【问题标题】:Nginx subdomain too many redirectsNginx 子域重定向过多
【发布时间】:2018-10-07 06:58:29
【问题描述】:

我目前有一个用于https://www.example.com 和http://sub.example.com 的工作Django + Gunicorn + Nginx 设置。注意主域有 ssl 而子域没有。

这与以下两个 nginx 配置一起正常工作。首先是www.example.com:

upstream example_app_server {
  server unix:/path/to/example/gunicorn/gunicorn.sock fail_timeout=0;
}

server {
 listen 80;
 server_name www.example.com;

 return 301 https://www.example.com$request_uri;
}

server {
    listen   443 ssl;
    server_name www.example.com;

    if ($host = 'example.com') {
      return 301 https://www.example.com$request_uri;
    }

    ssl_certificate       /etc/nginx/example/cert_chain.crt;
    ssl_certificate_key   /etc/nginx/example/example.key;
    ssl_session_timeout   1d;
    ssl_session_cache     shared:SSL:50m;
    ssl_protocols         TLSv1.1 TLSv1.2;
    ssl_ciphers           'ciphers removed to save space in post';
    ssl_prefer_server_ciphers   on;

    client_max_body_size 4G;

    access_log            /var/log/nginx/www.example.com.access.log;
    error_log             /var/log/nginx/www.example.com.error.log info;

    location /static {
      autoindex on;
      alias /path/to/example/static;
    }

    location /media {
      autoindex on;
      alias /path/to/example/media;
    }

    location / {
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header Host $http_host;
        proxy_redirect off;
        if (!-f $request_filename) {
            proxy_pass http://example_app_server;
            break;
        }
    }
}

接下来是sub.example.com:

upstream sub_example_app_server {
  server unix:/path/to/sub_example/gunicorn/gunicorn.sock fail_timeout=0;
}

server {
    listen   80;
    server_name sub.example.com;
    client_max_body_size 4G;
    access_log            /var/log/nginx/sub.example.com.access.log;
    error_log             /var/log/nginx/sub.example.com.error.log info;

    location /static {
      autoindex on;
      alias /path/to/sub_example/static;
    }

    location /media {
      autoindex on;
      alias /path/to/sub_example/media;
    }

    location / {
      proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
      proxy_set_header Host $http_host;
      proxy_redirect off;
      if (!-f $request_filename) {
        proxy_pass http://sub_example_app_server;
        break;
      }
    }
}

如前所述,这一切正常。我现在要做的是在子域上也使用ssl。为此,我有第二个 ssl 证书,该证书已通过该子域的域注册激活。

我已经从上面更新了 sub.example.com 的原始 nginx 配置,使其具有与 example.com 完全相同的格式,但指向相关的 ssl 证书/密钥等:

upstream sub_example_app_server {
  server unix:/path/to/sub_example/gunicorn/gunicorn.sock fail_timeout=0;
}

server {
 listen 80;
 server_name sub.example.com;

 return 301 https://sub.example.com$request_uri;
}

server {
    listen   443 ssl;
    server_name sub.example.com;

    if ($host = 'sub.example.com') {
      return 301 https://sub.example.com$request_uri;
    }

    ssl_certificate       /etc/nginx/sub_example/cert_chain.crt;
    ssl_certificate_key   /etc/nginx/sub_example/example.key;
    ssl_session_timeout   1d;
    ssl_session_cache     shared:SSL:50m;
    ssl_protocols         TLSv1.1 TLSv1.2;
    ssl_ciphers           'ciphers removed to save space in post';
    ssl_prefer_server_ciphers   on;

    client_max_body_size 4G;

    access_log            /var/log/nginx/sub.example.com.access.log;
    error_log             /var/log/nginx/sub.example.com.error.log info;

    location /static {
      autoindex on;
      alias /path/to/sub_example/static;
    }

    location /media {
      autoindex on;
      alias /path/to/sub_example/media;
    }

    location / {
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header Host $http_host;
        proxy_redirect off;
        if (!-f $request_filename) {
            proxy_pass http://sub_example_app_server;
            break;
        }
    }
}

我没有对我的域注册/dns 进行任何更改,因为在为子域添加 ssl 之前一切都已经正常工作。不确定是否需要更改?

浏览到http://sub.example.com 时,我被重定向到https://sub.example.com,因此该部分似乎正在工作。但是网站没有加载,浏览器错误是:This page isn't working. sub.example.com redirected you too many times. ERR_TOO_MANY_REDIRECTS

https://www.example.com 仍在工作。

我的 nginx 或 gunicorn 日志中没有任何错误。我只能猜测我在sub.example.com nginx 配置中配置了一些错误。

【问题讨论】:

  • ssl 服务器配置中的部分: if ($host = 'sub.example.com') { return 301 sub.example.com$request_uri } 是问题,总是会被触发。在 www 配置中,主机匹配在 'example.com' 而不是 'www.example.com'
  • 感谢您的回复。我不确定解决方案是什么?哪一部分需要改变?
  • 应该删除 if 块。它没有增加任何价值。乍一看,如果它被删除,太多的重定向错误应该会消失。
  • 哦,我明白了,它现在可以工作了。你是一个救生员。请根据您的评论创建一个答案,以便我接受。
  • 没问题,乐于助人!

标签: django ssl nginx


【解决方案1】:

ssl服务器配置部分:

if ($host = 'sub.example.com') { return 301 sub.example.com$request_uri } 

是问题所在。该规则将始终被触发。删除它应该可以消除太多的重定向错误。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2016-06-26
    • 2017-07-14
    • 1970-01-01
    • 2014-01-13
    • 2017-04-04
    • 1970-01-01
    • 1970-01-01
    • 2021-04-14
    相关资源
    最近更新 更多