You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx配置异常导致自定义SSL证书无法启动BigBlueButton

问题描述

我在Ubuntu 20.04家用服务器上安装BigBlueButton,执行命令:

sudo ./bbb-install.sh -w -v focal-270 -s bigbluebutton.mycustomdomain.org

我已经拥有bigbluebutton.mycustomdomain.org的有效Let's Encrypt SSL证书,尝试单独使用-e、-x、-d(将证书软链接到/local/certs)参数,以及不使用这些参数,都会得到相同错误:

# Potential problems described below
curl: (60) SSL: no alternative certificate subject name matches target host name 'bigbluebutton.mycustomdomain.org'
More details here: https://curl.haxx.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the web page mentioned above.
.curl: (60) SSL: no alternative certificate subject name matches target host name 'bigbluebutton.mycustomdomain.org'
More details here: https://curl.haxx.se/docs/sslcerts.html

在浏览器访问https://bigbluebutton.mycustomdomain.org时,显示Nginx默认页或自定义站点,且提示SSL证书无效(属于其他域名)。

安装脚本生成的Nginx配置文件/etc/nginx/sites-available/bigbluebutton(已链接到/etc/nginx/sites-enabled/bigbluebutton)内容如下:

server_tokens off;

server {
  listen 80;
  listen [::]:80;
  server_name bigbluebutton.mycustomdomain.org;

  location ^~ / {
    return 301 https://$server_name$request_uri; #redirect HTTP to HTTPS
  }

  location ^~ /.well-known/acme-challenge/ {
    allow all;
    default_type "text/plain";
    root /var/www/bigbluebutton-default/assets;
  }

  location = /.well-known/acme-challenge/ {
    return 404;
  }
}

set_real_ip_from 127.0.0.1;
real_ip_header proxy_protocol;
real_ip_recursive on;
server {
  # this double listenting is intended. We terminate SSL on haproxy. HTTP2 is a
  # binary protocol. haproxy has to decide which protocol is spoken. This is
  # negotiated by ALPN.
  #
  # Depending on the ALPN value traffic is redirected to either port 82 (HTTP2,
  # ALPN value h2) or 81 (HTTP 1.0 or HTTP 1.1, ALPN value http/1.1 or no value)

  listen 127.0.0.1:82 http2 proxy_protocol;
  listen [::1]:82 http2;
  listen 127.0.0.1:81 proxy_protocol;
  listen [::1]:81;
  server_name bigbluebutton.mycustomdomain.org;

  # nginx does not know its external port/protocol behind haproxy, so use relative redirects.
  absolute_redirect off;
    
  # HSTS (uncomment to enable)
  #add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;

  access_log  /var/log/nginx/bigbluebutton.access.log;

  # This variable is used instead of $scheme by bigbluebutton nginx include
  # files, so $scheme can be overridden in reverse-proxy configurations.
  set $real_scheme "https";

  # BigBlueButton landing page.
  location / {
    root   /var/www/bigbluebutton-default/assets;
    try_files $uri @bbb-fe;
  }

  # Include specific rules for record and playback
  include /etc/bigbluebutton/nginx/*.nginx;
}

我尝试像配置其他站点一样添加SSL证书配置,但无效:

ssl_certificate /etc/letsencrypt/live/bigbluebutton.mycustomdomain.org/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/bigblugbutton.mycustomdomain.org/privkey.pem;

注:这里证书路径存在拼写错误(bigblugbutton应为bigbluebutton)。我猜测原因是缺少HTTPS的443端口server块,但不确定如何正确配置BigBlueButton使用已有SSL证书。


解决方案

BigBlueButton默认使用HAProxy处理443端口的SSL终止,而非直接在Nginx中配置SSL,这就是你修改Nginx配置无效的原因。按以下步骤操作:

  1. 编辑HAProxy配置文件
    打开HAProxy的主配置文件:

    sudo nano /etc/haproxy/haproxy.cfg
    
  2. 配置SSL证书路径
    在文件中找到对应443端口的frontend http-https配置段,原配置类似:

    frontend http-https
        bind *:80
        bind *:443 ssl crt /etc/haproxy/certs/
        ...
    

    HAProxy要求证书与密钥合并为单个.pem文件,先合并你的Let's Encrypt证书:

    sudo cat /etc/letsencrypt/live/bigbluebutton.mycustomdomain.org/fullchain.pem /etc/letsencrypt/live/bigbluebutton.mycustomdomain.org/privkey.pem > /etc/haproxy/certs/bigbluebutton.mycustomdomain.org.pem
    sudo chmod 600 /etc/haproxy/certs/bigbluebutton.mycustomdomain.org.pem
    

    然后修改HAProxy配置中的bind行,指定合并后的证书路径:

    bind *:443 ssl crt /etc/haproxy/certs/bigbluebutton.mycustomdomain.org.pem
    
  3. 验证配置并重启HAProxy
    检查HAProxy配置语法是否正确:

    sudo haproxy -c -f /etc/haproxy/haproxy.cfg
    

    无报错则重启服务:

    sudo systemctl restart haproxy
    
  4. 清理冲突的Nginx配置
    确保没有其他Nginx站点(如默认的default.conf)监听443端口,避免端口抢占:

    sudo unlink /etc/nginx/sites-enabled/default
    sudo systemctl reload nginx
    
  5. 验证生效
    用curl测试SSL连接:

    curl -v https://bigbluebutton.mycustomdomain.org
    

    或在浏览器中访问,确认证书有效且显示BigBlueButton页面。


内容的提问来源于stack exchange,提问作者ezze

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 12:00:53