从Apache2迁移至Nginx后HTTPS访问异常的配置合理性排查请求
Hey there, let's work through your Nginx configuration issues step by step—you're already halfway there, just a few syntax and logic tweaks needed to get HTTPS running smoothly.
First, a quick clarification on the IP access issue:
When you load the site via your elastic IP directly, the invalid certificate error is totally expected. Your Let's Encrypt certificate is issued specifically for mywebsite.com and mywebsite.blah.com, not for raw IP addresses. That part isn't a bug—focus on accessing your site through your domain names instead.
Now, let's fix the critical Nginx configuration mistakes:
1. Fix invalid syntax in website.conf (port 80 config)
Your current port 80 server block has a nested server declaration (invalid Nginx syntax) and a broken rewrite rule that sends traffic directly to your backend's 8080 port. Here's the corrected version:
server { listen 80; listen [::]:80; server_name mywebsite.com mywebsite.blah.com; # Redirect all HTTP traffic to HTTPS return 301 https://$host$request_uri; # Block .htaccess files (Nginx doesn't use these anyway) location ~ /\.ht { deny all; } }
No need for PHP or root directives here—we're just redirecting all HTTP traffic to HTTPS.
2. Merge SSL configs and fix backend proxy logic
You have multiple conflicting website-ssl*.conf files. Let's combine them into one clean HTTPS server block that handles both domains, proxies correctly to your backend, and supports WebSockets:
server { listen 443 ssl; listen [::]:443 ssl; server_name mywebsite.com mywebsite.blah.com; ssl_certificate /etc/letsencrypt/live/mywebsite.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/mywebsite.com/privkey.pem; include /etc/letsencrypt/options-ssl-nginx.conf; # Handle regular traffic + WebSocket upgrades for all paths location / { proxy_pass http://localhost:8080/; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; # Fix cookie domain/path to match your frontend domain proxy_cookie_domain localhost $host; proxy_cookie_path / /; # WebSocket upgrade handling proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection $connection_upgrade; } # Explicit WebSocket config for /api/ws (adds longer timeout for persistent connections) location /api/ws { proxy_pass http://localhost:8080/api/ws; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_read_timeout 86400; } access_log /var/log/nginx/access.log main; error_log /var/log/nginx/error.log warn; }
Key fixes here:
- Added both domain names to
server_nameso the certificate works for both - Switched
proxy_passtolocalhost:8080to avoid DNS loops (your Apache config mixed external domains and localhost—stick with localhost for backend traffic) - Added proper WebSocket upgrade handling. For this to work, add this line to your
nginx.confunder thehttpblock:map $http_upgrade $connection_upgrade { default upgrade; '' close; }
3. Clean up nginx.conf
You have duplicate include /etc/nginx/sites-enabled/*; lines—delete one of them to avoid loading configs twice, which can cause unexpected behavior.
Final steps to apply fixes:
- Disable old conflicting configs:
sudo unlink /etc/nginx/sites-enabled/website-ssl.conf sudo unlink /etc/nginx/sites-enabled/website-ssl2.conf - Link your corrected configs to the enabled directory:
sudo ln -s /etc/nginx/sites-available/website.conf /etc/nginx/sites-enabled/ sudo ln -s /etc/nginx/sites-available/website-ssl.conf /etc/nginx/sites-enabled/ - Test Nginx for syntax errors:
sudo nginx -t - If the test passes, reload Nginx:
sudo systemctl reload nginx - Visit
https://mywebsite.comandhttps://mywebsite.blah.com—your certificate should now be valid, and traffic should proxy correctly to your backend.
Let me know if you run into any errors after applying these changes!
备注:内容来源于stack exchange,提问作者jabroni

