You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu16.04 LEMP环境下WordPress配置Cloudflare HTTPS访问异常求助

Troubleshooting HTTPS Access for aaronstone.io

Hey there! As someone who’s been in your shoes—stumbling through my first site setups and SSL headaches—I’ll walk you through fixing this HTTPS issue step by step. Let’s break it down:

1. Make Sure UFW Allows HTTPS Traffic

First up: your firewall needs to let port 443 (HTTPS) through. Check your sudo ufw status output for lines like this:

443/tcp                     ALLOW       Anywhere
443/tcp (v6)                ALLOW       Anywhere (v6)

If those lines are missing, add the rule and reload UFW:

sudo ufw allow 443/tcp
sudo ufw reload

2. Validate Your Nginx HTTPS Configuration

Your Nginx config needs a dedicated server block for HTTPS. Double-check it includes these critical bits (adjust paths to match your setup):

server {
    listen 443 ssl;
    listen [::]:443 ssl;

    server_name aaronstone.io www.aaronstone.io;

    # Paths to your Cloudflare cert files
    ssl_certificate /var/ssl/ssl.pem;
    ssl_certificate_key /var/ssl/ssl.key;

    # Recommended SSL hardening settings
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    # Your existing site root and routing rules
    root /var/www/your-site-directory;
    index index.html index.htm;

    location / {
        try_files $uri $uri/ =404;
    }
}

Also, add an HTTP-to-HTTPS redirect if you want all traffic to use secure connections:

server {
    listen 80;
    listen [::]:80;

    server_name aaronstone.io www.aaronstone.io;
    return 301 https://$server_name$request_uri;
}

After editing, test the config for syntax errors and restart Nginx:

sudo nginx -t
sudo systemctl restart nginx

3. Confirm Port 443 Is Being Listened On

Check your netstat -atpn output for lines showing Nginx listening on 443. It should look like this:

tcp        0      0 0.0.0.0:443             0.0.0.0:*               LISTEN      [nginx-pid]/nginx: master
tcp6       0      0 :::443                  :::*                    LISTEN      [nginx-pid]/nginx: master

If you don’t see this, Nginx isn’t configured to listen on 443 (go back to step 2) or failed to start properly.

4. Check Nginx Error Logs for Clues

If the config looks good but HTTPS still fails, dig into the error logs:

sudo tail -n 20 /var/log/nginx/error.log

Common issues here include:

  • Permission errors on SSL files: Even if /var/ssl has 700 permissions, make sure the cert files themselves are readable by Nginx:
    sudo chmod 600 /var/ssl/ssl.pem /var/ssl/ssl.key
    
  • Mismatched cert/key pair: Double-check you didn’t mix up the Cloudflare-provided .pem and .key files.

5. Verify Cloudflare SSL/TLS Settings

Since you’re using Cloudflare, their SSL mode is critical. Log into your Cloudflare dashboard, go to the SSL/TLS tab for your domain, and set the mode to Full (not Flexible). Flexible mode only encrypts traffic between Cloudflare and users, not between Cloudflare and your server—your server needs a valid cert for Full mode to work.

Also, confirm your DNS record for aaronstone.io is set to Proxied (orange cloud icon) if you want Cloudflare to handle SSL termination. Even if it’s DNS-only, your server’s HTTPS should still work directly.

6. Test HTTPS Directly on Your Server

To rule out Cloudflare issues, test HTTPS on your server’s IP directly:

curl -v https://165.227.182.40/ --insecure

The --insecure flag skips certificate validation (since you’re accessing via IP, the cert won’t match). If this works, the problem is with Cloudflare settings; if not, focus back on your server config.

Give these steps a try, and let me know if you hit any specific errors—I’ll help you work through them!

内容的提问来源于stack exchange,提问作者Aaron

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 04:21:03