You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx服务器出现OpenSSL版本号错误,请求技术排查解决

AWS EC2 Nginx配置Svelte应用时SSL版本错误求助

我在AWS EC2实例上折腾Nginx跑Svelte应用已经一周了,时好时坏,肯定是漏了某个小细节,找到的时候估计要拍大腿。

核心问题:用curl -v访问绑定实例且有有效SSL证书的域名时,报错(35) OpenSSL/3.0.8: error:0A00010B:SSL routines::wrong version number,找不到原因。

已知这个错误是客户端期望HTTPS响应,但服务器返回了HTTP内容,但不清楚触发原因。


当前Nginx站点配置

upstream sveltekit {
  server 127.0.0.1:3000;
  keepalive 8;
}


server {
    listen 80;
    server_name domain.fr www.domain.fr;

    # Redirect HTTP to HTTPS
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl;
    server_name domain.fr www.domain.fr;

    ssl_certificate /etc/letsencrypt/live/domain.fr/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/domain.fr/privkey.pem; # managed by certbot

    root /var/www/html;
    index index.html;

    location / {
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-NginX-Proxy true;
        proxy_set_header X-Forwarded-Proto $scheme;

        proxy_pass http://sveltekit;
        proxy_redirect off;

        error_page 502 = @static;
    }
    location @static {
        try_files $uri /index.html =502;
    }
}

简化HTTPS测试配置(仍无效)

server {
    listen 443 ssl;
    server_name domain.fr;

    ssl_certificate /etc/letsencrypt/live/domain.fr/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/domain.fr/privkey.pem;
    
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;


    location / {
        return 200 'SSL is working';
        add_header Content-Type text/plain;
    }
}

nginx.conf(仅新增一条导入,其余默认)

# For more information on configuration, see:
#   * Official English Documentation: http://nginx.org/en/docs/
#   * Official Russian Documentation: http://nginx.org/ru/docs/

user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log notice;
pid /run/nginx.pid;

# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic.
include /usr/share/nginx/modules/*.conf;

events {
    worker_connections 1024;
}

http {
    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';

    access_log  /var/log/nginx/access.log  main;

    sendfile            on;
    tcp_nopush          on;
    keepalive_timeout   65;
    types_hash_max_size 4096;

    include             /etc/nginx/mime.types;
    default_type        application/octet-stream;

    # Load modular configuration files from the /etc/nginx/conf.d directory.
    # See http://nginx.org/en/docs/ngx_core_module.html#include
    # for more information.
    include /etc/nginx/conf.d/*.conf;
    include /etc/nginx/sites-enabled/*;

}

已完成的排查和确认项

  • 域名、SSL证书、防火墙/安全组配置正常,昨天还能正常将443端口流量转发到3000端口的Svelte应用,网站可正常访问
  • sudo nginx -t配置测试通过
  • /var/log/nginx/error.log无错误记录
  • 修改配置后均执行sudo systemctl restart nginx
  • conf.d和default.d目录为空
  • 仅Nginx在监听443端口
  • Svelte应用运行正常,curl localhost:3000可获取正确响应
  • sudo openssl s_client -connect domain.fr:443和sudo openssl x509 -in /etc/letsencrypt/live/domain.fr/fullchain.pem -text -noout执行无异常

可能的排查方向和解决方案

  • 检查Nginx监听IP范围:执行ss -tulpn | grep :443,确认Nginx监听的是0.0.0.0:443或实例公网IP,而非仅127.0.0.1:443,否则公网请求无法触达SSL服务。
  • 验证AWS网络层配置:检查网络ACL是否放行443端口的入站/出站流量;用nc -zv domain.fr 443或telnet测试公网端口连通性。
  • 修复证书文件权限:确保Nginx用户(nginx)能读取证书文件,执行sudo chmod -R 755 /etc/letsencrypt/live/和sudo chown -R root:nginx /etc/letsencrypt/live/。
  • 本地实例内测试HTTPS:在EC2内部执行curl -v https://localhost或curl -v https://domain.fr,若本地正常但外部异常,大概率是网络层问题;若本地也报错,需重新排查Nginx配置。
  • 清除本地DNS缓存:Windows执行ipconfig /flushdns,Linux执行sudo systemd-resolve --flush-caches,避免旧IP解析导致的异常。

内容的提问来源于stack exchange,提问作者Septillion

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 02:37:12