You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在IIS上配置Web.config运行ASGI应用及实现HTTPS支持

问题描述

原本在IIS服务器上通过FastCGI配置了WSGI模式的Django项目,Web.config配置如下:

<?xml version="1.0" encoding="utf-8"?>
<configuration>
  <system.webServer>
    
    <handlers>
      <clear />
      <remove name="Python-FastCGI" />
      <remove name="Python27_via_FastCGI" />
      <remove name="Python34_via_FastCGI" />
      <add name="Python FastCGI" path="*" verb="*" modules="FastCgiModule" scriptProcessor="c:\users\administrator\appdata\local\programs\python\python37-32\python.exe|c:\users\administrator\appdata\local\programs\python\python37-32\lib\site-packages\wfastcgi.py" resourceType="Unspecified" />
    </handlers>
        <directoryBrowse enabled="false" />
        <httpProtocol>
            <customHeaders>
                <add name="Expires" value="1" />
            </customHeaders>
        </httpProtocol>
        <staticContent>
            <clientCache cacheControlMode="UseMaxAge" cacheControlMaxAge="1.00:00:00" />
        </staticContent>
  </system.webServer>
  <appSettings>
    <add key="WSGI_HANDLER" value="django_site.wsgi.application" />
    <add key="PYTHONPATH" value="C:\Hosted\django_site" />    
    <add key="DJANGO_SETTINGS_MODULE" value="django_site.settings" />
  </appSettings>
</configuration>

引入Channels后,应用只能通过命令行py -m daphne django_site.asgi:application -b abc.xyz运行,且不支持HTTPS。现有两个需求:

  1. 如何正确配置Web.config,让IIS支持运行ASGI应用?
  2. 若上述方案不可行,如何让命令行运行的ASGI应用支持HTTPS(如https://abc.xyz)?

已部署Let's Encrypt证书,但无法配置安全协议。尝试过的Web.config配置如下:

<configuration>
    <system.webServer>
        <handlers accessPolicy="Read, Execute, Script">
            <add 
              name="httpplatformhandler" 
              path="*" verb="*" modules="httpPlatformHandler" resourceType="Unspecified" requireAccess="Script" />
        </handlers>
            <httpPlatform 
              processPath="C:\Project\myApp\Scripts\python.exe" 
              arguments="-m daphne myApp.asgi:application -b abc.xyz" 
              startupTimeLimit="10" 
              startupRetryCount="10" 
              stdoutLogEnabled="true" 
              stdoutLogFile="\.\logs\">
            <environmentVariables>
                <environmentVariable name="myApp" value="bar" />
            </environmentVariables>
        </httpPlatform>
    </system.webServer>
</configuration>

IIS日志显示Daphne监听8000端口,希望去掉该端口但无法实现。

解决方案

1. 配置IIS支持ASGI应用(修正Web.config)

使用IIS的HttpPlatformHandler是正确方向,调整配置让IIS负责端口转发,Daphne仅本地监听即可:

修正后的Web.config示例:

<?xml version="1.0" encoding="utf-8"?>
<configuration>
  <system.webServer>
    <handlers>
      <clear />
      <add name="httpplatformhandler" path="*" verb="*" modules="httpPlatformHandler" resourceType="Unspecified" requireAccess="Script" />
    </handlers>
    <httpPlatform 
      processPath="C:\Project\myApp\Scripts\python.exe" 
      arguments="-m daphne -b 127.0.0.1 -p 8000 django_site.asgi:application" 
      startupTimeLimit="30" 
      stdoutLogEnabled="true" 
      stdoutLogFile=".\logs\daphne_stdout.log">
      <environmentVariables>
        <environmentVariable name="PYTHONPATH" value="C:\Hosted\django_site" />
        <environmentVariable name="DJANGO_SETTINGS_MODULE" value="django_site.settings" />
      </environmentVariables>
    </httpPlatform>
    <!-- 保留原有静态资源相关配置 -->
    <directoryBrowse enabled="false" />
    <httpProtocol>
      <customHeaders>
        <add name="Expires" value="1" />
      </customHeaders>
    </httpProtocol>
    <staticContent>
      <clientCache cacheControlMode="UseMaxAge" cacheControlMaxAge="1.00:00:00" />
    </staticContent>
  </system.webServer>
</configuration>

关键调整点:

  • 让Daphne绑定127.0.0.1:8000,仅本地监听,由IIS对外接收请求并转发
  • 补充PYTHONPATH和DJANGO_SETTINGS_MODULE环境变量,确保Django能正确加载项目配置
  • 调整日志路径为具体文件,避免目录权限问题
  • 延长启动超时时间,保证Daphne完全启动

另外需确认IIS已安装HttpPlatformHandler模块,未安装可通过Web平台安装器下载部署。

2. 让命令行运行的Daphne支持HTTPS

直接启动Daphne时,指定Let's Encrypt的证书文件路径即可:

py -m daphne -b abc.xyz -p 443 --ssl-certificate "C:\path\to\fullchain.pem" --ssl-key "C:\path\to\privkey.pem" django_site.asgi:application

注意事项:

  • 绑定443端口需要管理员权限运行命令
  • Let's Encrypt证书通常存放在C:\Certbot\live\abc.xyz目录,fullchain.pem为证书链文件,privkey.pem为私钥文件
  • 若不想用443端口,可指定其他端口(如8443),但访问时需附加端口号;也可通过IIS反向代理转发到该端口
  • 若遇到证书权限问题,需给运行Python的用户授予证书文件的读取权限

内容的提问来源于stack exchange,提问作者Сергей Немец

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 18:32:08