You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache2+Node Express部署后API请求报unable to verify the first certificate

解决"unable to verify the first certificate"错误方案

一、检查并修复证书链顺序

这个错误最常见的原因是证书链合并顺序错误,正确的证书链顺序必须是域名证书在前,中间证书次之,根证书最后。

重新生成complete_chain.crt:

cat File_Wildcard.servername.com.crt ChainFile_ChainBundle.crt CA_GLOBALSIGN_ROOT_CA.crt > complete_chain.crt

将新生成的文件替换服务器上原有的complete_chain.crt。

二、简化Apache配置

Apache无需单独指定根证书,且代理到本地HTTPS端口会额外增加证书验证环节,建议调整为代理到Node的HTTP端口,由Apache统一处理HTTPS:

修改后的Apache配置文件(.conf):

<VirtualHost *:80>
    ServerName servername.com
    Redirect permanent / https://servername.com/
</VirtualHost>
<VirtualHost *:443>
    ServerName servername.com

    SSLEngine on
    SSLCertificateKeyFile /etc/apache2/ssl/KeyFile_Wildcard.servername.com_crt.key
    SSLCertificateFile /etc/apache2/ssl/complete_chain.crt

    ProxyRequests Off
    ProxyPreserveHost On
    # 代理到Node的HTTP端口,避免HTTPS嵌套验证
    ProxyPass / http://localhost:3005/
    ProxyPassReverse / http://localhost:3005/
</VirtualHost>

三、调整Node.js服务配置

既然Apache已经处理HTTPS,Node服务无需再启动HTTPS服务器,改成HTTP服务即可,减少证书配置复杂度:

修改后的app.js:

const express = require('express');
const orderRoutes = require('./routes/orderRoutes');
const swaggerUi = require('swagger-ui-express');
const swaggerJSDoc = require('swagger-jsdoc');
const swaggerDef = require('./utils/swaggerDef');

const app = express();

app.use(express.json());

const options = {
  swaggerDefinition: swaggerDef,
  apis: ['./routes/*.js', './controllers/*.js'],
};

const swaggerSpec = swaggerJSDoc(options);

app.use('/api-docs', swaggerUi.serve, swaggerUi.setup(swaggerSpec));
app.use('/api', orderRoutes);

const PORT = process.env.PORT || 3005;

app.listen(PORT, () => {
    console.log(`Server is running on port ${PORT}`);
});

module.exports = app;

四、重启服务并验证配置

  1. 重新加载Apache配置并重启服务:
sudo a2enmod ssl proxy proxy_http
sudo systemctl reload apache2
sudo systemctl restart apache2
  1. 重启Node服务:
# 假设你用pm2管理Node进程,若无则直接重启服务
pm2 restart app.js
  1. 用openssl验证证书链:
openssl s_client -connect servername.com:443 -showcerts

若输出末尾出现Verify return code: 0 (ok),说明证书链配置正确。

五、本地请求验证

本地发送API请求时,直接使用https://servername.com/api/xxx地址,此时应该不再出现证书验证错误。

内容的提问来源于stack exchange,提问作者seung

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 12:16:12