如何将AWS EC2实例从HTTP重定向至HTTPS?Jenkins证书配置故障
Fixing Jenkins HTTPS & Redirect Issues on AWS EC2
Let’s tackle your problems one by one—first fixing that annoying "not secure" certificate warning, then setting up reliable HTTP-to-HTTPS redirects for your Jenkins instance.
1. Resolve the "Not Secure" Certificate Warning
The error you’re seeing is almost certainly because the self-signed certificate from the tutorial isn’t trusted by browsers by default. Here are two solutions:
Option A: Use Let’s Encrypt (Trusted, Free Cert – Recommended for Production)
This is the best approach for public-facing instances:
- Step 1: Install Certbot
On Ubuntu/Debian:
On Amazon Linux 2/RHEL/CentOS:sudo apt update && sudo apt install certbot -ysudo amazon-linux-extras install epel -y && sudo yum install certbot -y - Step 2: Validate Your Domain
First, confirm your domainmyinstance.compoints to your EC2 instance’s public (or elastic) IP. Temporarily stop Jenkins to free up port 80:
Run Certbot to generate the trusted certificate:sudo systemctl stop jenkins
Follow the prompts to verify domain ownership.sudo certbot certonly --standalone -d myinstance.com - Step 3: Configure Jenkins to Use the Cert
Open your Jenkins config file (location varies by OS):- Ubuntu/Debian:
/etc/default/jenkins - Amazon Linux/RHEL:
/etc/sysconfig/jenkins
Modify these parameters:
# Disable default HTTP port (or keep it for redirects later) HTTP_PORT="-1" # Set HTTPS to standard port 443 HTTPS_PORT="443" # Add SSL cert paths to Jenkins startup args JENKINS_ARGS="--httpsPort=$HTTPS_PORT --httpsCertificate=/etc/letsencrypt/live/myinstance.com/fullchain.pem --httpsPrivateKey=/etc/letsencrypt/live/myinstance.com/privkey.pem" - Ubuntu/Debian:
- Step 4: Restart Jenkins
Visitingsudo systemctl restart jenkinshttps://myinstance.comshould now show a trusted connection.
Option B: Fix Self-Signed Cert (For Testing Only)
If you’re just testing, you can fix the trust issue:
- Regenerate the cert with your actual domain as the Common Name (CN) (this is critical):
When prompted, enterkeytool -genkey -keyalg RSA -alias jenkins -keystore /var/lib/jenkins/jenkins.jks -validity 3650 -keysize 2048myinstance.comas the Common Name. - Update Jenkins to use this new keystore in your config file, then export the cert to import into your browser:
keytool -export -alias jenkins -keystore /var/lib/jenkins/jenkins.jks -file jenkins.crt - Import
jenkins.crtinto your browser’s trusted root certificates store. This stops the warning but isn’t suitable for production.
2. Set Up HTTP-to-HTTPS Redirects
You have two solid options—using Jenkins directly or a reverse proxy like Nginx (more flexible for production).
Option A: Jenkins Built-In Redirect
If you want to avoid extra software:
- Open your Jenkins config file again, set
HTTP_PORT="80"(instead of-1). - Add this to
JENKINS_ARGS:--redirectHttpToHttps - Restart Jenkins. Note: Jenkins needs root privileges to bind to port 80 (a privileged port <1024). If you get permission errors, use
authbindto grant access, or use the Nginx method below.
Option B: Nginx Reverse Proxy (Recommended)
This is more stable and scalable:
- Step 1: Install Nginx
# Ubuntu/Debian sudo apt install nginx -y # Amazon Linux/RHEL sudo yum install nginx -y - Step 2: Configure Nginx
Create a config file:- Ubuntu/Debian:
/etc/nginx/sites-available/jenkins - Amazon Linux/RHEL:
/etc/nginx/conf.d/jenkins.conf
Paste this content (adjust paths if needed):
# Redirect all HTTP traffic to HTTPS server { listen 80; server_name myinstance.com; return 301 https://$host$request_uri; } # Serve Jenkins over HTTPS server { listen 443 ssl; server_name myinstance.com; # Use Let's Encrypt certs ssl_certificate /etc/letsencrypt/live/myinstance.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/myinstance.com/privkey.pem; location / { proxy_pass http://127.0.0.1:8080; # Default Jenkins port proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } - Ubuntu/Debian:
- Step 3: Enable & Test the Config
For Ubuntu/Debian:
Test for config errors:sudo ln -s /etc/nginx/sites-available/jenkins /etc/nginx/sites-enabled/
If all is good, restart Nginx:sudo nginx -tsudo systemctl restart nginx - Step 4: Update Jenkins
In your Jenkins config file, setHTTP_PORT="8080"(default) and disable HTTPS mode (HTTPS_PORT="-1"). Then go to Jenkins UI → Manage Jenkins → Configure System → Jenkins Location and set theJenkins URLtohttps://myinstance.com. Also enable proxy compatibility in Manage Jenkins → Configure Global Security → check Enable proxy compatibility.
Final Checks
- Ensure your EC2 security group allows inbound traffic on ports 80 (HTTP) and 443 (HTTPS) from your desired IP ranges.
- If using an elastic IP for your EC2 instance, confirm your domain’s DNS record points to this static IP to avoid downtime if the instance restarts.
内容的提问来源于stack exchange,提问作者fuzzi
相关产品推荐
相关产品推荐

