You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx配置求助:如何为带自定义端口的IP地址启用HTTPS?

Nginx配置求助:如何为带自定义端口的IP地址启用HTTPS?

Hey there, let's work through getting HTTPS up and running on your IP address with port 8888 in Nginx. I'll break down the issues in your current config and walk you through the fixes step by step.

First, let's look at the problems in your existing server block:

  • You don't need the separate ssl on; line — the listen 8888 ssl directive already enables SSL for that port, and including both can cause errors in newer Nginx versions.
  • Your IPv6 listen directive (listen [::]:8888 default_server;) is missing the ssl flag, so IPv6 requests won't use HTTPS.
  • You need to make sure your SSL certificate is valid for your IP address (regular domain certificates won't work here).

Step 1: Fix the HTTPS Server Block

Here's the corrected version of your HTTPS config, with optional security tweaks:

server {
    listen 8888 ssl default_server;
    listen [::]:8888 ssl default_server;  # Added `ssl` flag for IPv6

    ssl_certificate      /etc/ssl/certificate.crt;
    ssl_certificate_key  /etc/ssl/private.key;

    # Optional: Hardening SSL settings for better security
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    server_name 138.51.151.51;

    access_log   /var/log/nginx/nginx.vhost.access.log;
    error_log    /var/log/nginx/nginx.vhost.error.log;

    location / {
        root         /home/www/html;
        index        index.html;
    }
}

To make it user-friendly, add a separate server block to redirect all HTTP requests (port 80) to your HTTPS port 8888:

server {
    listen 80;
    listen [::]:80;
    server_name 138.51.151.51;

    # Redirect all HTTP traffic to HTTPS on port 8888
    return 301 https://$server_name:8888$request_uri;
}

Step 3: Verify Your SSL Certificate

Since you're using an IP address instead of a domain, you can't use a standard Let's Encrypt certificate. You'll need either:

  1. A commercial SSL certificate issued for your IP address, or
  2. A self-signed certificate (note: browsers will show a security warning unless you manually trust it)

If you need a self-signed certificate, generate one with this command (replace the IP with yours):

openssl req -x509 -newkey rsa:4096 -keyout /etc/ssl/private.key -out /etc/ssl/certificate.crt -days 365 -nodes -subj "/CN=138.51.151.51"

Make sure the certificate and key files have correct permissions:

chmod 600 /etc/ssl/private.key
chmod 644 /etc/ssl/certificate.crt
chown root:root /etc/ssl/private.key /etc/ssl/certificate.crt

Step 4: Check Firewall and Nginx Config

  • Open the necessary ports in your firewall (adjust for your firewall tool, e.g., UFW):
    ufw allow 80/tcp
    ufw allow 8888/tcp
    ufw reload
    
  • Test your Nginx config for errors:
    nginx -t
    
  • If no errors show up, restart Nginx to apply changes:
    systemctl restart nginx
    

After these steps, visiting http://138.51.151.51:8888 or http://138.51.151.51 should redirect to https://138.51.151.51:8888. If you used a self-signed cert, you'll need to accept the browser's security warning to access the site.

备注:内容来源于stack exchange,提问作者MAX 303

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 08:40:31