如何用.NET 6 Web API、NGINX、OpenSSL启用SSL?运行报错求助
问题描述
已通过OpenSSL生成证书,该证书可正常用于Blazor Wasm应用,说明证书无问题;API以HTTP配置在80端口运行时可正常工作,说明API本身无问题。但运行API时抛出以下错误:
Aborted
root@TEST:/var/www/TEST/api# ./TEST_Web_API
Unhandled exception. System.InvalidOperationException: Unable to configure HTTPS endpoint. No server certificate was specified, and the default developer certificate could not be found or is out of date.
To generate a developer certificate run 'dotnet dev-certs https'. To trust the certificate (Windows and macOS only) run 'dotnet dev-certs https –trust'.
NGINX配置
server { listen 444 ssl; server_name test.fritz.box; ssl_certificate /etc/ssl/certs/nginx.crt; ssl_certificate_key /etc/ssl/private/nginx.key; location / { proxy_pass http://127.0.0.1:5000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection keep-alive; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; }} server { #Working Blazor wasm app listen 443 ssl default_server; server_name test.fritz.box; ssl_certificate /etc/ssl/certs/nginx.crt; ssl_certificate_key /etc/ssl/private/nginx.key; access_log /var/log/nginx/access.demo.log; error_log /var/log/nginx/error.demo.log; root /var/www/test; index index.html;}
API配置代码
string _MyAllowSpecificOrigins = "_myAllowSpecificOrigins"; builder.Services.AddCors(options => { //allow CORS options.AddPolicy(_MyAllowSpecificOrigins, builder => builder.WithOrigins("https://localhost:444","http://localhost:81", "http://localhost:5000") .AllowAnyHeader() .AllowAnyMethod() .AllowCredentials() .SetIsOriginAllowed((host) => true)); }); var app = builder.Build(); app.UseForwardedHeaders(new ForwardedHeadersOptions { ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto }); app.UseSwagger(); app.UseSwaggerUI(); if (!app.Environment.IsDevelopment()) { //Raspberry PI app.UseHttpsRedirection(); app.Urls.Add("http://192.168.178.51:5000"); app.Urls.Add("http://localhost:5000"); } app.UseCors(_MyAllowSpecificOrigins);//Do not change the position of app.UseCors, the order is important! app.UseAuthorization(); app.MapControllers(); app.Run();
错误原因
问题出在API的非开发环境配置中:
- 调用了
app.UseHttpsRedirection(),这个中间件会尝试将HTTP请求重定向到HTTPS端点,但你的API只配置了HTTP监听地址(http://192.168.178.51:5000和http://localhost:5000),没有配置任何HTTPS端点。 - 当
UseHttpsRedirection找不到可用的HTTPS端点时,会尝试使用默认开发证书,但生产环境(树莓派)没有生成或配置这个证书,因此抛出错误。
另外CORS配置存在疏漏:Blazor Wasm实际运行在https://test.fritz.box:443,但WithOrigins里只添加了https://localhost:444,这会导致实际部署后CORS校验失败。
解决方案
1. 移除不必要的HTTPS重定向
NGINX已经作为SSL终止层处理了HTTPS请求,API只需在HTTP端口运行即可,因此在非开发环境中删除app.UseHttpsRedirection():
if (!app.Environment.IsDevelopment()) { //Raspberry PI // 移除该行:app.UseHttpsRedirection(); app.Urls.Add("http://192.168.178.51:5000"); app.Urls.Add("http://localhost:5000"); }
2. 修正CORS配置的允许源
将Blazor Wasm的实际访问地址加入允许列表,替换无效的localhost地址:
options.AddPolicy(_MyAllowSpecificOrigins, builder => builder.WithOrigins("https://test.fritz.box", "http://localhost:81", "http://localhost:5000") .AllowAnyHeader() .AllowAnyMethod() .AllowCredentials() .SetIsOriginAllowed((host) => true));
3. 验证配置
修改后重新编译API,启动后通过NGINX的444端口访问API,确认错误消失且CORS正常工作。
内容的提问来源于stack exchange,提问作者Christoph1972

