www转非www的HTTPS重定向SSL证书异常问题求助
解决HTTPS www子域名SSL警告并实现全量重定向
问题根源
你遇到的SSL警告是因为DNSMadeEasy的HTTP重定向记录只处理HTTP请求,当用户访问https://www.my-example-domain.com时,请求会被DNSMadeEasy的代理服务器拦截,并用他们的通配符证书返回,而非你服务器上的Certbot证书,导致浏览器触发安全警告。
解决步骤
1. 先修改DNS配置(必须操作)
- 登录DNSMadeEasy控制台,删除
www.my-example-domain.com的HTTP重定向记录 - 添加一条A记录:
www.my-example-domain.com指向和主域名my-example-domain.com相同的服务器IP - 等待DNS生效(通常10-30分钟,可通过
nslookup www.my-example-domain.com验证)
2. 调整Apache2虚拟主机配置
确保你的Apache能处理www子域名的HTTPS请求,并将其重定向到主域名。
80端口配置(统一处理所有HTTP请求重定向)
替换或补充现有80端口虚拟主机配置,确保覆盖主域名和www子域名:
<VirtualHost *:80> ServerName my-example-domain.com ServerAlias www.my-example-domain.com # 永久重定向到HTTPS主域名 Redirect permanent / https://my-example-domain.com/ </VirtualHost>
443端口配置(处理HTTPS请求)
保留Certbot生成的主域名443配置,新增一个针对www子域名的443虚拟主机:
# 主域名HTTPS站点配置(Certbot自动生成,无需修改) <VirtualHost *:443> ServerName my-example-domain.com DocumentRoot /var/www/your-site-root SSLCertificateFile /etc/letsencrypt/live/my-example-domain.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/my-example-domain.com/privkey.pem Include /etc/letsencrypt/options-ssl-apache.conf # 其他站点相关配置... </VirtualHost> # www子域名HTTPS重定向配置 <VirtualHost *:443> ServerName www.my-example-domain.com # 使用同一张包含www的Certbot证书 SSLCertificateFile /etc/letsencrypt/live/my-example-domain.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/my-example-domain.com/privkey.pem Include /etc/letsencrypt/options-ssl-apache.conf # 永久重定向到主域名 Redirect permanent / https://my-example-domain.com/ </VirtualHost>
3. 验证配置并重启Apache
# 检查配置语法是否正确 apache2ctl configtest # 重启Apache生效 systemctl restart apache2
验证效果
完成后,访问以下地址都应自动跳转到https://my-example-domain.com且无SSL警告:
http://my-example-domain.comhttp://www.my-example-domain.comhttps://my-example-domain.comhttps://www.my-example-domain.com
内容的提问来源于stack exchange,提问作者Abdul Sadik Yalcin
相关产品推荐
相关产品推荐

