You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地开发中Docker+Nginx配置SSL遇问题求助

本地Nginx Docker环境启用SSL遇到的问题

我是一名开发者,同时也是Nginx新手,希望在本地开发环境中启用SSL以使用HTTPS进行开发。制作了极简示例后,执行docker compose up构建并运行容器,访问https://tom.dev:8000本应显示:

It works!

但实际出现以下问题:

浏览器错误

您的连接不是私密连接 攻击者可能试图从tom.dev窃取您的信息(例如密码、消息或信用卡)。了解更多 NET::ERR_CERT_AUTHORITY_INVALID

curl请求输出

执行curl https://tom.dev:8000 -verbose得到以下信息:

curl https://tom.dev:8000 -verbose

* Trying 127.0.0.1:8000...
* Connected to tom.dev (127.0.0.1) port 8000
* ALPN: curl offers h2,http/1.1
* (304) (OUT), TLS handshake, Client hello (1):
* CAfile: /etc/ssl/cert.pem
* CApath: none
* LibreSSL/3.3.6: error:1404B42E:SSL routines:ST_CONNECT:tlsv1 alert protocol version
* Closing connection
  curl: (35) LibreSSL/3.3.6: error:1404B42E:SSL routines:ST_CONNECT:tlsv1 alert protocol version

相关配置文件

docker-compose.yml

version: '3'

services:

    nginx:
        container_name: nginx-ssl
        image: nginx
        ports:
            - 8000:80
            - 443:443
        volumes:
            - .:/var/www
            - .docker/nginx/nginx.conf:/etc/nginx/nginx.conf
            - .docker/nginx/certs/tom.dev.crt:/etc/nginx/ssl/tom.dev.crt
            - .docker/nginx/certs/tom.dev.key:/etc/nginx/ssl/tom.dev.key

nginx.conf

user  nginx;
worker_processes  1;

error_log  /var/log/nginx/error.log warn;
pid        /var/run/nginx.pid;

events {}

http {
    include /etc/nginx/mime.types;

    server {
        listen 80;
        return 301 https://$server_name$request_uri;
    }

    server {
        listen 443 ssl ;
        server_name tom.dev;
        ssl_certificate /etc/nginx/ssl/tom.dev.crt;
        ssl_certificate_key /etc/nginx/ssl/tom.dev.key;

      location / {
        root /var/www/;
        index  index.html;
        try_files $uri $uri/ /index.html;
      }
    }
}

证书生成方式

尝试了两种证书生成方法,均出现相同错误,不确定哪种方式正确或配置是否存在问题:

mkcert方式

cd .docker/nginx/certs
mkcert "*.tom.dev"

openssl方式

cd .docker/nginx/certs 

openssl req -x509 -nodes -new -sha256 -days 1024 -newkey rsa:2048 -keyout tom.dev.key -out tom.dev.pem -subj "/C=US/CN=Example-Root-CA" 

openssl x509 -outform pem -in tom.dev.pem -out tom.dev.crt

内容的提问来源于stack exchange,提问作者t t

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 15:54:53