准备文件:
4 O3 j2 @# [: Ewget https://www.openssl.org/source/openssl-1.1.0f.tar.gz
; q5 J" r- x& [- Dtar xvzf openssl-1.1.0f.tar.gz+ C" C* ~9 }, j p1 H: c& g
wget ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/pcre-8.41.tar.gz
5 `5 U, q6 D3 |tar xvzf pcre-8.41.tar.gz
, e7 j- v' s7 W; A( @" l4 Q* }: A7 i4 D- L+ q. V9 S
wget http://nginx.org/download/nginx-1.13.6.tar.gz
: p4 a9 g0 A9 s2 a% D8 itart xvzf nginx-1.13.6.tar.gz6 N# r3 R6 ~, C4 R* {7 M6 U
/ K( D* b6 F6 L3 G( D ~9 w
wget https://github.com/openresty/sregex/archive/master.zip: I1 n( T: ]$ r% \% S
mv master.zip replace-filter-nginx-module-master.zip
, @7 ]( S) n% E& |9 Y, N) ]unzip replace-filter-nginx-module-master.zip& V9 N+ t, N: c
" E3 x* X3 c) X9 s. f. E u8 r安装sregex5 ^! W% |0 `3 ?( w
[replace-filter-nginx-module-master关键词替换模块需要这个东西,如果不喜欢可以用ngx_http_substitutions_filter_module这个关键字替换模块]0 R' | |& d8 x/ M$ ]" r# \
wget https://github.com/openresty/sregex/archive/master.zip
& A) `9 N! r3 w; a; Amv master.zip sregex.zip B( f9 r5 v% T3 \8 i( o
unzip sregex.zip
1 B& V# a% Y% ?* l) Jcd sregex1 b7 Y3 ^1 i5 O' ]% P* Y
make && make installln -s /usr/lib/libsregex.so.0 /usr/local/lib/libsregex.so.0.0.1 #按实际情况调整
G- [+ u0 U9 \; b6 \ldconfig
1 Y# ^ O2 B& ^ v: q e2 b% I: M$ b2 I/ y! ^% `
安装modsecurity
) C" D% [- k; e8 {/ o5 l; K8 r『依赖的包:pcre httpd-devel libxml2 apr 视情况安装。yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel)』0 r" n4 K L ?# n2 P
git clone https://github.com/SpiderLabs/ModSecurity.git mod_security
2 |+ v5 o3 b- ?1 t7 x5 m6 Q" j0 ucd mod_security
. H$ B. v7 a/ ^. K: F% F& X6 k) A./autogen.sh
2 t0 T+ U. n& z( }8 J4 ^+ ^/ V./configure --enable-standalone-module
. Q: Z* s& L6 H6 u4 s+ |* @4 pmake+ m" ]# I8 F6 s% Z5 a1 Y
f; t/ I- ^' I
* t: B' M. {# ]0 D7 G6 t安装nginx) k2 U- R I4 O% c$ c$ L
cd nginx-1.13.6; x$ L+ k1 r7 W( j) \4 B: {; e) N
) L/ K# S. Q# y- S2 P) e
[Bash shell] 纯文本查看 复制代码 ./configure \
--user=www \
--group=www \
--prefix=/www/webserver/nginx-1.13.6 \
--sbin-path=/www/webserver/nginx-1.13.6/sbin/nginx \
--pid-path=/www/webserver/nginx-1.13.6/logs/nginx.pid \
--conf-path=/www/webserver/nginx-1.13.6/conf/nginx.conf \
--error-log-path=/www/webserver/nginx-1.13.6/logs/error.log \
--http-log-path=/www/webserver/nginx-1.13.6/logs/access.log \
--http-client-body-temp-path=/www/webserver/nginx-1.13.6/temp/client \
--http-proxy-temp-path=/www/webserver/nginx-1.13.6/temp/proxy \
--http-fastcgi-temp-path=/www/webserver/nginx-1.13.6/temp/fcgi \
--http-scgi-temp-path=/www/webserver/nginx-1.13.6/temp/scgi \
--http-uwsgi-temp-path=/www/webserver/nginx-1.13.6/temp/uwsgi \
--with-http_flv_module \
--with-http_stub_status_module \
--with-http_realip_module \
--with-http_ssl_module \
--with-http_v2_module \
--with-http_gzip_static_module \
--with-pcre=/root/pcre-8.41 \
--with-http_sub_module \
--add-module=/root/replace-filter-nginx-module-master \
--add-module=/root/mod_security/nginx/modsecurity \
--with-openssl=/root/openssl-1.1.0f ' P/ B' u. N" _ r i1 i2 ~
make
) D2 e0 \3 \. ]1 q2 Q9 \0 c& Xmake install
4 T0 U- d1 k0 s. K; ^
/ N+ Z9 F7 v$ o$ G3 T& a T注:--with-ipv6 已经被移除默认支持ipv6, --with-http_spdy 已经被移除合并到--with-http_v2_module, W: F9 c, M& C$ [9 S4 ?9 E
* q B% |, c1 R% L, Z$ ^- L8 u" O6 h, y7 j3 ~
& O2 u+ m' {" y1 h7 u' M
& c( t+ I+ Z4 I4 T
2 Q7 `* l, K5 H {
8 ]2 K0 Q' B# @' m, x* U- p: [ }/ M) {/ N* ^% i: v
" m, N7 }! T* A' a+ r9 }/ o2 c3 x; v
|