SSL配置正常但线上WebSocket连接失败求助(ERR_INSECURE_RESPONSE)
net::ERR_INSECURE_RESPONSE in Production (Works Locally) Let’s break down this issue and fix it step by step—since your WebSocket connection works locally but fails in production, the problem is almost certainly tied to production-specific SSL or network settings for your WebSocket service. The net::ERR_INSECURE_RESPONSE error means your browser doesn’t trust the SSL certificate presented by your WebSocket server on port 9175, even though your main website’s SSL is configured correctly.
Here’s how to diagnose and resolve the problem:
Validate the WebSocket server’s SSL certificate
Your main domain (tutorclass.co.uk) has a valid SSL cert, but the WebSocket service running on port 9175 might be using a mismatched, expired, or self-signed certificate (which browsers trust locally but reject in production). Use this command to test the certificate directly:openssl s_client -connect www.tutorclass.co.uk:9175Look for the line
Verify return code: 0 (ok)—any other error code here points to a invalid certificate. Ensure the certificate coverswww.tutorclass.co.ukand hasn’t expired.Fix incomplete certificate chain
Even if the main certificate is valid, missing intermediate certificates will cause browsers to reject the connection. Combine your primary SSL certificate with all required intermediate certificates into a single chain file, then update your WebSocket service to use this full chain instead of just the main cert.Check firewall/security group rules for port 9175
Production servers often have stricter firewall rules. Confirm that port 9175 is open to incoming traffic, and that your firewall isn’t intercepting SSL handshake packets (some security tools block non-standard HTTPS ports by default).Verify WebSocket service SSL configuration
Double-check that your WebSocket server is configured to use SSL correctly:- Ensure it’s pointing to the correct certificate and private key files (not outdated paths from local testing)
- Confirm it’s not running in HTTP mode while you’re trying to connect via
wss://(which requires SSL encryption)
Rule out browser caching issues
Browsers sometimes cache invalid certificate data. Test the connection in incognito mode, or force a full refresh (Ctrl+Shift+R) to clear cached SSL state.Check for SNI support
If your production server hosts multiple domains, your WebSocket service needs to support Server Name Indication (SNI) to serve the correct certificate forwww.tutorclass.co.uk. Without SNI, it might return a default certificate that doesn’t match the domain, triggering the insecure response error.
tunnel.min.js:17 WebSocket connection to 'wss://www.tutorclass.co.uk:9175/groupworld_websocket' failed: Error in connection establishment: net::ERR_INSECURE_RESPONSE in tunnel.min.js
内容的提问来源于stack exchange,提问作者bhumika

