You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

容器化Classic ASP应用:Caddy反向代理HTTPS 502错误求助

容器化Classic ASP应用本地反向代理HTTPS访问502问题

当前环境配置

  • Hosts文件配置:
127.27.16.9   sub.mysite.com
  • Caddy反向代理配置(Caddyfile):
sub.mysite.com:80 {
    reverse_proxy 127.27.16.9:8086
}

sub.mysite.com:443 {
    reverse_proxy 127.27.16.9:8087
    tls star_mysite_com.pem wildcard_mysite_com.key
}
  • 容器端口映射:容器内80端口映射到本地8086,443端口映射到本地8087;HTTP模式下访问http://sub.mysite.com正常。

证书导入与IIS绑定操作

持有Digicert提供的PFX格式证书,通过以下PowerShell命令导入证书并配置IIS站点绑定:

$pwd = ConvertTo-SecureString -String "password" -AsPlainText -Force
$cert = Import-PfxCertificate -Password $pwd -FilePath "c:\cert\wildcard_mysite_com.pfx" -CertStoreLocation Cert:\LocalMachine\My
New-IISSiteBinding -Name MySite -BindingInformation "*:443:sub.mysite.com" -CertificateThumbPrint $cert.Thumbprint -CertStoreLocation "cert:\LocalMachine\my"  -Protocol "https"

执行Get-Website查看站点绑定信息,结果显示绑定配置正常:

Name     ID   State      Physical Path           Bindings
----     --   -----      -------------           --------
MySite   1387 Started    c:\webcode              http *:80:
                 7529                            https *:443:sub.mysite.com sslFlags=0

问题现象

访问https://sub.mysite.com时出现502错误,Caddy日志报错内容如下:

http.log.error  read tcp 127.0.0.1:59340->127.27.16.9:8087: wsarecv: An existing connection was forcibly closed by the remote host.     
{"request": {"remote_ip": "127.0.0.1", "remote_port": "59338", "client_ip": "127.0.0.1", "proto": "HTTP/2.0", "method": "GET", "host": "sub.mysite.com", "uri": "/", "headers": {"Sec-Ch-Ua": ["\"Not/A)Brand\";v=\"99\", \"Google Chrome\";v=\"115\", \"Chromium\";v=\"115\""], "Upgrade-Insecure-Requests": ["1"], "Sec-Fetch-Mode": ["navigate"], "Accept": ["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7"], "Sec-Fetch-Site": ["none"], "Accept-Encoding": ["gzip, deflate, br"], "Accept-Language": ["en-US,en;q=0.9,la;q=0.8"], "Sec-Ch-Ua-Mobile": ["?0"], "Sec-Ch-Ua-Platform": ["\"Windows\""], "Dnt": ["1"], "User-Agent": ["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36"], "Sec-Fetch-User": ["?1"], "Sec-Fetch-Dest": ["document"], "Cookie": []}, "tls": {"resumed": false, "version": 772, "cipher_suite": 4865, "proto": "h2", "server_name": "sub.mysite.com"}}, "duration": 0.0057207, "status": 502, "err_id": "zv6amhucn", "err_trace": "reverseproxy.statusError (reverseproxy.go:1248)"}

补充排查结果

  • 启用FailedRequestsLogging后,容器外部发起的请求未生成日志,仅Caddy报错;
  • 在容器内Hosts文件添加120.0.0.1 sub.mysite.com后,执行curl https://sub.mysite.com -UseBasicParsing可正常获取响应并生成日志;
  • 直接访问https://sub.mysite.com:8087(本地8087端口映射到容器内443端口)正常,证书验证有效,说明问题出在反向代理配置环节。

初步分析与解决方案计划

初步怀疑证书格式不兼容:容器使用PFX证书,Caddy要求PEM格式证书(两者均为Digicert直接下载,未做格式转换)。计划尝试两种方式解决:

  • 重新导入.cer格式证书;
  • 从现有PFX证书生成PEM格式证书及对应私钥。
    另外,不局限于Caddy,正在寻找Windows本地环境下最简单的反向代理方案。

内容的提问来源于stack exchange,提问作者Jay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 09:29:54