You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用自签名证书时localhost可访问但127.0.0.1无法访问的问题

问题分析

核心问题是自签名证书的主机名匹配失败:

  • 你生成证书时指定的CN是eventstore.com,用127.0.0.1访问时,证书标识与请求主机名不匹配,导致TLS握手阶段服务端直接关闭连接。
  • localhost能访问是因为浏览器对localhost的证书验证有宽松处理,并非证书本身匹配localhost。
解决方案

1. 重新生成含127.0.0.1和localhost的自签名证书

用OpenSSL生成带SAN(Subject Alternative Name)扩展的证书,覆盖所有需要的访问地址:

# 创建临时配置文件,添加SAN扩展
cat > ssl.conf << EOF
[req]
default_bits = 2048
prompt = no
default_md = sha256
distinguished_name = dn
req_extensions = req_ext

[dn]
CN = localhost

[req_ext]
subjectAltName = @alt_names

[alt_names]
DNS.1 = localhost
IP.1 = 127.0.0.1
EOF

# 生成证书和密钥
openssl req -x509 -sha256 -nodes -days 365 -config ssl.conf -newkey rsa:2048 -keyout eventstore.pem -out eventstore.crt

# 转换为EventStore需要的PKCS12格式
openssl pkcs12 -export -inkey eventstore.pem -in eventstore.crt -out eventstore.p12 -passout pass:

2. 更新EventStore配置

确保eventstore.conf指定正确证书路径,且绑定地址包含目标访问地址:

# 证书配置
CertificateFile: eventstore.p12
CertificatePassword: "" # 对应上面生成时的空密码

# 绑定地址(保留127.0.0.1,也可添加localhost)
HttpPrefixes: ["https://127.0.0.1:2113", "https://localhost:2113"]

3. 修复Windows本地运行的问题

Windows下--dev模式的默认证书同样缺少127.0.0.1的SAN,可替换为自定义证书启动:

.\EventStore.ClusterNode.exe --dev --certificate-file=eventstore.p12 --certificate-password=""

4. 信任证书(可选,消除浏览器警告)

  • Windows:双击eventstore.crt,安装到受信任的根证书颁发机构
  • WSL:将证书复制到/usr/local/share/ca-certificates/,执行update-ca-certificates
关键说明

现代TLS协议和浏览器要求证书通过SAN扩展明确列出允许的DNS名称和IP地址,仅靠CN字段已无法通过严格验证。这就是用127.0.0.1访问时直接断开连接的原因——服务端在TLS握手时检测到主机名不匹配,主动终止了连接。

内容的提问来源于stack exchange,提问作者patrick

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 03:16:19