You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx搭配Spring Boot与Let’s Encrypt证书的SSL握手问题求助

Nginx配置Let’s Encrypt SSL证书后SSL握手失败

为子域名api.example.com配置Nginx反向代理Spring Boot应用时,使用Let’s Encrypt SSL证书出现SSL握手问题,Nginx错误日志报错:

SSL_do_handshake() failed (SSL: error:141CF06C:SSL routines:tls_parse_ctos_key_share:bad key share)

环境信息

  • 操作系统:Ubuntu 22.04 LTS
  • Nginx版本:1.18.0
  • Spring Boot版本:3.1.5
  • SSL证书:Let’s Encrypt(由Certbot管理)

Nginx配置

server {
    listen 80;
    server_name api.example.com;

    # 重定向HTTP到HTTPS
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl;
    server_name api.example.com;
    
    # 启用TLS版本
    ssl_protocols TLSv1.2 TLSv1.3;

    # SSL证书与密钥路径
    ssl_certificate /etc/letsencrypt/live/api.example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/api.example.com/privkey.pem;

    # 额外SSL设置
    ssl_prefer_server_ciphers on;
    ssl_ciphers 'HIGH:!aNULL:!MD5';

    location / {
        proxy_pass http://localhost:8080;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_cache_bypass $http_upgrade;
        proxy_ssl_server_name on;
    }
}

已完成的验证步骤

  1. 验证SSL证书有效性:
    sudo openssl x509 -in /etc/letsencrypt/live/api.example.com/fullchain.pem -text -noout
    
    证书有效且未过期。
  2. 检查Nginx配置语法:
    sudo nginx -t
    
    无语法错误。
  3. 确认防火墙端口:
    sudo ufw status
    
    80和443端口均已放行。
  4. Spring Boot应用可通过http://localhost:8080正常访问,修改配置后已执行sudo systemctl restart nginx重启服务。

错误详情

  • Nginx错误日志:
    2024/10/03 17:14:09 [crit] 168657#168657: *30 SSL_do_handshake() failed (SSL: error:141CF06C:SSL routines:tls_parse_ctos_key_share:bad key share) while SSL handshaking, client: xxx.xx.xxx.xx, server: 0.0.0.0:443
    
  • Postman测试:HTTP可正常访问,HTTPS返回错误:

    Error: write EPROTO 988800:error:100000f7:SSL routines:OPENSSL_internal:WRONG_VERSION_NUMBER:........\src\third_party\boringssl\src\ssl\tls_record.cc:231:

解决方案

1. 修复TLS算法配置

bad key share错误多与TLS 1.3密钥共享算法不兼容有关,调整SSL配置:

server {
    listen 443 ssl;
    server_name api.example.com;
    
    ssl_protocols TLSv1.2 TLSv1.3;
    # 适配TLS 1.2和1.3的标准算法集
    ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384';
    ssl_prefer_server_ciphers off; # TLS 1.3不推荐强制服务器优先算法
    
    # 保留证书与代理配置...
}

2. 移除冗余代理配置

proxy_ssl_server_name on用于代理HTTPS后端,但你的Spring Boot应用运行在HTTP端口,该配置完全多余,直接删除这一行。

3. 升级Nginx版本(可选)

Nginx 1.18.0对TLS 1.3的支持不完善,通过官方源升级到稳定版:

sudo apt update
sudo apt install nginx-full

4. 验证SSL握手

修改配置后重启Nginx,用openssl测试:

sudo systemctl restart nginx
openssl s_client -connect api.example.com:443 -tls1_3

握手成功会返回证书信息与连接状态。

5. 检查Postman配置

Postman的版本错误可能是误发HTTP请求到HTTPS端口,确认请求URL为https://api.example.com,关闭不必要的全局代理。


内容的提问来源于stack exchange,提问作者xRay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 18:43:28