【问题标题】:SSL not working with Elastic Load Balancer and NginxSSL 不适用于弹性负载均衡器和 Nginx
【发布时间】:2016-02-10 06:08:21
【问题描述】:

我最近购买了一个 SSL 证书,并尝试使用 Nginx EC2 实例将其加载到我的弹性负载均衡器上。

网站没有加载任何东西,我的错误日志显示这个错误:no "ssl_certificate" is defined in server listening on SSL port while SSL handshaking

亚马逊网站上的所有健康检查都通过了,所以我不确定问题出在哪里。 SSL 证书也已正确上传到我的 ELB。我的 nginx 代理文件如下所示:

server {    
    listen 80;
    listen 443 default_server ssl;

    rewrite ^(.*) https://$host$1 permanent;

    client_max_body_size 4G;
    client_header_timeout 60;
    client_body_buffer_size 1K;
    client_header_buffer_size 1k;
    server_name %(DOMAINS)s %(EC2_INSTANCES)s;
    keepalive_timeout 20;
    root %(PROJECT_PATH)s;

    location / {
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header Host $http_host;
        proxy_redirect off;
        if (!-f $request_filename) {
            proxy_pass http://app_server;
            break;
        }
    }
    error_page 500 502 503 504 /500.html;
    location = /500.html {
        root /path/to/app/current/public;
    }
}

非常感谢任何建议!提前谢谢!

编辑 - - -

该网站现在显示一个纯白色页面,但是当我检查元素时出现 503 错误(通过 Chrome)。不确定这是否起作用,但我认为信息越多越好。

【问题讨论】:

  • 您不能在带有 ELB 的后端服务器上使用 SSL,除非您实际上已经在每个后端服务器上安装了 SSL 证书。
  • @Michael-sqlbot 那么您会提出什么解决方案呢?如果我删除 SSL 设置并只保留标准 HTTP,我仍然会收到一个空白屏幕。还有什么我应该做的吗?
  • 您要么需要后端证书,要么更改 ELB 以将其终止的 SSL 流量发送到后端的端口 80。 (设置:负载均衡器协议 HTTPS、负载均衡器端口 443、实例协议 HTTP、实例端口 80)。 X-Forwarded-Proto: 标头将包含值 https 如果请求在前端是安全的,http 如果不是,这就是你将在后端测试的内容,如果你想强制/重定向 http到 https。
  • @Michael-sqlbot 如果您想将其作为解决方案发布,我会为您接受。感谢您的帮助!

标签: ssl amazon-web-services nginx amazon-ec2 amazon-elb


【解决方案1】:

在您的 ELB 中,将流量从 443 重定向到 80 端口,然后在您的 vhost 中执行以下操作:

server {

listen 80;
rewrite ^(.*) https://$host$1 permanent;    

client_max_body_size 4G;
client_header_timeout 60;
client_body_buffer_size 1K;
client_header_buffer_size 1k;
server_name %(DOMAINS)s %(EC2_INSTANCES)s;
keepalive_timeout 20;
root %(PROJECT_PATH)s;

location / {
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header Host $http_host;

    set $is_https 'off';
            if ($http_x_forwarded_proto ~ 'https') {
                    set $is_https 'on';
            }
    proxy_set_header HTTPS $is_https;

    proxy_redirect off;
    if (!-f $request_filename) {
        proxy_pass http://app_server;
        break;
    }
}
error_page 500 502 503 504 /500.html;
location = /500.html {
    root /path/to/app/current/public;
}

}

如果您在 ELB 中终止 SSL,则不需要在您的虚拟主机中检查 SSL。您只需要检查 http_x_forwarded_proto 标头并将其传递给后端即可。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2017-01-13
    • 2023-04-09
    • 1970-01-01
    • 2016-11-10
    • 2021-05-26
    • 2016-05-16
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多