Nginx HTTPS端口配置求助:实现无端口访问及复用443端口
问题描述
默认HTTPS端口443已被占用,将Nginx的HTTPS端口切换为444后,网站只能通过https://example.com:444访问,直接访问https://example.com无法正常打开。需要配置实现无需显式指定端口即可访问网站,确保根URL(https://example.com)和子路径(如https://example.com/map)的所有请求都能正常跳转至目标页面。
当前Nginx配置
#user nobody; worker_processes 1; #error_log logs/error.log; #error_log logs/error.log notice; #error_log logs/error.log info; #pid logs/nginx.pid; events { worker_connections 1024; } http { include mime.types; default_type application/octet-stream; #log_format main '$remote_addr - $remote_user [$time_local] "&$request" ' # '$status $body_bytes_sent "&$http_referer" ' # '&"$http_user_agent" "&$http_x_forwarded_for"'; #access_log logs/access.log main; sendfile on; #tcp_nopush on; #keepalive_timeout 0; keepalive_timeout 65; #gzip on; server { listen 80; server_name example.com www.example.com; #charset koi8-r; #access_log logs/host.access.log main; location / { proxy_pass http://localhost:8080; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Host $http_host; } #error_page 404 /404.html; # redirect server error pages to the static page /50x.html # error_page 500 502 503 504 /50x.html; location = /50x.html { root html; } } # HTTPS server # server { #listen 444 ssl http2 default_server; #listen [::]:444 ssl http2 default_server; listen 444 ssl; server_name example.com www.example.com; # Disable root application access. You may want to allow this in development. #location ~ ^/$ { # return 404; #} ssl_certificate C:\Users\Administrator\Desktop\ssl\wildcard24.pem; ssl_certificate_key C:\Users\Administrator\Desktop\ssl\wildcard24.pem; ssl_password_file C:\Users\Administrator\Desktop\ssl\psw.txt; ssl_session_cache shared:SSL:1m; ssl_session_timeout 5m; ssl_ciphers HIGH:!aNULL:!MD5; ssl_prefer_server_ciphers on; location / { proxy_pass http://localhost:8080; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Host $http_host; } } }
解决方案
1. 释放443端口
首先需要找出并停止占用443端口的进程:
- 在Windows命令提示符中执行:
netstat -ano | findstr ":443",获取占用端口的PID - 打开任务管理器,切换到「详细信息」标签,找到对应PID的进程,右键选择「结束任务」
- 如果是系统服务(如IIS、Windows HTTP服务),可以通过「服务」面板停止对应的服务
2. 修改Nginx配置监听443端口
修改HTTPS server块的监听端口为443,并优化HTTP端口的跳转逻辑:
http { # ... 保留原有其他配置 ... # HTTP 80端口:自动跳转至HTTPS server { listen 80; server_name example.com www.example.com; # 所有HTTP请求跳转至HTTPS return 301 https://$server_name$request_uri; } # HTTPS server server { listen 443 ssl http2; listen [::]:443 ssl http2; # 支持IPv6 server_name example.com www.example.com; # ... 保留原有SSL证书、缓存、加密套件配置 ... location / { proxy_pass http://localhost:8080; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Host $http_host; } } }
关键说明
- 浏览器访问
https://example.com时会自动使用443端口,因此Nginx监听443后无需显式指定端口即可访问 - HTTP 80端口配置301跳转,确保用户输入
http://example.com时也会自动跳转到HTTPS地址,提升访问一致性 - 保留原有
proxy_set_header配置,确保后端服务能正确获取客户端信息
内容的提问来源于stack exchange,提问作者Andreas
相关产品推荐
相关产品推荐

