You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Matrix Synapse联邦故障:根域名用户名无法使用,证书不匹配

解决Matrix Synapse联邦功能证书验证失败问题

问题核心

联邦测试器报错x509: certificate is valid for matrix.phsta.de, not phsta.de,本质原因是:

  • 你的Synapse服务器server_name设为phsta.de,其他联邦服务器发起请求时,会以phsta.de作为SNI(服务器名称指示)验证证书
  • 但当前Matrix服务器的SSL证书仅包含matrix.phsta.de域名,与phsta.de不匹配,导致TLS握手失败

可行解决方案

方案一:更新SSL证书,添加phsta.de作为备用域名

直接让matrix.phsta.de的证书同时覆盖phsta.de域名:

  1. 重新申请SSL证书,同时包含matrix.phsta.de和phsta.de两个域名
    • 若使用Let's Encrypt的Certbot,执行命令:
      certbot certonly --nginx -d matrix.phsta.de -d phsta.de
      
    • 其他证书颁发机构需确保证书包含两个域名的SAN(Subject Alternative Name)字段
  2. 修改Synapse配置文件,将tls_certificate_path和tls_private_key_path指向新生成的证书和密钥文件
  3. 重启Synapse服务

方案二:通过主服务器反向代理联邦请求

利用phsta.de指向的主服务器做反向代理,复用其已有的phsta.de证书转发联邦请求:

  1. 在主服务器的Web服务(如Nginx)中添加8448端口的反向代理配置:
    server {
        listen 8448 ssl;
        listen [::]:8448 ssl;
        server_name phsta.de;
    
        # 使用主服务器已有的phsta.de证书
        ssl_certificate /path/to/phsta.de/fullchain.pem;
        ssl_certificate_key /path/to/phsta.de/privkey.pem;
    
        location /_matrix/federation {
            proxy_pass https://matrix.phsta.de:8448;
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
        }
    }
    
  2. 重启主服务器的Web服务
  3. 保持Matrix服务器的server_name为phsta.de,无需额外修改

验证

完成配置后,重新运行联邦测试器,确认ValidCertificates变为true、FederationOK变为true即可。

内容的提问来源于stack exchange,提问作者Philipp Stappert

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 08:50:38