配置Nginx反向代理WSS访问Spring Boot遇403错误求助
配置Nginx反向代理WebSocket时出现403错误的排查与解决
我尝试配置支持WS的Nginx反向代理,但访问https://game.memoux.com/时出现403(禁止访问)错误,WebSocket无法正常工作。不过直接访问http://game.memoux.com:8080时一切正常,说明问题出在Nginx配置而非后端Spring Boot应用。
当前Nginx配置文件
server { root /var/www/html8080; server_name game.memoux.com; # managed by Certbot listen 443 ssl; # managed by Certbot ssl_certificate /etc/letsencrypt/live/game.memoux.com/fullchain.pem; # managed by Certbot ssl_certificate_key /etc/letsencrypt/live/game.memoux.com/privkey.pem; # managed by Certbot include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot location / { # redirect all HTTP traffic to localhost:8080 proxy_pass http://localhost:8080; proxy_set_header X-Real-IP $remote_addr; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; # WebSocket support (nginx 1.4) proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; } }
Nginx错误日志(2023年11月5日)
2023/11/05 01:46:15 [crit] 705581#705581: *2917 SSL_do_handshake() failed (SSL: error:0A00006C:SSL routines::bad key share) while SSL handshaking, client: 167.172.240.54, server: 0.0.0.0:443 2023/11/05 02:14:22 [error] 705581#705581: *2937 connect() failed (111: Connection refused) while connecting to upstream, client: 36.99.136.129, server: memoux.com, request: "GET / HTTP/1.1", upstream: "http://[::1]:3000/", host: "memoux.com" 2023/11/05 02:14:36 [error] 705581#705581: *2975 connect() failed (111: Connection refused) while connecting to upstream, client: 146.70.192.180, server: memoux.com, request: "GET /_next/static/chunks/framework-2c79e2a64abdb08b.js HTTP/1.1", upstream: > 2023/11/05 04:13:33 [crit] 705581#705581: *3022 SSL_do_handshake() failed (SSL: error:0A00006C:SSL routines::bad key share) while SSL handshaking, client: 65.49.1.17, server: 0.0.0.0:443 2023/11/05 06:51:34 [crit] 705581#705581: *3087 SSL_do_handshake() failed (SSL: error:0A00006C:SSL routines::bad key share) while SSL handshaking, client: 212.102.40.218, server: 0.0.0.0:443 2023/11/05 07:10:27 [crit] 705581#705581: *3110 SSL_do_handshake() failed (SSL: error:0A00006C:SSL routines::bad key share) while SSL handshaking, client: 68.183.200.199, server: 0.0.0.0:443 2023/11/05 07:44:42 [crit] 705581#705581: *3136 SSL_do_handshake() failed (SSL: error:0A00006C:SSL routines::bad key share) while SSL handshaking, client: 104.131.184.235, server: 0.0.0.0:443 2023/11/05 07:47:26 [crit] 705581#705581: *3147 SSL_do_handshake() failed (SSL: error:0A00006C:SSL routines::bad key share) while SSL handshaking, client: 35.216.204.22, server: 0.0.0.0:443 2023/11/05 08:25:08 [error] 705581#705581: *3177 connect() failed (111: Connection refused) while connecting to upstream, client: 3.249.231.245, server: memoux.com, request: "GET / HTTP/1.0", upstream: "http://[::1]:3000/", host: "memoux.com" 2023/11/05 11:02:06 [crit] 705581#705581: *3217 SSL_do_handshake() failed (SSL: error:0A00006C:SSL routines::bad key share) while SSL handshaking, client: 87.236.176.112, server: 0.0.0.0:443
错误截图

排查与解决步骤
1. 移除无效的root配置
配置中的root /var/www/html8080;属于冗余设置,Nginx会优先尝试访问本地文件目录而非转发到上游服务。当该目录不存在或权限不足时,直接返回403错误。删除这一行配置即可避免本地文件查找逻辑干扰反向代理。
2. 修复SSL握手错误
日志中频繁出现的SSL_do_handshake() failed是由于SSL密钥交换算法不兼容导致的,调整SSL配置解决:
- 打开
/etc/letsencrypt/options-ssl-nginx.conf,替换加密套件为兼容版本:ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384; - 添加TLS版本限制,确保仅启用安全协议:
ssl_protocols TLSv1.2 TLSv1.3;
3. 补充WebSocket长连接配置
WebSocket需要保持长连接,在location /块中添加以下超时配置:
proxy_set_header X-Forwarded-Proto $scheme; proxy_read_timeout 86400; proxy_send_timeout 86400; proxy_connect_timeout 75;
4. 验证SSL证书权限
确保Nginx运行用户(通常为www-data)对SSL证书目录有读取权限:
chown -R www-data:www-data /etc/letsencrypt/live/game.memoux.com/ chmod -R 755 /etc/letsencrypt/live/game.memoux.com/
5. 重启Nginx生效
修改配置后先验证语法正确性:
nginx -t
确认无错误后重启Nginx:
systemctl restart nginx
内容的提问来源于stack exchange,提问作者degr
相关产品推荐
相关产品推荐

