwords, them nyiaj, cov ntaub ntawv kho mob lossis lwm yam ntaub ntawv rhiab heev. Tab sis ua li cas yog tias koj tuaj yeem tau txais daim ntawv pov thawj SSL dawb thiab siv tau rau koj lub npe?

Kev tiv thaiv lub vev xaib ua haujlwm li cas?

Txhawm rau pab kom HTTPS daim ntawv pov thawj kev nyab xeeb, koj yuav tsum tau nruab SSL (Secure Socket Layer). Nws muaj tus yuam sij rau pej xeem uas yuav tsum tau pib qhov kev sib kho kom zoo. Thaum thov HTTPS txuas rau nplooj ntawv web, lub xaib xa daim ntawv pov thawj SSL rau koj tus browser. Lawv mam li pib ua "SSL handshake", uas koom nrog kev sib koom "kev zais cia" los tsim kom muaj kev sib txuas ruaj ntseg ntawm koj tus browser thiab lub vev xaib.

HTTPS daim ntawv pov thawj
HTTPS daim ntawv pov thawj

Standard thiab Extended SSL

Yog tias lub xaib siv daim ntawv pov thawj SSL tus qauv, koj yuav pom lub cim xauv hauv thaj chaw URL ntawm koj tus browser. Yog siv daim ntawv pov thawj Extended Validation (EV), qhov chaw nyob bar lossis URL yuav ntsuab. EV SSL cov qauv zoo dua rau cov qauv SSL. EV SSL muab pov thawj ntawm tus tswv ntawm tus tswv. Tau txais daim ntawv pov thawj EV SSL tseem xav kom cov neeg thov nkag mus los ntawm cov txheej txheem tshuaj xyuas nruj kom paub tseeb tias lawv qhov tseeb thiab cov tswv cuab.

Yuav ua li cas yog tias koj siv HTTPS yam tsis muaj daim ntawv pov thawj?

Txawm tias koj lub vev xaib tsis lees txais lossis qhia cov ntaub ntawv rhiab, muaj ntau qhov laj thawj vim li cas koj thiaj li xav kom muaj lub vev xaib ruaj ntseg thiab siv daim ntawv pov thawj SSL dawb thiab siv tau rau koj lub npe.

Kev ua tau zoo. SSL tuaj yeem txhim kho lub sijhawm nws siv los thauj nplooj ntawv.

Tshawb nrhiav cav optimization (SEO). Google lub hom phiaj yog ua kom lub vev xaib muaj kev nyab xeeb thiab nyab xeeb rau txhua tus, tsis yog cov neeg siv Google Chrome, Gmail, thiab Drive, piv txwv li. Lub tuam txhab tau hais tias kev ruaj ntseg yuav yog qhov tseem ceeb hauv lawv qhov chaw nyob hauv cov txiaj ntsig tshawb nrhiav. Txog tam sim no tsis txaus. Txawm li cas los xij, yog tias koj muaj lub vev xaib ruaj ntseg thiab koj cov neeg sib tw tsis ua, koj lub xaib yuav nyob qib siab dua, uas yuav tsim nyog los ua kom nws muaj koob meej los ntawm nplooj ntawv tshawb fawb.

Yog tias koj lub xaib tsis ruaj ntseg thiab khaws cov passwords lossis credit cards, cov neeg siv ntawm Chrome 56 (tso tawm Lub Ib Hlis 2017) yuav pom cov lus ceeb toom tiastias qhov chaw tsis nyab xeeb. Cov neeg tuaj saib tsis paub txog kev siv thev naus laus zis (feem ntau cov neeg siv lub vev xaib) yuav ceeb toom kom pom "HTTPS daim ntawv pov thawj yuam kev" lub thawv thiab tawm hauv koj lub xaib vim lawv tsis nkag siab tias nws txhais li cas. Ntawm qhov tod tes, yog tias koj lub xaib muaj kev nyab xeeb, nws tuaj yeem ua rau cov neeg tuaj saib tau yooj yim dua, ua rau lawv muaj peev xwm ua tiav daim ntawv sau npe lossis tawm lus hauv koj lub xaib. Google muaj txoj kev npaj mus sij hawm ntev los qhia txhua qhov chaw HTTP tsis muaj kev nyab xeeb hauv Chrome.

HTTPS Certificate
HTTPS Certificate

Kuv tuaj yeem tau txais daim ntawv pov thawj HTTPS dawb nyob qhov twg?

Koj tau txais daim ntawv pov thawj SSL los ntawm daim ntawv pov thawj txoj cai. Cov ntawv pov thawj zoo li no siv tau rau 90 hnub, tab sis kev rov ua dua 60 hnub tau pom zoo. Qee qhov chaw dawb uas ntseeg tau:

  • Cloudflare: Dawb rau tus kheej lub vev xaib thiab blogs.
  • FreeSSL: pub dawb rau cov tsis muaj txiaj ntsig thiab kev pib ua haujlwm tam sim no; tsis tuaj yeem yog Symantec, Thawte, GeoTrust, lossis RapidSSL tus neeg siv khoom.
  • StartSSL: Cov ntawv pov thawj siv tau rau 1 txog 3 xyoos.
  • GoDaddy: Daim ntawv pov thawj rau cov haujlwm qhib, siv tau 1 xyoos.

Daim ntawv pov thawj hom thiab lub sijhawm siv tau nyob ntawm qhov chaw. Feem ntau cov tub ceev xwm muab cov qauv SSL daim ntawv pov thawj dawb thiab them nqi rau EV SSL daim ntawv pov thawj yog tias lawv muab rau lawv. Cloudflare muaj cov phiaj xwm pub dawb thiab them nyiaj thiab ntau yam kev xaiv ntxiv.

