如何在IIS上配置Web.config运行ASGI应用及实现HTTPS支持
问题描述
原本在IIS服务器上通过FastCGI配置了WSGI模式的Django项目,Web.config配置如下:
<?xml version="1.0" encoding="utf-8"?> <configuration> <system.webServer> <handlers> <clear /> <remove name="Python-FastCGI" /> <remove name="Python27_via_FastCGI" /> <remove name="Python34_via_FastCGI" /> <add name="Python FastCGI" path="*" verb="*" modules="FastCgiModule" scriptProcessor="c:\users\administrator\appdata\local\programs\python\python37-32\python.exe|c:\users\administrator\appdata\local\programs\python\python37-32\lib\site-packages\wfastcgi.py" resourceType="Unspecified" /> </handlers> <directoryBrowse enabled="false" /> <httpProtocol> <customHeaders> <add name="Expires" value="1" /> </customHeaders> </httpProtocol> <staticContent> <clientCache cacheControlMode="UseMaxAge" cacheControlMaxAge="1.00:00:00" /> </staticContent> </system.webServer> <appSettings> <add key="WSGI_HANDLER" value="django_site.wsgi.application" /> <add key="PYTHONPATH" value="C:\Hosted\django_site" /> <add key="DJANGO_SETTINGS_MODULE" value="django_site.settings" /> </appSettings> </configuration>
引入Channels后,应用只能通过命令行py -m daphne django_site.asgi:application -b abc.xyz运行,且不支持HTTPS。现有两个需求:
- 如何正确配置Web.config,让IIS支持运行ASGI应用?
- 若上述方案不可行,如何让命令行运行的ASGI应用支持HTTPS(如https://abc.xyz)?
已部署Let's Encrypt证书,但无法配置安全协议。尝试过的Web.config配置如下:
<configuration> <system.webServer> <handlers accessPolicy="Read, Execute, Script"> <add name="httpplatformhandler" path="*" verb="*" modules="httpPlatformHandler" resourceType="Unspecified" requireAccess="Script" /> </handlers> <httpPlatform processPath="C:\Project\myApp\Scripts\python.exe" arguments="-m daphne myApp.asgi:application -b abc.xyz" startupTimeLimit="10" startupRetryCount="10" stdoutLogEnabled="true" stdoutLogFile="\.\logs\"> <environmentVariables> <environmentVariable name="myApp" value="bar" /> </environmentVariables> </httpPlatform> </system.webServer> </configuration>
IIS日志显示Daphne监听8000端口,希望去掉该端口但无法实现。
解决方案
1. 配置IIS支持ASGI应用(修正Web.config)
使用IIS的HttpPlatformHandler是正确方向,调整配置让IIS负责端口转发,Daphne仅本地监听即可:
修正后的Web.config示例:
<?xml version="1.0" encoding="utf-8"?> <configuration> <system.webServer> <handlers> <clear /> <add name="httpplatformhandler" path="*" verb="*" modules="httpPlatformHandler" resourceType="Unspecified" requireAccess="Script" /> </handlers> <httpPlatform processPath="C:\Project\myApp\Scripts\python.exe" arguments="-m daphne -b 127.0.0.1 -p 8000 django_site.asgi:application" startupTimeLimit="30" stdoutLogEnabled="true" stdoutLogFile=".\logs\daphne_stdout.log"> <environmentVariables> <environmentVariable name="PYTHONPATH" value="C:\Hosted\django_site" /> <environmentVariable name="DJANGO_SETTINGS_MODULE" value="django_site.settings" /> </environmentVariables> </httpPlatform> <!-- 保留原有静态资源相关配置 --> <directoryBrowse enabled="false" /> <httpProtocol> <customHeaders> <add name="Expires" value="1" /> </customHeaders> </httpProtocol> <staticContent> <clientCache cacheControlMode="UseMaxAge" cacheControlMaxAge="1.00:00:00" /> </staticContent> </system.webServer> </configuration>
关键调整点:
- 让Daphne绑定
127.0.0.1:8000,仅本地监听,由IIS对外接收请求并转发 - 补充
PYTHONPATH和DJANGO_SETTINGS_MODULE环境变量,确保Django能正确加载项目配置 - 调整日志路径为具体文件,避免目录权限问题
- 延长启动超时时间,保证Daphne完全启动
另外需确认IIS已安装HttpPlatformHandler模块,未安装可通过Web平台安装器下载部署。
2. 让命令行运行的Daphne支持HTTPS
直接启动Daphne时,指定Let's Encrypt的证书文件路径即可:
py -m daphne -b abc.xyz -p 443 --ssl-certificate "C:\path\to\fullchain.pem" --ssl-key "C:\path\to\privkey.pem" django_site.asgi:application
注意事项:
- 绑定443端口需要管理员权限运行命令
- Let's Encrypt证书通常存放在
C:\Certbot\live\abc.xyz目录,fullchain.pem为证书链文件,privkey.pem为私钥文件 - 若不想用443端口,可指定其他端口(如8443),但访问时需附加端口号;也可通过IIS反向代理转发到该端口
- 若遇到证书权限问题,需给运行Python的用户授予证书文件的读取权限
内容的提问来源于stack exchange,提问作者Сергей Немец
相关产品推荐
相关产品推荐

