Nginx配置异常导致自定义SSL证书无法启动BigBlueButton
我在Ubuntu 20.04家用服务器上安装BigBlueButton,执行命令:
sudo ./bbb-install.sh -w -v focal-270 -s bigbluebutton.mycustomdomain.org
我已经拥有bigbluebutton.mycustomdomain.org的有效Let's Encrypt SSL证书,尝试单独使用-e、-x、-d(将证书软链接到/local/certs)参数,以及不使用这些参数,都会得到相同错误:
# Potential problems described below curl: (60) SSL: no alternative certificate subject name matches target host name 'bigbluebutton.mycustomdomain.org' More details here: https://curl.haxx.se/docs/sslcerts.html curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the web page mentioned above. .curl: (60) SSL: no alternative certificate subject name matches target host name 'bigbluebutton.mycustomdomain.org' More details here: https://curl.haxx.se/docs/sslcerts.html
在浏览器访问https://bigbluebutton.mycustomdomain.org时,显示Nginx默认页或自定义站点,且提示SSL证书无效(属于其他域名)。
安装脚本生成的Nginx配置文件/etc/nginx/sites-available/bigbluebutton(已链接到/etc/nginx/sites-enabled/bigbluebutton)内容如下:
server_tokens off; server { listen 80; listen [::]:80; server_name bigbluebutton.mycustomdomain.org; location ^~ / { return 301 https://$server_name$request_uri; #redirect HTTP to HTTPS } location ^~ /.well-known/acme-challenge/ { allow all; default_type "text/plain"; root /var/www/bigbluebutton-default/assets; } location = /.well-known/acme-challenge/ { return 404; } } set_real_ip_from 127.0.0.1; real_ip_header proxy_protocol; real_ip_recursive on; server { # this double listenting is intended. We terminate SSL on haproxy. HTTP2 is a # binary protocol. haproxy has to decide which protocol is spoken. This is # negotiated by ALPN. # # Depending on the ALPN value traffic is redirected to either port 82 (HTTP2, # ALPN value h2) or 81 (HTTP 1.0 or HTTP 1.1, ALPN value http/1.1 or no value) listen 127.0.0.1:82 http2 proxy_protocol; listen [::1]:82 http2; listen 127.0.0.1:81 proxy_protocol; listen [::1]:81; server_name bigbluebutton.mycustomdomain.org; # nginx does not know its external port/protocol behind haproxy, so use relative redirects. absolute_redirect off; # HSTS (uncomment to enable) #add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; access_log /var/log/nginx/bigbluebutton.access.log; # This variable is used instead of $scheme by bigbluebutton nginx include # files, so $scheme can be overridden in reverse-proxy configurations. set $real_scheme "https"; # BigBlueButton landing page. location / { root /var/www/bigbluebutton-default/assets; try_files $uri @bbb-fe; } # Include specific rules for record and playback include /etc/bigbluebutton/nginx/*.nginx; }
我尝试像配置其他站点一样添加SSL证书配置,但无效:
ssl_certificate /etc/letsencrypt/live/bigbluebutton.mycustomdomain.org/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/bigblugbutton.mycustomdomain.org/privkey.pem;
注:这里证书路径存在拼写错误(bigblugbutton应为bigbluebutton)。我猜测原因是缺少HTTPS的443端口server块,但不确定如何正确配置BigBlueButton使用已有SSL证书。
BigBlueButton默认使用HAProxy处理443端口的SSL终止,而非直接在Nginx中配置SSL,这就是你修改Nginx配置无效的原因。按以下步骤操作:
编辑HAProxy配置文件
打开HAProxy的主配置文件:sudo nano /etc/haproxy/haproxy.cfg配置SSL证书路径
在文件中找到对应443端口的frontend http-https配置段,原配置类似:frontend http-https bind *:80 bind *:443 ssl crt /etc/haproxy/certs/ ...HAProxy要求证书与密钥合并为单个
.pem文件,先合并你的Let's Encrypt证书:sudo cat /etc/letsencrypt/live/bigbluebutton.mycustomdomain.org/fullchain.pem /etc/letsencrypt/live/bigbluebutton.mycustomdomain.org/privkey.pem > /etc/haproxy/certs/bigbluebutton.mycustomdomain.org.pem sudo chmod 600 /etc/haproxy/certs/bigbluebutton.mycustomdomain.org.pem然后修改HAProxy配置中的
bind行,指定合并后的证书路径:bind *:443 ssl crt /etc/haproxy/certs/bigbluebutton.mycustomdomain.org.pem验证配置并重启HAProxy
检查HAProxy配置语法是否正确:sudo haproxy -c -f /etc/haproxy/haproxy.cfg无报错则重启服务:
sudo systemctl restart haproxy清理冲突的Nginx配置
确保没有其他Nginx站点(如默认的default.conf)监听443端口,避免端口抢占:sudo unlink /etc/nginx/sites-enabled/default sudo systemctl reload nginx验证生效
用curl测试SSL连接:curl -v https://bigbluebutton.mycustomdomain.org或在浏览器中访问,确认证书有效且显示BigBlueButton页面。
内容的提问来源于stack exchange,提问作者ezze