HTTPS daim ntawv pov thawj
HTTPS daim ntawv pov thawj

Yuav tsum xav txog dab tsi thaum tau txaisSSL daim ntawv pov thawj?

Google pom zoo ib daim ntawv pov thawj nrog tus yuam sij 2048-ntsis ntawm no. Yog tias koj twb muaj daim ntawv pov thawj 1024-ntsis uas tsis muaj zog, nws pom zoo kom hloov kho nws.

Koj yuav tsum tau txiav txim siab yog tias koj xav tau ib qho, ntau lub npe lossis daim ntawv pov thawj wildcard:

  1. Ib daim ntawv pov thawj yuav siv rau ib lub npe (xws li www.example.com).
  2. Daim ntawv pov thawj ntau lub npe yuav siv rau ntau lub npe zoo (xws li www.example.com, cdn.example.com, example.co.uk).
  3. daim ntawv pov thawj Wildcard yuav raug siv rau qhov chaw ruaj ntseg nrog ntau lub subdomains dynamic (piv txwv li a.example.com, b.example.com).
ssl daim ntawv pov thawj https
ssl daim ntawv pov thawj https

Kuv yuav nruab daim ntawv pov thawj SSL li cas?

Koj lub vev xaib tuaj yeem nruab daim ntawv pov thawj dawb lossis them nqi. Qee tus tswv yeej muaj qhov kev xaiv rau nruab Let's Encrypt hauv lawv tus kheej cPanel, uas ua rau tej yam yooj yim dua. Nug koj tus tswv tsev tam sim no lossis nrhiav ib qho uas muaj kev txhawb nqa ncaj qha rau Let's Encrypt. Yog tias tus tswv tsev tsis muab qhov kev pabcuam no, koj lub tuam txhab saib xyuas lub vev xaib lossis tus tsim tawm tuaj yeem nruab daim ntawv pov thawj rau koj. Koj yuav tsum tau npaj rau qhov tseeb tias koj yuav tau rov qab daim ntawv pov thawj ntau zaus. Tshawb xyuas lub sijhawm nrog daim ntawv pov thawj.

HTTPS daim ntawv pov thawj
HTTPS daim ntawv pov thawj

Yuav ua li cas ntxiv?

Tom qab tau txais thiab txhim kho daim ntawv pov thawj SSL, koj yuav tsum tswj hwm SSL ntawm qhov chaw. Ntxiv dua thiab, koj tuaj yeem nug koj lub vev xaib, lub tuam txhab pabcuam, lossistus tsim tawm los ua qhov haujlwm no. Txawm li cas los xij, yog tias koj xav ua koj tus kheej thiab koj lub xaib yog siv los ntawm WordPress, koj tuaj yeem ua li ntawd los ntawm rub tawm, txhim kho thiab siv lub plugin. Nrog rau qhov kev xaiv tom kawg, nco ntsoov xyuas kev sib raug zoo nrog koj lub version ntawm WordPress.

Ob qhov nrov SSL tswj hwm plugins: yooj yim SSLWP, tswj SSLSSL plugin. Nco ntsoov thaub qab koj qhov chaw thiab ceev faj thaum ua li ntawd. Yog tias koj teeb tsa qee yam tsis raug, nws tuaj yeem ua rau muaj kev puas tsuaj loj: cov neeg tuaj saib yuav tsis tuaj yeem pom koj lub xaib, cov duab yuav tsis tso tawm, cov ntawv yuav tsis thauj khoom, uas yuav cuam tshuam li cas qee yam ntawm koj qhov chaw ua haujlwm, xws li kev sau ntawv thiab xim. tsis pom zoo. way.

Koj yuav tsum tau xa rov qab cov neeg siv thiab tshawb fawb xyaw rau HTTPS nplooj ntawv siv 301 redirects hauv.htaccess cov ntaub ntawv hauv lub hauv paus nplaub tshev ntawm lub server. Cov ntaub ntawv.htaccess yog cov ntaub ntawv tsis pom, yog li xyuas kom koj qhov kev pab cuam FTP tau teeb tsa los qhia cov ntaub ntawv zais. Hauv FileZilla, piv txwv li, mus rau Server> Force saib ntawm cov ntaub ntawv zais. FileZilla Ua ntej, ua ntej ntxiv redirects, nws yuav yog ib lub tswv yim zoo rau thaub qab koj cov ntaub ntawv.htaccess. Ntawm tus neeg rau zaub mov, ib ntus hloov npe cov ntaub ntawv los ntawm kev tshem tawm lub sijhawm (uas ua rau pom tsis pom hauv thawj qhov chaw), rub tawm cov ntaub ntawv (uas tam sim no yuav pom hauv koj lub khoos phis tawj vim tias lub sijhawm raug tshem tawm), tom qab ntawd ntxiv lub sijhawm rov qab. rau dab tsi ntawm tus neeg rau zaub mov.

HTTPS daim ntawv pov thawj
HTTPS daim ntawv pov thawj

Hloov chawGoogle Analytics

Tom qab ua tiav cov kauj ruam no, koj yuav tsum hloov qhov koj nyiam URL hauv koj tus lej Google Analytics los tso saib HTTPS version ntawm koj lub npe. Txwv tsis pub, koj cov txheeb cais kev tsheb yuav raug cuam tshuam vim HTTP version ntawm URL raug kho raws li qhov chaw sib txawv kiag li los ntawm HTTPS version ntawm daim ntawv pov thawj. Google Search Console kho HTTP thiab HTTPS raws li cov npe sib cais, yog li ntxiv HTTPS tus lej sau rau nws. Nco ntsoov, thaum koj hloov ntawm HTTP mus rau HTTPS daim ntawv pov thawj, yog tias koj lub xaib muaj cov nyees khawm nkag tshwj xeeb, lub txee yuav rov pib dua.

Pom zoo: