Nginx服务器出现OpenSSL版本号错误,请求技术排查解决
AWS EC2 Nginx配置Svelte应用时SSL版本错误求助
我在AWS EC2实例上折腾Nginx跑Svelte应用已经一周了,时好时坏,肯定是漏了某个小细节,找到的时候估计要拍大腿。
核心问题:用curl -v访问绑定实例且有有效SSL证书的域名时,报错(35) OpenSSL/3.0.8: error:0A00010B:SSL routines::wrong version number,找不到原因。
已知这个错误是客户端期望HTTPS响应,但服务器返回了HTTP内容,但不清楚触发原因。
当前Nginx站点配置
upstream sveltekit { server 127.0.0.1:3000; keepalive 8; } server { listen 80; server_name domain.fr www.domain.fr; # Redirect HTTP to HTTPS return 301 https://$host$request_uri; } server { listen 443 ssl; server_name domain.fr www.domain.fr; ssl_certificate /etc/letsencrypt/live/domain.fr/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/domain.fr/privkey.pem; # managed by certbot root /var/www/html; index index.html; location / { proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-NginX-Proxy true; proxy_set_header X-Forwarded-Proto $scheme; proxy_pass http://sveltekit; proxy_redirect off; error_page 502 = @static; } location @static { try_files $uri /index.html =502; } }
简化HTTPS测试配置(仍无效)
server { listen 443 ssl; server_name domain.fr; ssl_certificate /etc/letsencrypt/live/domain.fr/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/domain.fr/privkey.pem; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; location / { return 200 'SSL is working'; add_header Content-Type text/plain; } }
nginx.conf(仅新增一条导入,其余默认)
# For more information on configuration, see: # * Official English Documentation: http://nginx.org/en/docs/ # * Official Russian Documentation: http://nginx.org/ru/docs/ user nginx; worker_processes auto; error_log /var/log/nginx/error.log notice; pid /run/nginx.pid; # Load dynamic modules. See /usr/share/doc/nginx/README.dynamic. include /usr/share/nginx/modules/*.conf; events { worker_connections 1024; } http { log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; access_log /var/log/nginx/access.log main; sendfile on; tcp_nopush on; keepalive_timeout 65; types_hash_max_size 4096; include /etc/nginx/mime.types; default_type application/octet-stream; # Load modular configuration files from the /etc/nginx/conf.d directory. # See http://nginx.org/en/docs/ngx_core_module.html#include # for more information. include /etc/nginx/conf.d/*.conf; include /etc/nginx/sites-enabled/*; }
已完成的排查和确认项
- 域名、SSL证书、防火墙/安全组配置正常,昨天还能正常将443端口流量转发到3000端口的Svelte应用,网站可正常访问
sudo nginx -t配置测试通过/var/log/nginx/error.log无错误记录- 修改配置后均执行
sudo systemctl restart nginx conf.d和default.d目录为空- 仅Nginx在监听443端口
- Svelte应用运行正常,
curl localhost:3000可获取正确响应 sudo openssl s_client -connect domain.fr:443和sudo openssl x509 -in /etc/letsencrypt/live/domain.fr/fullchain.pem -text -noout执行无异常
可能的排查方向和解决方案
- 检查Nginx监听IP范围:执行
ss -tulpn | grep :443,确认Nginx监听的是0.0.0.0:443或实例公网IP,而非仅127.0.0.1:443,否则公网请求无法触达SSL服务。 - 验证AWS网络层配置:检查网络ACL是否放行443端口的入站/出站流量;用
nc -zv domain.fr 443或telnet测试公网端口连通性。 - 修复证书文件权限:确保Nginx用户(nginx)能读取证书文件,执行
sudo chmod -R 755 /etc/letsencrypt/live/和sudo chown -R root:nginx /etc/letsencrypt/live/。 - 本地实例内测试HTTPS:在EC2内部执行
curl -v https://localhost或curl -v https://domain.fr,若本地正常但外部异常,大概率是网络层问题;若本地也报错,需重新排查Nginx配置。 - 清除本地DNS缓存:Windows执行
ipconfig /flushdns,Linux执行sudo systemd-resolve --flush-caches,避免旧IP解析导致的异常。
内容的提问来源于stack exchange,提问作者Septillion
相关产品推荐
相关产品推荐

