You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Docker部署反向代理时Cloudflare签发SSL证书的Fullchain缺失错误排查

Hey there, let's work through this problem step by step—you're super close, just a few configuration tweaks needed to get your WordPress site working with the domain via Cloudflare.

Fixing the "ssl_stapling ignored" Warnings

Those warnings pop up because Nginx can't find the full certificate chain (root + intermediate certificates) needed for SSL stapling to work. Right now, you're using only the end-entity certificate from Cloudflare, missing the chain that links it to a trusted root CA. Let's first fix how you get the proper certificate files from Cloudflare.

How to Get Cloudflare's Fullchain Certificate

Cloudflare absolutely provides fullchain certificates for origin servers—here's how to grab yours:

  • Log into your Cloudflare dashboard and navigate to your domain's management page
  • Head to the SSL/TLS > Origin Server tab
  • Locate the certificate you previously created for your server
  • Click the Download button next to it
  • From the download options, select PEM (full chain) and save the file
  • Upload this file to your Nginx server's /etc/nginx/ssl/example.com/ directory (you can name it fullchain.pem for clarity)

Correcting Your Nginx Reverse Proxy Configuration

Looking at your current config, there are a couple of key issues that are blocking your domain from working correctly:

  1. The proxy_pass value is incorrect (https://example.com:8845/80 creates a loop and doesn't point to your Docker container properly)
  2. You're missing the Host header that WordPress needs to recognize the domain
  3. The root /srv/ line is unnecessary since we're proxying requests to Docker

Here's a revised, working version of your wordpress.conf:

listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name example.com;

# Use the fullchain certificate we downloaded
ssl_certificate /etc/nginx/ssl/example.com/fullchain.pem;
ssl_certificate_key /etc/nginx/ssl/example.com/sslkey.key;
include snippets/ssl-params.conf;

# Enable and configure SSL stapling properly
ssl_stapling on;
ssl_stapling_verify on;
# Point to your system's trusted root certificates (common path on Debian/Ubuntu)
ssl_trusted_certificate /etc/ssl/certs/ca-certificates.crt;

client_max_body_size 40M;
server_tokens off;

location / {
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    # Point directly to your Docker container's mapped port on localhost
    proxy_pass http://127.0.0.1:8845;
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection "upgrade";
    # Critical: Tell WordPress the domain that's being requested
    proxy_set_header Host $host;
    proxy_ssl_session_reuse off;
    # Remove this line if your Docker container uses HTTP (not HTTPS) internally
    # proxy_ssl_server_name on;
}

location ~ /\.ht {
    deny all;
}

# Remove or properly configure this if you actually need fancyindex
# location /fancyindex {
#     root /path/to/your/fancyindex/files;
# }

gzip on;
gzip_http_version 1.1;
gzip_vary on;
gzip_comp_level 6;
gzip_proxied any;
gzip_types text/plain text/css application/json application/javascript application/x-javascript text/javascript;

Cloudflare Side Checks

Don't forget to verify these settings in Cloudflare to ensure everything syncs up:

  • Make sure your domain's DNS A/AAAA record is set to Proxied (orange cloud icon)
  • Go to SSL/TLS > Overview and set the SSL mode to Full (since you're using Cloudflare's origin certificate, this is the safest option that avoids certificate mismatch errors)
  • Update your WordPress admin settings: Go to Settings > General and set both WordPress Address (URL) and Site Address (URL) to https://example.com (not your IP:PORT—this fixes redirect loops and ensures WordPress uses the correct domain)

Final Troubleshooting Steps

After making these changes:

  1. Test your Nginx config for syntax errors: sudo nginx -t
  2. If no errors show up, restart Nginx: sudo systemctl restart nginx
  3. Clear your browser cache or use incognito mode to visit https://example.com
  4. If you still run into issues, check Nginx logs for specific errors:
    sudo tail -f /var/log/nginx/error.log
    sudo tail -f /var/log/nginx/access.log
    

内容的提问来源于stack exchange,提问作者Michaelp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 21:24:06