如何为Windows XAMPP服务器配置支持外网访问的SSL证书?
Fixing ERR_CERT_COMMON_NAME_INVALID for XAMPP SSL on Windows
Got it, let's tackle that Chrome error you're facing. The root issue here is that XAMPP's old makecert tool generates certificates that don't meet modern browser standards—specifically, it only sets a Common Name (CN) field, but Chrome now requires the Subject Alternative Name (SAN) extension to explicitly list your server's domain or public IP. Here's a step-by-step fix using OpenSSL (which comes pre-installed with XAMPP):
Step 1: Update OpenSSL Configuration
First, we need to configure OpenSSL to include the SAN field in our certificate:
- Navigate to your XAMPP install directory (usually
C:\xampp) and openapache\conf\openssl.cnfin a text editor. - Find the
[ v3_req ]section (if it doesn't exist, look for[ v3_ca ]instead) and add these lines at the bottom of the section:
Add both lines if you plan to access the server via both domain and IP, or just the one you need.subjectAltName = @alt_names [ alt_names ] DNS.1 = your-domain.com # Replace with your public domain (if using one) IP.1 = 123.45.67.89 # Replace with your server's public IP address
Step 2: Generate a Valid SSL Certificate & Key
Use XAMPP's built-in OpenSSL to create the certificate:
- Open the XAMPP Control Panel, click the Shell button to launch a command prompt in the XAMPP directory.
- Run this command to generate a private key:
openssl genrsa -out server.key 2048 - Next, create a Certificate Signing Request (CSR). When prompted, fill in the details—make sure the Common Name (CN) matches the domain/IP you added in the SAN section earlier (other fields can be left blank or filled with dummy values):
openssl req -new -key server.key -out server.csr - Finally, generate the signed certificate (valid for 365 days):
Move the generatedopenssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt -extensions v3_req -extfile "C:\xampp\apache\conf\openssl.cnf"server.keyandserver.crtfiles toC:\xampp\apache\conffor easy access.
Step 3: Configure Apache to Use the New Certificate
Update XAMPP's SSL settings:
- Open
C:\xampp\apache\conf\extra\httpd-ssl.confin a text editor. - Find these lines and replace the paths with your new certificate files:
SSLCertificateFile "C:/xampp/apache/conf/server.crt" SSLCertificateKeyFile "C:/xampp/apache/conf/server.key"
Step 4: Restart Apache & Verify
- Go back to the XAMPP Control Panel, stop the Apache server, then start it again.
- Access your server via
https://your-domain.comorhttps://your-public-ipin Chrome—you might still see a warning (since it's a self-signed certificate), but theERR_CERT_COMMON_NAME_INVALIDerror should be gone.
Optional: Trust the Self-Signed Certificate in Chrome
To eliminate the "Not Secure" warning entirely:
- Double-click the
server.crtfile you generated. - Click Install Certificate, select Local Computer, then click Next.
- Choose Place all certificates in the following store, click Browse, and select Trusted Root Certification Authorities.
- Complete the installation, restart Chrome, and the warning will disappear.
Quick Notes
- Make sure your server's 443 port is open in Windows Firewall and forwarded on your router so external users can access the HTTPS service.
- If using a domain, ensure it's properly pointed to your public IP via DNS.
内容的提问来源于stack exchange,提问作者user6944995
相关产品推荐
相关产品推荐

