【发布时间】:2015-01-12 09:19:28
【问题描述】:
我在他面前做了一个基于 Tomcat 和 Nginx 的 web 项目。
必须努力工作以使其正常工作。
但是,当我将 ssl 添加到 nginx 时。停止工作的服务器发送事件。
如果我直接访问后端服务器 - 它可以工作,那么 nginx 的某个地方会出现问题。
有人遇到这样的问题吗?
这是配置的相关部分
我的 nginx.conf(我还没有使用启用站点,并且我的应用程序也配置在这里。基本设置在 conf 的末尾)。 /SecurConfig/api/tutorial/listen - 是事件的来源
user www-data;
worker_processes 4;
pid /run/nginx.pid;
events {
worker_connections 768;
# multi_accept on;
}
http {
root /data/;
server{
listen 80;
# server_name ajaxdemo.in.ua;
# proxy_set_header Host ajaxdemo.in.ua;
location / {
rewrite ^(.*)$ https://ajaxdemo.in.ua$1 permanent;
}
}
server {
#listen 80;
listen 443 default ssl;
#ssl on;
ssl_certificate /etc/nginx/ssl/server.crt;
ssl_certificate_key /etc/nginx/ssl/server.key;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
location / {
root /data/www;
add_header 'Access-Control-Allow-Origin' *;
add_header 'Access-Control-Allow-Credentials' 'true';
add_header 'Access-Control-Allow-Methods' 'GET';
if ($http_cookie ~* "jsessionid=([^;]+)(?:;|$)") {
set $co "jsessionid=$1";
}
#proxy_set_header Cookie "$co";
proxy_pass http://127.0.0.1:1666/SecurConfig/;
#proxy_pass http://88.81.229.142:1666/SecurConfig/;
add_before_body /header.html;
add_after_body /footer.html;
}
location /SecurConfig/api/tutorial/listen {
add_header 'Access-Control-Allow-Origin' *;
add_header 'Access-Control-Allow-Credentials' 'true';
add_header 'Access-Control-Allow-Methods' 'GET';
##Server sent events set
proxy_set_header Connection '';
proxy_http_version 1.1;
chunked_transfer_encoding off;
proxy_connect_timeout 300;
proxy_send_timeout 300;
proxy_read_timeout 300;
proxy_buffering on;
proxy_buffer_size 8k;
#proxy_cache off;
##
if ($http_cookie ~* "jsessionid=([^;]+)(?:;|$)") {
set $co "jsessionid=$1";
}
#proxy_set_header Cookie "$co";
proxy_pass http://127.0.0.1:1666/;
#proxy_pass http://88.81.229.142:1666/;
}
location /SecurConfig/ {
root /data/www;
add_header 'Access-Control-Allow-Origin' *;
add_header 'Access-Control-Allow-Credentials' 'true';
add_header 'Access-Control-Allow-Methods' 'GET';
if ($http_cookie ~* "jsessionid=([^;]+)(?:;|$)") {
set $co "jsessionid=$1";
}
#proxy_set_header Cookie "$co";
proxy_pass http://127.0.0.1:1666/;
#proxy_pass http://88.81.229.142:1666/;
add_before_body /header.html;
add_after_body /footer.html;
}
location ~ \.css$ {
root /data/css/;
}
location /header.html {
root /data/www;
}
location /footer.html {
root /data/www;
}
location ~ \.(gif|jpg|png|jpeg)$ {
root /data/images;
}
}
##
# Basic Settings
##
sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 65;
types_hash_max_size 2048;
client_max_body_size 100m;
include /etc/nginx/mime.types;
default_type application/octet-stream;
##
# Logging Settings
##
access_log /var/log/nginx/access.log;
error_log /var/log/nginx/error.log;
##
# Gzip Settings
##
gzip on;
gzip_disable "msie6";
##
# Virtual Host Configs
##
include /etc/nginx/conf.d/*.conf;
# include /etc/nginx/sites-enabled/*;
}
nginx的错误日志中没有错误条目。 但是在访问日志中也提到了对 /SecurConfig/api/tutorial/listen 的访问。代码 200 表示“一切正常”
"GET /SecurConfig/api/tutorial/listen HTTP/1.1" 200 187 "https://ajaxdemo.in.ua/SecurConfig/api/tutorial/map/11111111" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:34.0) Gecko/20100101 Firefox/34.0"
Tomcat 日志显示对 /SecurConfig/api/tutorial/listen 的访问权限和往常一样(例如,检查安全访问权限,接受它,然后重新发送到控制器)。
如果我在 chrome 开发者模式下运行我的页面,我会看到这个错误
GET https://ajaxdemo.in.ua/SecurConfig/api/tutorial/listen net::ERR_EMPTY_RESPONSE
更新
好的。当我在互联网上搜索信息时,我在打开 SSE 的情况下离开了我的页面。 10 分钟后,我看到,我的数据按原样出现了。我根据缓冲注释了所有设置
#proxy_buffering on; #proxy_buffer_size 8k; #proxy_cache off;
我还评论了参数
#proxy_connect_timeout 300; #proxy_send_timeout 300; #proxy_read_timeout 300;
所以这个参数返回了它的默认值(大约 20 秒) 我的所有数据都在~20 秒后出现。 所以我设置了
proxy_connect_timeout 2; proxy_send_timeout 2; proxy_read_timeout 2;
而且数据出现得更快。但它的.s 仍然是一件(一次 3-4 个事件),在启用 ssl 事件之前一一显示。
仍然需要您的帮助和解释,我错了。
更新
这是我服务器的配置,当我“关闭”ssl 并且 SSE 工作时。
ssl is off - sse works
80 port redirecting to 443 ssl - sse not works
【问题讨论】:
-
是否需要任何身份验证或 cookie?您确定在使用 SSL 时没有遇到任何 CORS 限制吗? (http 和 https 算作不同的来源)(还要确保您已经在 Chrome 和 Firefox 中进行了测试,因为我记得在这方面遇到过浏览器错误。)我想知道的另一件事是为什么 proxy_buffering 在你的配置。如果这些猜测有帮助,请告诉我,我会发布正确的答案:-)
-
1) 是的。在 tomcat 端进行会话安全检查需要 Cookie。它成功地检查了cookie。 2)“add_header‘访问控制允许来源’*;” - 这应该保护我免受跨域起源。至于 http/https - 我不知道如何检查是否有问题。 3)是的,我检查了 chrome 和 firefox。 4)proxy_buffering 必须保护我免受“粉碎”消息。如果缓冲如果“关闭”,那么 nginx 可以将长消息分开。无论如何,它在启用 ssl 之前工作。
标签: ssl nginx server-sent-events