配置Nginx反向代理.NET Core 6应用HTTPS访问出现404错误求助
问题描述
已在Nginx上部署MERN栈应用并配置反向代理,运行正常。近期开发了.NET Core 6.0 Web应用,尝试接入Nginx后,通过HTTPS访问域名时页面显示404(域名已配置Certbot SSL证书),但在全新服务器上仅安装.NET和Nginx后,HTTP访问可正常运行。
已配置内容
1. .NET应用的systemd服务配置
[Unit] Description=Example .NET Web API App running on Ubuntu [Service] WorkingDirectory=/var/www/html/webApp ExecStart=/usr/bin/dotnet /var/www/html/webApp/web-app.dll Restart=always # Restart service after 10 seconds if the dotnet service crashes: RestartSec=10 KillSignal=SIGINT SyslogIdentifier=dotnet-example User=www-data Environment=ASPNETCORE_ENVIRONMENT=Production Environment=DOTNET_PRINT_TELEMETRY_MESSAGE=false [Install] WantedBy=multi-user.target
2. Nginx配置
server { #Path to the React front end root /var/www/html/MERNAPI/client/build; #the main html file index index.html; #Enter the IP address of your droplet server_name mydomain.com www.mydomain.com #STORE the nginx access logs for this app here access_log /var/log/nginx/mydomain.com.access.log; #Store the error logs for this app here error_log /var/log/nginx/mydomain.com.error.log; client_max_body_size 64M; location / { # Without this line routing in your Single Page APP will not work try_files $uri $uri/ /index.html =404; } #REST API BACKEND CONFIG location /api { proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-NginX-Proxy true; proxy_pass http://localhost:3003; proxy_ssl_session_reuse off; proxy_set_header Host $http_host; proxy_cache_bypass $http_upgrade; proxy_redirect off; } #Socket IO Config location /socket.io { proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-NginX-Proxy true; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_http_version 1.1; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Host $host; proxy_pass http://localhost:3003/socket.io/; } location /EV { proxy_pass http://127.0.0.1:5000/; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection keep-alive; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } listen [::]:443 ssl ipv6only=on; # managed by Certbot listen 443 ssl; # managed by Certbot ssl_certificate /etc/letsencrypt/live/mydomain.com/fullchain.pem; # managed by Certbot ssl_certificate_key /etc/letsencrypt/live/mydomain.com/privkey.pem; # managed by Certbot include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot } server { if ($host = www.mydomain.com) { return 301 https://$host$request_uri; } # managed by Certbot if ($host = mydomain.com) { return 301 https://$host$request_uri; } # managed by Certbot listen 80; listen [::]:80; server_name mydomain.com www.mydomain.com; #STORE the nginx access logs for this app here access_log /var/log/nginx/mydomain.com.access.log; return 404; # managed by Certbot }
3. .NET Program.cs代码
using MySqlConnector; var builder = WebApplication.CreateBuilder(args); // Add services to the container. builder.Services.AddControllersWithViews(); ConfigurationManager configuration = builder.Configuration; builder.Services.AddTransient<MySqlConnection>(_ => new MySqlConnection(configuration["ConnectionStrings:Default"])); builder.Services.AddSingleton<IHttpContextAccessor, HttpContextAccessor>(); builder.Services.AddSession(options => { options.IdleTimeout = TimeSpan.FromMinutes(30);//We set Time here options.Cookie.HttpOnly = true; options.Cookie.IsEssential = true; }); builder.Services.AddMvc(); var app = builder.Build(); // Configure the HTTP request pipeline. if (!app.Environment.IsDevelopment()) { app.UseExceptionHandler("/Home/Error"); // The default HSTS value is 30 days. You may want to change this for production scenarios app.UseHsts(); //app.UseHttpsRedirection(); } app.UseStaticFiles(); app.UseRouting(); app.UseSession(); app.UseAuthorization(); app.MapControllerRoute( name: "default", pattern: "{controller=Account}/{action=Login}/{id?}"); app.Run();
4. appsetting.json配置
{ "ConnectionStrings": { "Default": "server=127.0.0.1;port=3306;user=root;password=123;database=xyz" }, "Logging": { "LogLevel": { "Default": "Information", "Microsoft.AspNetCore": "Warning" } }, "AllowedHosts": "*" }
排查解决步骤
1. 修复Nginx配置语法错误
你的Nginx配置存在两处致命语法问题:
- 两处
server_name mydomain.com www.mydomain.com末尾都缺少分号,需补全为server_name mydomain.com www.mydomain.com; - SSL证书行的注释被截断,需修正为完整格式(如
# managed by Certbot)
执行命令验证配置语法:
sudo nginx -t
修复后重新加载Nginx:
sudo systemctl reload nginx
2. 确认.NET应用监听端口
Nginx将/EV路径代理到127.0.0.1:5000,需确认.NET应用确实在该端口运行:
- 查看应用运行日志:
sudo journalctl -u dotnet-example.service -f
- 检查端口占用情况:
sudo lsof -i :5000
若应用未监听5000端口,可在appsettings.json中添加端口配置:
"Urls": "http://localhost:5000"
或修改systemd服务的环境变量:
Environment=ASPNETCORE_URLS=http://localhost:5000
修改后重启.NET服务:
sudo systemctl restart dotnet-example.service
3. 验证代理路径访问
当前Nginx仅将/EV路径代理到.NET应用,需访问https://mydomain.com/EV才能触发.NET应用的路由。若需.NET应用处理其他路径,需调整Nginx的location规则。
4. 检查HTTPS证书配置
- 确认SSL证书文件路径正确且Nginx有读取权限:
sudo ls -l /etc/letsencrypt/live/mydomain.com/
- 查看Nginx服务状态,确认HTTPS监听正常:
sudo systemctl status nginx
5. 通过日志定位问题
- 查看Nginx错误日志,获取404的具体原因:
sudo tail -f /var/log/nginx/mydomain.com.error.log
- 查看.NET应用日志,确认请求是否到达应用:
sudo journalctl -u dotnet-example.service -f
内容的提问来源于stack exchange,提问作者Dharmeshkumar
相关产品推荐
相关产品推荐

