Azure VM上SSRS无法通过DNS域名HTTPS访问,求排查方向
Let's break down the common missing configurations that could be causing this issue—since you can access via HTTP+IP, the core SSRS service is running, so we need to focus on HTTPS, domain, and network layers:
Bind the Let's Encrypt certificate in SSRS Configuration Manager
It's easy to install the certificate on the VM but forget to link it to SSRS itself. Open the Reporting Services Configuration Manager, connect to your SSRS instance, then:- Go to Web Service URL → click Add under HTTPS bindings.
- Select your Let's Encrypt certificate from the dropdown, enter your target port, and save.
- Repeat the same steps for the Web Portal URL section.
Don't forget to restart the SQL Server Reporting Services service after making these changes.
Verify the certificate's domain coverage
Let's Encrypt certificates require that your SSRS domain is listed in either the Subject or Subject Alternative Name (SAN) field. Open the Certificate Manager on the VM (runcertlm.msc), navigate to Personal > Certificates, find your Let's Encrypt cert, and check its details to confirm the domain matches exactly (including subdomains if you're using one).Double-check Azure NSG and VM Firewall Rules
Even if you added an inbound rule for your port, make sure:- The rule uses TCP protocol (HTTPS relies on TCP).
- The source range is set correctly (e.g.,
0.0.0.0/0for public access, or restricted to your IPs). - No higher-priority deny rules are overriding your allow rule.
Also, confirm the Windows Defender Firewall on the VM has an inbound rule allowing your HTTPS port—NSG rules don't bypass the local OS firewall.
Validate DNS Resolution
Ensure your domain points to the correct public IP of your Azure VM. Runnslookup yourssrsdomain.comfrom a local machine; the returned IP should match the VM's public IP. If you're using a dynamic public IP, consider switching to a static IP or setting up a DDNS service to keep the record updated.Check Port Listening and Conflicts
Confirm SSRS is actually listening on your HTTPS port. Run this command in an elevated PowerShell prompt on the VM:netstat -ano | findstr :<your-https-port>Look for a process ID matching the SSRS service (you can cross-reference with Task Manager). If another service is using the port, either change the port in SSRS or stop the conflicting service.
Ensure Certificate is Stored in the Correct Location
Let's Encrypt certificates need to be in the Local Computer > Personal certificate store (not the Current User store) for SSRS to access them. If you installed it in the wrong store, move it using the Certificate Manager (certlm.mscfor local computer,certmgr.mscfor current user).Clear Browser Cache or Use Incognito Mode
Sometimes browsers cache old HTTP connections or flag new HTTPS certificates as untrusted. Try accessing your domain in incognito/private mode first, or clear your browser's cache and cookies.
内容的提问来源于stack exchange,提问作者Theodorus Agum Gumilang

