You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Django+Nginx部署SSL后网站无法访问及服务器名冲突排查

Django Channels + Nginx SSL部署问题排查方案

1. 解决Nginx Server Name冲突警告

  • 执行nginx -T命令查看完整生效的Nginx配置,搜索www.aniconnect.org,找出所有定义该域名的server块
  • 检查/etc/nginx/sites-available/、/etc/nginx/sites-enabled/以及/etc/nginx/conf.d/目录下的所有配置文件,删除重复的server块,或合并相同域名的配置规则
  • 修改后执行nginx -s reload重启Nginx,确认警告是否消失

2. 排查SSL握手失败问题

2.1 验证DNS解析有效性

  • 执行dig www.aniconnect.org或nslookup www.aniconnect.org,确认返回的IP地址与服务器公网IP一致
  • 若解析未生效,等待DNS缓存过期(通常10-30分钟),或联系域名服务商刷新DNS记录
  • 本地可尝试清除DNS缓存(Windows用ipconfig /flushdns,Linux用systemd-resolve --flush-caches)

2.2 检查Nginx SSL配置正确性

  • 确认certbot生成的证书路径配置正确:
    ssl_certificate /etc/letsencrypt/live/www.aniconnect.org/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/www.aniconnect.org/privkey.pem;
    
  • 检查证书文件权限:确保Nginx进程(通常是www-data用户)能读取证书文件,可执行chmod 644 /etc/letsencrypt/live/www.aniconnect.org/*.pem
  • 确认服务器防火墙开放443端口:
    • UFW防火墙:执行ufw allow 443/tcp
    • iptables:执行iptables -A INPUT -p tcp --dport 443 -j ACCEPT
  • 用openssl s_client -connect www.aniconnect.org:443查看SSL握手详情,重点关注Verify return code字段,返回0则证书验证正常,非0则对应排查证书过期、域名不匹配等问题

2.3 检查WebSocket SSL配置

由于应用使用Django Channels,需确保Nginx对WebSocket请求的代理配置正确,添加以下规则到SSL的server块中:

location /ws/ {
    proxy_pass http://127.0.0.1:8000;  # 对应Gunicorn/ASGI服务器的地址
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection "upgrade";
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
}

3. 处理hetong.js找不到的异常

  • 搜索所有Nginx配置文件,查找是否有引入该文件的规则:
    grep -r "hetong.js" /etc/nginx/
    
  • 若找到相关配置行,直接删除(非自定义文件无需保留),重启Nginx
  • 用curl -v https://www.aniconnect.org查看页面响应,确认该请求是否来自页面HTML中的引用,若存在则检查Django模板是否有残留代码,或清除浏览器缓存后重新访问

通用排查步骤

  • 实时查看Nginx错误日志:tail -f /var/log/nginx/error.log,获取SSL握手失败、文件缺失的具体错误信息
  • 确认Gunicorn/ASGI服务器正常运行:systemctl status gunicorn(若用systemd管理),确保服务未崩溃

内容的提问来源于stack exchange,提问作者user21744561

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 05:32:48