You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx配置SSL后网站被标记危险及AWS负载均衡证书问题排查

问题排查与解决:HTTPS站点标记危险及AWS负载均衡异常

一、问题背景

  • 用Nginx做Node.js反向代理,按DigitalOcean教程生成SSL证书后,Nginx运行正常,但浏览器标记站点为「存在欺骗性站点,my-host.com上的恶意用户可能诱骗您执行危险操作」
  • 尝试用AWS证书配置负载均衡HTTPS跳转,同样出现异常

二、现有环境信息

Nginx运行状态

● nginx.service - The nginx HTTP and reverse proxy server
   Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; vendor preset: disabled)
   Active: active (running) since Fri 2023-03-03 07:52:25 UTC; 16s ago
  Process: 21031 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS)
  Process: 21028 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS)
  Process: 21026 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS)
 Main PID: 21033 (nginx)
   CGroup: /system.slice/nginx.service
           ├─21033 nginx: master process /usr/sbin/nginx
           ├─21034 nginx: worker process
           └─21035 nginx: worker process

Mar 03 07:52:25 ip-MY-IP.eu-south-1.compute.internal systemd[1]: Starting The nginx HTTP and reverse proxy server...
Mar 03 07:52:25 ip-MY-IP.eu-south-1.compute.internal nginx[21028]: nginx: [warn] the "ssl" directive is deprecated, use the "listen ... ssl" directive instead in /etc/nginx/sites-available/gestionale.conf:23
Mar 03 07:52:25 ip-MY-IP.eu-south-1.compute.internal nginx[21028]: nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
Mar 03 07:52:25 ip-MY-IP.eu-south-1.compute.internal nginx[21028]: nginx: configuration file /etc/nginx/nginx.conf test is successful
Mar 03 07:52:25 ip-MY-IP.eu-south-1.compute.internal nginx[21031]: nginx: [warn] the "ssl" directive is deprecated, use the "listen ... ssl" directive instead in /etc/nginx/sites-available/gestionale.conf:23
Mar 03 07:52:25 ip-MY-IP.eu-south-1.compute.internal systemd[1]: Started The nginx HTTP and reverse proxy server.

Nginx站点配置文件

server
{
        listen 443;
        server_name my-host.com; 
        #root /usr/share/nginx/www; index index.html index.htm;
        ssl on;
        ssl_certificate /etc/nginx/ssl/server.crt;
        ssl_certificate_key /etc/nginx/ssl/server.key;
        location / {
                proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                proxy_set_header Host $host;
                proxy_pass http://127.0.0.1:3000;
                proxy_http_version 1.1;
                proxy_set_header Upgrade $http_upgrade;
                proxy_set_header Connection "upgrade";
                #location /overview {
                #       proxy_pass http://127.0.0.1:3000$request_uri;
               #        proxy_redirect off;
                #}
        }
}

三、问题原因分析

1. Nginx+DigitalOcean证书导致站点标记危险

  • 证书不被信任:如果生成的是自签名证书,浏览器会直接判定危险;即使是Let's Encrypt证书,也可能存在证书链不完整、域名与证书绑定不匹配的情况
  • Nginx配置缺陷:没有配置HTTP到HTTPS的强制跳转,用户可能通过未加密的HTTP访问触发警告;同时缺少SSL协议、加密套件的规范配置,导致浏览器认为站点安全标准不达标
  • 域名信誉问题:my-host.com可能曾被标记为恶意站点,或站点内容触发了浏览器的安全拦截规则

2. AWS负载均衡HTTPS跳转异常

  • 证书关联错误:AWS证书管理器(ACM)中的证书未正确绑定到负载均衡的HTTPS监听器,或证书域名与站点域名不匹配
  • 跳转规则配置错误:HTTP到HTTPS的重定向规则未设置(比如未选301/302跳转),或规则优先级冲突导致不生效
  • 后端服务冲突:负载均衡已处理HTTPS加密,后端Nginx仍配置SSL,导致双层加密握手异常
  • 网络权限限制:负载均衡或EC2实例的安全组未开放80/443端口,导致HTTPS请求无法正常到达

四、解决方法

针对Nginx+DigitalOcean证书的修复步骤

  1. 验证并替换有效证书
    • 执行openssl s_client -connect my-host.com:443检查证书链,确认域名匹配、证书未过期、根证书被信任
    • 如果是自签名证书,直接用Certbot生成受信任的Let's Encrypt证书:certbot --nginx,该命令会自动配置证书和HTTP跳转
  2. 修正Nginx配置
    • 把过时的ssl on;改成listen 443 ssl;,消除配置警告
    • 添加HTTP强制跳转HTTPS的server块:
      server {
          listen 80;
          server_name my-host.com;
          return 301 https://$host$request_uri;
      }
      
    • 补充SSL安全配置,提升浏览器信任度:
      ssl_protocols TLSv1.2 TLSv1.3;
      ssl_ciphers HIGH:!aNULL:!MD5;
      ssl_prefer_server_ciphers on;
      
    • 重启Nginx生效:sudo systemctl restart nginx
  3. 排查域名信誉
    • 提交域名到主流浏览器的安全平台(如谷歌安全中心),申请解除恶意标记

针对AWS负载均衡HTTPS跳转的修复步骤

  1. 确认证书配置
    • 确保ACM中的证书已覆盖my-host.com域名,状态为「已颁发」
    • 在负载均衡的HTTPS监听器(443端口)中关联该ACM证书
  2. 配置HTTPS跳转规则
    • 在负载均衡的HTTP监听器(80端口)中添加规则,将所有请求重定向到HTTPS,选择301永久跳转
  3. 调整后端Nginx配置
    • 负载终结HTTPS后,后端Nginx只需监听80端口,删除SSL相关配置,避免双层加密冲突
    • 添加X-Forwarded-Proto头,让Node.js服务识别原始请求协议:
      proxy_set_header X-Forwarded-Proto $scheme;
      
  4. 检查网络权限
    • 负载均衡安全组开放80、443端口,允许所有公网访问
    • EC2实例安全组允许负载均衡的IP段访问80端口(或Node.js服务的3000端口)

内容的提问来源于stack exchange,提问作者Dmytro V

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 21:25:11