Nginx反向代理SSL握手失败:wrong version number错误求助
Nginx反向代理SSL握手错误(错误代码500)排查
错误日志信息
错误代码:500
2023/07/30 09:55:29 [error] 4277#4277: *54 SSL_do_handshake() 失败
(SSL: error:0A00010B:SSL routines::wrong version number),在与上游服务器进行SSL握手时,客户端:192.168.0.1,服务器:myserver.com,
请求:"GET / HTTP/2.0",上游服务器:"https://192.168.0.36:8081/",
主机:"myserver.com"
环境信息
- 192.168.0.1:路由器
- 192.168.0.36:运行在8081端口的NextCloud服务器(仅HTTP协议可正常工作)
- 192.168.0.37:Nginx网页服务器
- 域名
myserver.com指向192.168.0.37,通过Nginx的proxy_pass转发至192.168.0.36的NextCloud
当前Nginx SSL配置文件
server { listen 192.168.0.37:443 ssl; server_name myserver.com ; error_log /var/log/apache2/domains/myserver.com.error.log error; ssl_certificate /home/user1/conf/web/myserver.com/ssl/myserver.com.pem; ssl_certificate_key /home/user1/conf/web/myserver.com/ssl/myserver.com.key; ssl_stapling on; ssl_stapling_verify on; # TLS 1.3 0-RTT anti-replay if ($anti_replay = 307) { return 307 https://$host$request_uri; } if ($anti_replay = 425) { return 425; } include /home/user1/conf/web/myserver.com/nginx.hsts.conf*; location ~ /\.(?!well-known\/|file) { deny all; return 404; } location / { proxy_pass https://192.168.0.36:8081; location /error/ { alias /home/user1/web/myserver.com/document_errors/; } proxy_hide_header Upgrade; include /home/user1/conf/web/myserver.com/nginx.ssl.conf_*; }
已尝试的无效操作
添加以下配置后问题未解决:
proxy_ssl_name myserver.com; proxy_ssl_server_name on;
问题分析与解决方案
问题根源
错误wrong version number的核心原因是:上游NextCloud服务器仅支持HTTP协议,而你在proxy_pass中使用了https://协议头,导致Nginx向一个只懂HTTP的端口发起SSL握手请求,双方协议不匹配自然报错。
解决步骤
- 修改
proxy_pass协议为HTTP
直接将location /块中的proxy_pass目标协议改为http://,因为上游本身用HTTP提供服务:location / { proxy_pass http://192.168.0.36:8081; # 保留原有其他配置 } - 验证配置并重启Nginx
先检查配置语法是否正确:
确认无错误后重启服务:nginx -tsudo systemctl restart nginx - 可选:上游加密通信配置(若需要)
如果你想让Nginx和NextCloud之间的通信加密,需要先给NextCloud配置HTTPS(比如在NextCloud端部署SSL证书,监听HTTPS端口),之后再将proxy_pass改回https://,此时之前添加的proxy_ssl_name等配置才会生效。
额外说明
之前添加的proxy_ssl_name和proxy_ssl_server_name是用于上游支持HTTPS时的配置,现在上游用HTTP,这些配置可以直接移除。
内容的提问来源于stack exchange,提问作者ывапав
相关产品推荐
相关产品推荐

