HAproxy配置HTTP跳转HTTPS报ERR_SSL_PROTOCOL_ERROR故障咨询
问题根因
你配置的重定向规则未指定HTTPS服务端口,会默认沿用来访的5006端口发起HTTPS请求,而5006端口绑定的是HTTP协议,用HTTPS协议访问HTTP端口就会触发ERR_SSL_PROTOCOL_ERROR报错。
修正方案
- 调整重定向规则,明确指定跳转的HTTPS端口为5443,可选添加301/302状态码标识重定向类型,修正后的规则如下:
http-request redirect scheme https code 301 port 5443 unless { ssl_fc } - 如果需要兼容带自定义路径、域名的场景,也可以使用全路径跳转写法:
http-request redirect location https://%[hdr(host)]:5443%[capture.req.uri] code 301 unless { ssl_fc }
完整修正后配置示例
frontend simple_webapp mode http bind *:5006 bind *:5443 ssl crt /root/Downloads/simple_webapp_all.pem http-request redirect scheme https code 301 port 5443 unless { ssl_fc } default_backend simple_webapp backend simple_webapp balance roundrobin server centos8-1 <server ip1>:5006 check server centos8-2 <server ip2>:5006 check
内容的提问来源于stack exchange,提问作者joker57
相关产品推荐
相关产品推荐

