HTTPS裸域名(不带WWW)访问超时问题求助
Let’s walk through exactly why you’re hitting this timeout and how to resolve it, since your other redirects (non-HTTPS bare domain, www subdomain, and HTTP variants) are already working as expected.
Root Cause
The timeout happens because your bare domain (cashflowbux.com) doesn’t have a valid HTTPS route configured. When someone tries to access https://cashflowbux.com, there’s no server listening for that request. Namecheap’s note about needing to point the bare domain to a host with an SSL makes sense for traditional hosting, but since you’re using CloudFront + S3, we can handle this entirely within AWS and DNS settings.
Step-by-Step Fix
Verify your ACM certificate covers the bare domain
- Head to AWS Certificate Manager (must be in the
us-east-1region—required for CloudFront) and check your existing certificate. It needs to include bothwww.cashflowbux.comandcashflowbux.comas Subject Alternative Names (SANs). - If the bare domain isn’t listed, request a new certificate or update your current one to add it. You’ll validate ownership via DNS by adding a CNAME record provided by ACM to your Namecheap DNS settings.
- Head to AWS Certificate Manager (must be in the
Update your CloudFront distribution to include the bare domain
- Open your CloudFront distribution in the AWS Console, go to the General tab, and click "Edit".
- In the
Alternate Domain Names (CNAMEs)field, addcashflowbux.comnext to your existingwww.cashflowbux.com. - Ensure the
SSL Certificatedropdown is set to the ACM certificate that includes both domains. Save the changes—CloudFront will deploy this update globally (takes ~15-20 minutes).
Point the bare domain to CloudFront via Namecheap DNS
- Log into Namecheap, navigate to your domain’s BasicDNS settings.
- Delete any existing redirect records for the bare domain (these only work for HTTP, not HTTPS).
- Create an A Record (for IPv4):
- Hostname: Leave empty (this targets the bare domain)
- Value: Paste your CloudFront distribution’s domain name (e.g.,
d123xyz.cloudfront.net) - TTL: Select "Automatic"
- Optional (for IPv6 support): Add an AAAA Record using the IPv6 address associated with your CloudFront distribution (look this up via
nslookup -type=AAAA your-cloudfront-domain.net).
Configure CloudFront to redirect the bare domain to https://www.cashflowbux.com
- Go to your CloudFront distribution’s Behaviors tab.
- Create a new behavior (or edit your default behavior):
- Set
Path Patternto/* - Set
Viewer Protocol PolicytoRedirect HTTP to HTTPS - Choose one of these redirect methods:
- S3 Redirect: If your origin is an S3 static website, go to the bucket’s Properties > Static website hosting and set up a redirect rule that sends all requests to
https://www.cashflowbux.com. - Lambda@Edge: Create a simple Lambda function (in
us-east-1) that redirects requests fromcashflowbux.comtowww.cashflowbux.com, then attach it to the "Viewer Request" event of your CloudFront behavior.
- S3 Redirect: If your origin is an S3 static website, go to the bucket’s Properties > Static website hosting and set up a redirect rule that sends all requests to
- Set
Wait for propagation
- DNS changes can take 1-48 hours to fully propagate globally (most often done in 1-2 hours).
- CloudFront’s deployment will finish in ~15-20 minutes, but give it extra time to reach all edge locations.
Once all steps are complete, https://cashflowbux.com will no longer time out—it’ll redirect smoothly to https://www.cashflowbux.com just like your other domain variants.
内容的提问来源于stack exchange,提问作者Kek

