Nginx代理老旧TLSv1服务器遇SSL握手错误:unsafe legacy renegotiation disabled
解决方案:修复Nginx代理老旧TLSv1服务器的SSL握手失败问题
错误根源
你遇到的SSL_do_handshake() failed (SSL: error:0A000152:SSL routines::unsafe legacy renegotiation disabled)错误,核心原因是现代OpenSSL版本默认禁用了不安全的TLS旧版重新协商机制,而你的老旧Web服务器依赖该机制才能完成SSL握手。同时当前配置未明确指定匹配的TLS协议版本和密码套件,也会加剧握手兼容性问题。
修改后的Nginx配置
在原配置基础上添加关键兼容指令,完整配置如下:
server { listen 80; server_name _; access_log /var/log/nginx/access.log; error_log /var/log/nginx/error.log; # 启用OpenSSL旧版重新协商支持(适配老旧服务器) ssl_conf_command Options UnsafeLegacyRenegotiation; location ~ ^/(.*)$ { proxy_pass https://my-server:443/$1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_ssl_verify off; # 指定仅使用TLSv1协议(匹配老旧服务器配置) proxy_ssl_protocols TLSv1; # 指定服务器要求的密码套件 proxy_ssl_ciphers RSA-PSK-AES128-CBC-SHA; } }
关键指令说明
ssl_conf_command Options UnsafeLegacyRenegotiation;:强制OpenSSL启用不安全的旧版重新协商机制,解决握手阶段的协商失败问题(需Nginx基于OpenSSL 1.1.1及以上版本编译)。proxy_ssl_protocols TLSv1;:明确限制代理仅使用TLSv1协议,避免尝试更高版本协议导致不兼容。proxy_ssl_ciphers RSA-PSK-AES128-CBC-SHA;:指定与老旧服务器完全匹配的密码套件,确保加密算法一致。
验证步骤
- 保存修改后的配置文件。
- 执行
nginx -t验证配置语法正确性。 - 执行
nginx -s reload重新加载Nginx配置。 - 重新发送请求测试是否恢复正常响应。
内容的提问来源于stack exchange,提问作者ofirule
相关产品推荐
相关产品推荐

