Nginx配置咨询:HTTPS非WWW域名强制跳转至带WWW的HTTPS
Let's walk through your Nginx redirect issue and get everything sorted out properly.
When you visit https://example.com, Nginx can't find a server block listening on port 443 that explicitly matches example.com as its server_name. So it falls back to the default_server configured for port 443—and that server's SSL certificate is likely only valid for www.example.com (or another domain), causing the browser's certificate mismatch error.
rewrite for the HTTPS Non-WWW → WWW Redirect? No, you don’t need rewrite (though it would work). The return directive is Nginx’s recommended approach here—it’s simpler, faster, and avoids unnecessary regex processing. rewrite is better suited for complex URL transformations, but for straightforward domain redirects, return is the way to go.
Here’s a clean, efficient setup that covers all cases: HTTP → HTTPS WWW, and HTTPS non-WWW → HTTPS WWW:
# 1. Handle all HTTP traffic (port 80) → redirect to HTTPS WWW server { listen 80; server_name example.com www.example.com; # Permanent redirect (301) is best for SEO and caching return 301 https://www.example.com$request_uri; } # 2. Handle HTTPS non-WWW (port 443) → redirect to HTTPS WWW server { listen 443 ssl http2; server_name example.com; # Use the same SSL certificate as your WWW domain (must cover example.com) ssl_certificate /path/to/your/certificate.crt; ssl_certificate_key /path/to/your/private.key; # Optional: Add your usual SSL config (protocols, ciphers, etc.) here ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; return 301 https://www.example.com$request_uri; } # 3. Main HTTPS WWW server (your actual site) server { listen 443 ssl http2 default_server; server_name www.example.com; # Your SSL certificate (should cover www.example.com and example.com if using SAN/wildcard) ssl_certificate /path/to/your/certificate.crt; ssl_certificate_key /path/to/your/private.key; # Add your SSL hardening config here (same as above, or include a common file) ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; # Your site's root, index files, location blocks, etc. root /var/www/example.com; index index.html index.htm; # Rest of your site configuration... }
Key Notes:
- Make sure your SSL certificate covers both
example.comandwww.example.com(use a SAN certificate or wildcard certificate like*.example.com). If it doesn’t, you’ll still get SSL errors onhttps://example.com—so fix the certificate first if needed. - Using
301(permanent redirect) is ideal for search engines and browser caching; use302only if you plan to change the redirect later temporarily.
ssl http2 from the First Server Block? Absolutely—you must remove those directives.
The first server block listens on port 80, which is for unencrypted HTTP traffic. The ssl directive enables HTTPS, which only works on port 443 (or another custom SSL port). Including ssl in an HTTP server block will either prevent Nginx from starting or cause unexpected behavior. Similarly, http2 requires HTTPS, so it’s useless (and invalid) in an HTTP server block.
After updating your config, always test it first:
# Check for syntax errors sudo nginx -t # Reload Nginx to apply changes (no downtime) sudo systemctl reload nginx
Then test the redirects with curl to confirm:
# Test HTTP non-WWW curl -I http://example.com # Should return 301 with Location: https://www.example.com/ # Test HTTP WWW curl -I http://www.example.com # Should return 301 with Location: https://www.example.com/ # Test HTTPS non-WWW curl -I https://example.com # Should return 301 with Location: https://www.example.com/ # Test HTTPS WWW curl -I https://www.example.com # Should return 200 OK (your site loads correctly)
内容的提问来源于stack exchange,提问作者The Dude man

