You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为NGINX多Location统一配置后端SSL客户端证书?

简化NGINX双向TLS代理配置的方法

核心思路

把所有location共用的proxy_ssl_*、proxy_http_version等配置项移到server块级别——这类指令的作用域支持server层级,所有子location会自动继承这些配置,只需保留每个location独有的proxy_pass即可。

修改后的完整配置示例

server {
    # 此处添加server基础配置,如监听端口、域名等
    listen 443 ssl;
    server_name your-domain.com;

    # 所有location共用的双向TLS代理配置
    proxy_ssl_session_reuse on;
    proxy_ssl_verify on;
    proxy_redirect off;
    proxy_ssl_trusted_certificate /etc/nginx/ssl/backend-server-cert.pem;
    proxy_ssl_certificate /etc/nginx/ssl/server-cert.pem;
    proxy_ssl_certificate_key /etc/nginx/ssl/server-key.pem;
    proxy_http_version 1.1;

    location /toto {
        proxy_pass https://servcies1.domaine.com;
    }

    location /tata {
        proxy_pass https://servcies2.domaine.com/;
    }

    location /titi {
        proxy_pass https://servcies3.domaine.com/;
    }
}

进阶方案:用include拆分复用配置

如果需要把这套公共配置复用在多个server块中,可以将公共部分单独存为一个配置文件,比如/etc/nginx/conf.d/proxy-ssl-common.conf,内容如下:

proxy_ssl_session_reuse on;
proxy_ssl_verify on;
proxy_redirect off;
proxy_ssl_trusted_certificate /etc/nginx/ssl/backend-server-cert.pem;
proxy_ssl_certificate /etc/nginx/ssl/server-cert.pem;
proxy_ssl_certificate_key /etc/nginx/ssl/server-key.pem;
proxy_http_version 1.1;

之后在需要的server块中引入即可:

server {
    listen 443 ssl;
    server_name your-domain.com;

    # 引入公共双向TLS配置
    include /etc/nginx/conf.d/proxy-ssl-common.conf;

    location /toto {
        proxy_pass https://servcies1.domaine.com;
    }

    # 其他location配置...
}

关键说明

  • proxy_ssl_*系列指令的作用域覆盖http、server、location三个层级,因此在server层级配置后,所有子location会自动继承这些规则,无需重复编写。
  • 仅保留每个location独有的proxy_pass,能让配置结构更简洁,后续修改公共规则时只需调整一处即可。

内容的提问来源于stack exchange,提问作者SaidiK

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 22:35:10