如何解决AWS EC2 Ubuntu实例双端口的SSL证书配置问题?
Hey there, let's get your site back up and running properly! The key issue here isn't needing to add SSL directly to your 8080 port — instead, we'll use Nginx as the single HTTPS entry point that forwards requests to both your React app (port 5000) and Node backend (port 8080). This way, all external traffic uses HTTPS, and your backend only needs to handle internal HTTP requests (which is safe since it's only accessible from your server itself).
Step 1: Update Your Nginx Configuration
Replace the relevant parts of your /etc/nginx/sites-available/default file with this configuration. I'll break down what each part does:
# Redirect all HTTP traffic to HTTPS server { listen 80; server_name projectmatch.me www.projectmatch.me; return 301 https://$host$request_uri; } # HTTPS server block for your domain server { listen 443 ssl; server_name projectmatch.me www.projectmatch.me; # Path to your SSL certificates (update these to match your actual files) ssl_certificate /path/to/your/certificate.crt; ssl_certificate_key /path/to/your/private.key; # Basic SSL security settings (you can tweak these for stricter security if needed) ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; # Forward React app requests (root path) to port 5000 location / { proxy_pass http://localhost:5000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } # Forward /api requests to Node backend on port 8080 location /api { proxy_pass http://localhost:8080; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # Uncomment the line below if your backend doesn't expect the /api prefix in requests # rewrite ^/api/(.*)$ /$1 break; } }
Step 2: Key Configuration Details
- SSL Certificates: Double-check that the paths to
ssl_certificateandssl_certificate_keymatch where you stored your OpenSSL files (common locations are/etc/ssl/certs/and/etc/ssl/private/). - /api Prefix: If your Node backend doesn't use the
/apiprefix internally, uncomment therewriteline to strip it before forwarding requests. - Proxy Headers: These lines ensure your backend receives accurate details about the original request (like the client's IP address and that the request came over HTTPS).
Step 3: Verify and Restart Nginx
First, check for syntax errors in your config:
sudo nginx -t
If you see "test is successful", restart Nginx to apply the changes:
sudo systemctl restart nginx
Step 4: Secure Your EC2 Security Group
Make sure your EC2 security group allows inbound traffic on:
- Port 80 (HTTP) — for redirecting to HTTPS
- Port 443 (HTTPS) — the main public entry point for your site
You don't need to open ports 5000 or 8080 to the public — since Nginx forwards requests locally, those ports only need to be accessible from the server itself.
That should resolve the issue! Now all traffic to your site (including /api requests) will flow through HTTPS via Nginx, and your React app and Node backend will communicate securely behind the scenes.
内容的提问来源于stack exchange,提问作者ilvcs

