You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为Node.js(StrapiJs)应用配置Nginx安全HTTPS连接遇问题求助

问题排查:Strapi+Nginx+Cloudflare配置HTTPS后证书不匹配及SSL协议错误

环境与前置配置

  • Linode Ubuntu服务器,Strapi应用运行在8081端口
  • Nginx将80端口请求转发至8081端口
  • Cloudflare域名的A/AAAA记录已正确指向服务器IP

已执行的HTTPS配置步骤

  1. 初始Nginx配置(/etc/nginx/nginx.conf)
events {
        worker_connections 768;                                                          # multi_accept on;
}
                                                                                 
http {
    server {  
        listen 80;
        server_name mydomain.com;   
        location / {
            proxy_pass http://localhost:8081;  # Forward requests to localhost:8081                                                                                           proxy_set_header Host $host;         # Pass the Host header                      proxy_set_header X-Real-IP $remote_addr;  # Pass the client’s real IP
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;  # Forward the client's IP
            proxy_set_header X-Forwarded-Proto $scheme;  # Pass the protocol (HTTP or HTTPS)
        }                                                                        
     }
 }
  1. 安装Certbot及插件
sudo apt update 
sudo apt upgrade 
sudo apt install certbot
sudo apt install python3-certbot-nginx
  1. 生成证书并自动修改Nginx配置
sudo certbot --nginx -d mydomain.com

修改后的Nginx配置:

events {
        worker_connections 768;                                                          # multi_accept on;
}
                                                                                 
http {
    server {  # Listen on port 443 for HTTPS
        server_name mydomain.com;  # Replace with your domain      
        location / {
            proxy_pass http://localhost:8081;  # Forward requests to localhost:8081                                                                                           proxy_set_header Host $host;         # Pass the Host header                      proxy_set_header X-Real-IP $remote_addr;  # Pass the client’s real IP
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;  # Forward the client's IP
            proxy_set_header X-Forwarded-Proto $scheme;  # Pass the protocol (HTTP or HTTPS)
        }                                                                        
    listen 443 ssl; # managed by Certbot                                             ssl_certificate /etc/letsencrypt/live/dash.levelup.configfan.com/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/dash.levelup.configfan.com/privkey.pem; # managed by Certbot
    include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

}

    server {
    if ($host = mydomain.com) {
        return 301 https://$host$request_uri;
    } # managed by Certbot


        listen 80;
        server_name mydomain.com;
    return 404; # managed by Certbot


}}
  1. 验证并重载Nginx
sudo nginx -t
sudo nginx -s reload

当前问题现象

  • 访问服务器IP自动跳转HTTPS,但浏览器提示证书对应其他域名,存在安全警告
  • 访问域名跳转HTTPS后无法加载页面,报错:
This site can’t provide a secure connection
***.com uses an unsupported protocol.
ERR_SSL_VERSION_OR_CIPHER_MISMATCH

排查方案

1. 核对证书与域名匹配性

  • 检查证书绑定的域名:执行以下命令,确认输出的DNS记录与mydomain.com一致
openssl x509 -in /etc/letsencrypt/live/[你的实际域名]/fullchain.pem -text | grep DNS
  • 从当前配置看,证书路径指向dash.levelup.configfan.com,但server_name是mydomain.com,明显不匹配,需确认Certbot执行时是否指定错误域名,或配置文件被误修改

2. 检查Cloudflare SSL模式

  • Cloudflare需设置正确的SSL模式:
    • 服务器已配置HTTPS,需将Cloudflare控制台「SSL/TLS」>「加密模式」设为完全(Full)或严格(Full strict),避免使用「灵活」模式(该模式下Cloudflare与服务器间用HTTP通信,会引发SSL协议不匹配)
    • 在「SSL/TLS」>「边缘证书」中,确认SSL/TLS版本支持包含TLS 1.2及以上,禁用过时协议

3. 验证Nginx SSL配置

  • 检查/etc/letsencrypt/options-ssl-nginx.conf中的协议配置,确保包含:
ssl_protocols TLSv1.2 TLSv1.3;

避免仅启用过时协议或错误禁用全部主流协议

  • 执行nginx -V,确认编译参数包含--with-http_ssl_module,确保Nginx支持SSL功能

4. 检查端口与防火墙

  • 确认服务器443端口开放:执行ufw status,确保443/tcp规则为允许状态
  • 用curl -v https://mydomain.com测试,查看SSL握手过程的具体错误日志
  • 检查Cloudflare防火墙规则,确认未拦截HTTPS请求

5. 重新生成正确域名的证书

若确认证书域名不匹配,执行以下步骤重置:

# 删除错误证书(替换为实际错误域名)
sudo certbot delete -d dash.levelup.configfan.com
# 重新为目标域名生成证书
sudo certbot --nginx -d mydomain.com
# 重载Nginx
sudo nginx -s reload

内容的提问来源于stack exchange,提问作者Isaac Qadri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 18:46:16