You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx反向代理SSL握手失败:wrong version number错误求助

Nginx反向代理SSL握手错误(错误代码500)排查

错误日志信息

错误代码:500
2023/07/30 09:55:29 [error] 4277#4277: *54 SSL_do_handshake() 失败
(SSL: error:0A00010B:SSL routines::wrong version number),在与上游服务器进行SSL握手时,客户端:192.168.0.1,服务器:myserver.com,
请求:"GET / HTTP/2.0",上游服务器:"https://192.168.0.36:8081/",
主机:"myserver.com"

环境信息

  • 192.168.0.1:路由器
  • 192.168.0.36:运行在8081端口的NextCloud服务器(仅HTTP协议可正常工作)
  • 192.168.0.37:Nginx网页服务器
  • 域名myserver.com指向192.168.0.37,通过Nginx的proxy_pass转发至192.168.0.36的NextCloud

当前Nginx SSL配置文件

server {
    listen      192.168.0.37:443 ssl;
    server_name myserver.com ;
    error_log   /var/log/apache2/domains/myserver.com.error.log error;

    ssl_certificate     /home/user1/conf/web/myserver.com/ssl/myserver.com.pem;
    ssl_certificate_key /home/user1/conf/web/myserver.com/ssl/myserver.com.key;
    ssl_stapling        on;
    ssl_stapling_verify on;

    # TLS 1.3 0-RTT anti-replay
    if ($anti_replay = 307) { return 307 https://$host$request_uri; }
    if ($anti_replay = 425) { return 425; }

    include /home/user1/conf/web/myserver.com/nginx.hsts.conf*;

    location ~ /\.(?!well-known\/|file) {
        deny all;
        return 404;
    }

    location / {
        proxy_pass https://192.168.0.36:8081;

    location /error/ {
        alias /home/user1/web/myserver.com/document_errors/;
    }
    proxy_hide_header Upgrade;

    include /home/user1/conf/web/myserver.com/nginx.ssl.conf_*;
}

已尝试的无效操作

添加以下配置后问题未解决:

proxy_ssl_name myserver.com;
proxy_ssl_server_name on;

问题分析与解决方案

问题根源

错误wrong version number的核心原因是:上游NextCloud服务器仅支持HTTP协议,而你在proxy_pass中使用了https://协议头,导致Nginx向一个只懂HTTP的端口发起SSL握手请求,双方协议不匹配自然报错。

解决步骤

  1. 修改proxy_pass协议为HTTP
    直接将location /块中的proxy_pass目标协议改为http://,因为上游本身用HTTP提供服务:
    location / {
        proxy_pass http://192.168.0.36:8081;
        # 保留原有其他配置
    }
    
  2. 验证配置并重启Nginx
    先检查配置语法是否正确:
    nginx -t
    
    确认无错误后重启服务:
    sudo systemctl restart nginx
    
  3. 可选:上游加密通信配置(若需要)
    如果你想让Nginx和NextCloud之间的通信加密,需要先给NextCloud配置HTTPS(比如在NextCloud端部署SSL证书,监听HTTPS端口),之后再将proxy_pass改回https://,此时之前添加的proxy_ssl_name等配置才会生效。

额外说明

之前添加的proxy_ssl_name和proxy_ssl_server_name是用于上游支持HTTPS时的配置,现在上游用HTTP,这些配置可以直接移除。

内容的提问来源于stack exchange,提问作者ывапав

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 02:12:32