【问题标题】:Is it possible to redirect TCP connection with SSL Passthrough in nginx是否可以在 nginx 中使用 SSL Passthrough 重定向 TCP 连接
【发布时间】:2019-12-15 14:39:13
【问题描述】:

使用 nginx 中的 stream 块,TCP 代理在 nginx 中不可用。通过 SSL 直通配置,它可以将客户端证书一直传递到后端服务进行验证。

我想将此 TCP 连接从带有所有证书的 nginx 重定向到同一服务的 https 端点

更新问题: 因此,http://demo.local 的请求即将到来,需要将其重定向到 https://demo.local,然后在重定向 https 请求后进行 SSL 直通

----> Nginx 配置

http {
   server {
       listen 80;
       server_name demo.local;
       location / {
           return 302 https://demo.local$request_uri
       }
    }
}
stream {
# main log compatible format
    log_format stream '$remote_addr - - [$time_local] "$ssl_preread_server_name -> $name ($protocol)" '
                          '$status $bytes_sent "" "" "" ';

    map $ssl_preread_server_name $name {
        demo.local pt-up-demo.local;
    }
    upstream pt-up-demo.local {
        server 127.0.0.1:5000;
    }
    upstream proxy-up-demo.local {
        server x.x.x.x:8080;
    }
    server {
        listen 5000 proxy_protocol;
        proxy_pass proxy-up-demo.local'
    }
    server {
        listen 443;
        proxy_pass $name;
        proxy_protocol on;
        ssl_preread on;
        access_log /dev/stdout stream;
    }

}```

【问题讨论】:

    标签: ssl nginx nginx-config


    【解决方案1】:

    HTTP 重定向是在 HTTP 级别而不是在 HTTPS 级别完成的。为了让 nginx 发出此重定向,TLS 连接需要由 nginx 终止 - 这与您想要的 SSL 直通冲突。

    【讨论】:

    • 我们可以在http级别做重定向然后ssl通过吗?
    • @ChiragTayal:HTTPS 是 TLS 中的 HTTP。 SSL pass through 意味着传递 TLS,这意味着也传递 TLS 内的加密 HTTP。换句话说:nginx 无法在 HTTP 级别进行重定向,因为它无法通过 SSL 传递访问 HTTP 级别。
    • 我们可以像我在下一个答案中提到的那样做吗?
    • @ChiragTayal:同样,这不是配置问题,而是 HTTPS 工作方式的问题。重定向只能在 TLS 终止后进行。使用 SSL pass trough TLS 不会被 nginx 终止,因此 nginx 无法进行任何重定向。
    • 我不是重定向 HTTPS 请求,而是重定向 HTTP 请求。因此,http://demo.local 的请求即将到来,需要将其重定向到 https://demo.local,然后对 https 请求进行 SSL 直通
    猜你喜欢
    • 2020-07-21
    • 1970-01-01
    • 2015-08-04
    • 1970-01-01
    • 1970-01-01
    • 2015-06-09
    • 2011-11-28
    • 1970-01-01
    • 2013-10-08
    相关资源
    最近更新 更多