通过Docker部署反向代理时Cloudflare签发SSL证书的Fullchain缺失错误排查
Hey there, let's work through this problem step by step—you're super close, just a few configuration tweaks needed to get your WordPress site working with the domain via Cloudflare.
Fixing the "ssl_stapling ignored" Warnings
Those warnings pop up because Nginx can't find the full certificate chain (root + intermediate certificates) needed for SSL stapling to work. Right now, you're using only the end-entity certificate from Cloudflare, missing the chain that links it to a trusted root CA. Let's first fix how you get the proper certificate files from Cloudflare.
How to Get Cloudflare's Fullchain Certificate
Cloudflare absolutely provides fullchain certificates for origin servers—here's how to grab yours:
- Log into your Cloudflare dashboard and navigate to your domain's management page
- Head to the SSL/TLS > Origin Server tab
- Locate the certificate you previously created for your server
- Click the Download button next to it
- From the download options, select PEM (full chain) and save the file
- Upload this file to your Nginx server's
/etc/nginx/ssl/example.com/directory (you can name itfullchain.pemfor clarity)
Correcting Your Nginx Reverse Proxy Configuration
Looking at your current config, there are a couple of key issues that are blocking your domain from working correctly:
- The
proxy_passvalue is incorrect (https://example.com:8845/80creates a loop and doesn't point to your Docker container properly) - You're missing the
Hostheader that WordPress needs to recognize the domain - The
root /srv/line is unnecessary since we're proxying requests to Docker
Here's a revised, working version of your wordpress.conf:
listen 443 ssl http2; listen [::]:443 ssl http2; server_name example.com; # Use the fullchain certificate we downloaded ssl_certificate /etc/nginx/ssl/example.com/fullchain.pem; ssl_certificate_key /etc/nginx/ssl/example.com/sslkey.key; include snippets/ssl-params.conf; # Enable and configure SSL stapling properly ssl_stapling on; ssl_stapling_verify on; # Point to your system's trusted root certificates (common path on Debian/Ubuntu) ssl_trusted_certificate /etc/ssl/certs/ca-certificates.crt; client_max_body_size 40M; server_tokens off; location / { proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; # Point directly to your Docker container's mapped port on localhost proxy_pass http://127.0.0.1:8845; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; # Critical: Tell WordPress the domain that's being requested proxy_set_header Host $host; proxy_ssl_session_reuse off; # Remove this line if your Docker container uses HTTP (not HTTPS) internally # proxy_ssl_server_name on; } location ~ /\.ht { deny all; } # Remove or properly configure this if you actually need fancyindex # location /fancyindex { # root /path/to/your/fancyindex/files; # } gzip on; gzip_http_version 1.1; gzip_vary on; gzip_comp_level 6; gzip_proxied any; gzip_types text/plain text/css application/json application/javascript application/x-javascript text/javascript;
Cloudflare Side Checks
Don't forget to verify these settings in Cloudflare to ensure everything syncs up:
- Make sure your domain's DNS A/AAAA record is set to Proxied (orange cloud icon)
- Go to SSL/TLS > Overview and set the SSL mode to Full (since you're using Cloudflare's origin certificate, this is the safest option that avoids certificate mismatch errors)
- Update your WordPress admin settings: Go to Settings > General and set both
WordPress Address (URL)andSite Address (URL)tohttps://example.com(not your IP:PORT—this fixes redirect loops and ensures WordPress uses the correct domain)
Final Troubleshooting Steps
After making these changes:
- Test your Nginx config for syntax errors:
sudo nginx -t - If no errors show up, restart Nginx:
sudo systemctl restart nginx - Clear your browser cache or use incognito mode to visit
https://example.com - If you still run into issues, check Nginx logs for specific errors:
sudo tail -f /var/log/nginx/error.log sudo tail -f /var/log/nginx/access.log
内容的提问来源于stack exchange,提问作者Michaelp

