如何让Nextcloud的OnlyOffice与社区文档服务器适配自签名SSL证书
问题背景
基于官方Docker Compose(fpm+MariaDB)部署的Nextcloud 26.0.3,安装了documentserver_community 0.1.13和onlyoffice 7.8.0。在无SSL/正规SSL环境下功能正常,但使用自签名SSL时,执行occ onlyoffice:documentserver --check报错:
Error connection: cURL error 7: Failed to connect to localhost port 443: Connection refused (see https://curl.haxx.se/libcurl/c/libcurl-errors.html) for https://localhost/apps/documentserver_community/healthcheck
宿主机执行curl --insecure https://localhost/apps/documentserver_community/healthcheck可正常返回true,已添加verify_peer_off配置并导入证书,但问题仍存在。
解决方案
1. 修正核心网络问题:Docker容器内的localhost指向问题
Docker容器内的localhost是容器自身,而非宿主机。你的Nextcloud app容器是fpm模式,本身不监听443端口,443端口属于web代理容器(如nginx),因此app容器内访问localhost:443必然失败。
操作:
进入app容器,测试内部可访问的文档服务地址:
# 用Docker Compose服务名访问(假设web服务名称为web) sudo docker compose exec --user www-data app curl --insecure http://web/apps/documentserver_community/healthcheck # 或用宿主机IP访问(确保容器能通宿主机) sudo docker compose exec --user www-data app curl --insecure https://你的宿主机IP/apps/documentserver_community/healthcheck
能返回true的地址,就是你需要配置的正确地址。
2. 更新Nextcloud配置文件
修改nextcloud/config/config.php,指定正确的文档服务器地址并关闭证书校验:
'onlyoffice' => [ 'verify_peer_off' => true, 'DocumentServerUrl' => 'http://web/apps/documentserver_community/', // 替换为你测试通过的地址 ],
3. (可选)将自签名证书添加到容器系统信任库
如果容器间需要用HTTPS通信,需让app容器信任自签名证书:
# 复制证书到app容器 sudo docker cp localhost.crt 你的app容器名称:/usr/local/share/ca-certificates/localhost.crt # 更新证书缓存 sudo docker compose exec app update-ca-certificates # 重启app容器 sudo docker compose restart app
4. 重新执行检查命令
sudo docker compose exec --user www-data app php occ onlyoffice:documentserver --check
额外注意事项
- 官方
insecure示例默认用HTTP,若配置了SSL,需确保web代理容器(如nginx)正确挂载了自签名证书文件,并配置了443端口监听。 - 若使用反向代理,需确保Nextcloud的
trusted_domains配置包含访问域名/IP。
内容的提问来源于stack exchange,提问作者Василь Русин
相关产品推荐
相关产品推荐

