You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server上Rails应用Puma无法接受SSL连接问题求助

解决Windows Server上Rails应用HTTPS运行问题

问题根源解析

  1. Puma报错原因:你用netsh绑定了端口的SSL证书,但Puma仍以HTTP模式监听端口,外部发送的HTTPS加密请求被Puma当作普通HTTP解析,导致格式错误。netsh的SSL绑定是给IIS这类系统级服务用的,Rails服务器需要自行处理SSL加密。
  2. Thin报错原因:Thin依赖的eventmachine gem在Windows上默认安装可能未包含SSL支持,需要重新编译指定OpenSSL路径。

可行解决办法

办法1:直接配置Puma启用SSL

放弃netsh的端口绑定,让Puma直接加载证书文件处理SSL:

  1. 将你的Windows证书导出为PEM格式(包含私钥):
    • 如果是PFX格式证书,用OpenSSL命令转换:
      openssl pkcs12 -in your_certificate.pfx -out server.pem -nodes
      
    • 从server.pem中拆分出私钥文件server.key和证书文件server.crt(也可直接使用合并的PEM文件)。
  2. 用SSL参数启动Puma:
    rails s -p 7892 -e development --binding=0.0.0.0 --ssl --ssl-key-path=./server.key --ssl-cert-path=./server.crt
    
    或者在config/puma.rb中持久化配置:
    bind "ssl://0.0.0.0:7892?key=./server.key&cert=./server.crt"
    
    之后直接运行rails s -e development即可。

办法2:修复Thin的SSL支持

重新安装带SSL支持的eventmachine:

  1. 卸载现有eventmachine:
    gem uninstall eventmachine
    
  2. 指定OpenSSL路径重新安装(假设OpenSSL安装在C:\OpenSSL-win64):
    gem install eventmachine -- --with-ssl-dir=C:\OpenSSL-win64
    
  3. 启动Thin时指定证书文件:
    thin start -p 7892 --ssl --ssl-key-file=./server.key --ssl-cert-file=./server.crt
    

办法3:用IIS做反向代理(推荐稳定场景)

如果上述Ruby服务器的SSL配置仍有问题,用IIS作为前端反向代理,处理HTTPS后转发到Rails的HTTP端口:

  1. 确保IIS安装了URL重写和**应用程序请求路由(ARR)**模块。
  2. 在IIS中创建网站,绑定你的SSL证书(可直接在IIS界面操作,无需netsh命令)。
  3. 配置URL重写规则,将HTTPS请求转发到http://localhost:7892。
  4. Rails以HTTP模式启动,仅监听本地:
    rails s -p 7892 -e development --binding=127.0.0.1
    

内容的提问来源于stack exchange,提问作者Claudio Scabbia Sepúlveda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 12:43:10