Nginx搭配Spring Boot与Let’s Encrypt证书的SSL握手问题求助
Nginx配置Let’s Encrypt SSL证书后SSL握手失败
为子域名api.example.com配置Nginx反向代理Spring Boot应用时,使用Let’s Encrypt SSL证书出现SSL握手问题,Nginx错误日志报错:
SSL_do_handshake() failed (SSL: error:141CF06C:SSL routines:tls_parse_ctos_key_share:bad key share)
环境信息
- 操作系统:Ubuntu 22.04 LTS
- Nginx版本:1.18.0
- Spring Boot版本:3.1.5
- SSL证书:Let’s Encrypt(由Certbot管理)
Nginx配置
server { listen 80; server_name api.example.com; # 重定向HTTP到HTTPS return 301 https://$host$request_uri; } server { listen 443 ssl; server_name api.example.com; # 启用TLS版本 ssl_protocols TLSv1.2 TLSv1.3; # SSL证书与密钥路径 ssl_certificate /etc/letsencrypt/live/api.example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/api.example.com/privkey.pem; # 额外SSL设置 ssl_prefer_server_ciphers on; ssl_ciphers 'HIGH:!aNULL:!MD5'; location / { proxy_pass http://localhost:8080; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection 'upgrade'; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; proxy_ssl_server_name on; } }
已完成的验证步骤
- 验证SSL证书有效性:
证书有效且未过期。sudo openssl x509 -in /etc/letsencrypt/live/api.example.com/fullchain.pem -text -noout - 检查Nginx配置语法:
无语法错误。sudo nginx -t - 确认防火墙端口:
80和443端口均已放行。sudo ufw status - Spring Boot应用可通过
http://localhost:8080正常访问,修改配置后已执行sudo systemctl restart nginx重启服务。
错误详情
- Nginx错误日志:
2024/10/03 17:14:09 [crit] 168657#168657: *30 SSL_do_handshake() failed (SSL: error:141CF06C:SSL routines:tls_parse_ctos_key_share:bad key share) while SSL handshaking, client: xxx.xx.xxx.xx, server: 0.0.0.0:443 - Postman测试:HTTP可正常访问,HTTPS返回错误:
Error: write EPROTO 988800:error:100000f7:SSL routines:OPENSSL_internal:WRONG_VERSION_NUMBER:........\src\third_party\boringssl\src\ssl\tls_record.cc:231:
解决方案
1. 修复TLS算法配置
bad key share错误多与TLS 1.3密钥共享算法不兼容有关,调整SSL配置:
server { listen 443 ssl; server_name api.example.com; ssl_protocols TLSv1.2 TLSv1.3; # 适配TLS 1.2和1.3的标准算法集 ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384'; ssl_prefer_server_ciphers off; # TLS 1.3不推荐强制服务器优先算法 # 保留证书与代理配置... }
2. 移除冗余代理配置
proxy_ssl_server_name on用于代理HTTPS后端,但你的Spring Boot应用运行在HTTP端口,该配置完全多余,直接删除这一行。
3. 升级Nginx版本(可选)
Nginx 1.18.0对TLS 1.3的支持不完善,通过官方源升级到稳定版:
sudo apt update sudo apt install nginx-full
4. 验证SSL握手
修改配置后重启Nginx,用openssl测试:
sudo systemctl restart nginx openssl s_client -connect api.example.com:443 -tls1_3
握手成功会返回证书信息与连接状态。
5. 检查Postman配置
Postman的版本错误可能是误发HTTP请求到HTTPS端口,确认请求URL为https://api.example.com,关闭不必要的全局代理。
内容的提问来源于stack exchange,提问作者xRay
相关产品推荐
相关产品推荐

