Matrix Synapse联邦故障:根域名用户名无法使用,证书不匹配
解决Matrix Synapse联邦功能证书验证失败问题
问题核心
联邦测试器报错x509: certificate is valid for matrix.phsta.de, not phsta.de,本质原因是:
- 你的Synapse服务器
server_name设为phsta.de,其他联邦服务器发起请求时,会以phsta.de作为SNI(服务器名称指示)验证证书 - 但当前Matrix服务器的SSL证书仅包含
matrix.phsta.de域名,与phsta.de不匹配,导致TLS握手失败
可行解决方案
方案一:更新SSL证书,添加phsta.de作为备用域名
直接让matrix.phsta.de的证书同时覆盖phsta.de域名:
- 重新申请SSL证书,同时包含
matrix.phsta.de和phsta.de两个域名- 若使用Let's Encrypt的Certbot,执行命令:
certbot certonly --nginx -d matrix.phsta.de -d phsta.de - 其他证书颁发机构需确保证书包含两个域名的SAN(Subject Alternative Name)字段
- 若使用Let's Encrypt的Certbot,执行命令:
- 修改Synapse配置文件,将
tls_certificate_path和tls_private_key_path指向新生成的证书和密钥文件 - 重启Synapse服务
方案二:通过主服务器反向代理联邦请求
利用phsta.de指向的主服务器做反向代理,复用其已有的phsta.de证书转发联邦请求:
- 在主服务器的Web服务(如Nginx)中添加8448端口的反向代理配置:
server { listen 8448 ssl; listen [::]:8448 ssl; server_name phsta.de; # 使用主服务器已有的phsta.de证书 ssl_certificate /path/to/phsta.de/fullchain.pem; ssl_certificate_key /path/to/phsta.de/privkey.pem; location /_matrix/federation { proxy_pass https://matrix.phsta.de:8448; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } - 重启主服务器的Web服务
- 保持Matrix服务器的
server_name为phsta.de,无需额外修改
验证
完成配置后,重新运行联邦测试器,确认ValidCertificates变为true、FederationOK变为true即可。
内容的提问来源于stack exchange,提问作者Philipp Stappert
相关产品推荐
相关产品推荐

