You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx多域名同IP配置不同SSL证书问题求助

This is a classic SNI-related issue! Let's break down why your current config isn't working and how to fix it properly within a single Nginx instance.

When multiple server blocks listen on the same IP:443 port, Nginx relies on SNI (Server Name Indication) to identify which domain the client is accessing and serve the matching SSL certificate. If SNI support is missing or your config has subtle mismatches, Nginx will fall back to serving the certificate from the first matching server block—which is exactly why you're seeing domain1's cert on domain2.

Step 1: Verify Nginx Supports SNI

First, confirm your Nginx installation has the SSL module enabled and uses a modern enough OpenSSL version (SNI requires OpenSSL ≥ 0.9.8f and Nginx ≥ 0.8.21). Run this command to check:

nginx -V

Look for --with-http_ssl_module in the configure arguments, and verify the linked OpenSSL version meets the requirement. Most official Nginx packages already include this support by default.

Step 2: Fix Your Nginx Config

Your original config has redundant HTTP redirect blocks, but the core fix is ensuring each HTTPS server block is explicitly tied to its domain. Here's a cleaned-up, working version:

# Unified HTTP → HTTPS redirect for all domains (cuts down on repetition)
server {
    listen 80;
    server_name domain1.com domain2.com domainN.com;
    return 301 https://$host$request_uri;
}

# HTTPS config for domain1.com
server {
    listen 443 ssl;
    server_name domain1.com;

    root /app/dist;
    index index.html;

    # Path to domain1's unique SSL certificate/key
    ssl_certificate /etc/nginx/ssl/d1/certificate.crt;
    ssl_certificate_key /etc/nginx/ssl/d1/private.key;

    location / {
        try_files $uri $uri/ /index.html;
    }
}

# HTTPS config for domain2.com
server {
    listen 443 ssl;
    server_name domain2.com;

    root /app/dist;
    index index.html;

    # Path to domain2's unique SSL certificate/key
    ssl_certificate /etc/nginx/ssl/d2/certificate.crt;
    ssl_certificate_key /etc/nginx/ssl/d2/private.key;

    location / {
        try_files $uri $uri/ /index.html;
    }
}

# Repeat the HTTPS block pattern for domainN.com with its own cert paths

Step 3: Validate and Reload Nginx

Always check your config for syntax errors before applying changes:

nginx -t

If you see test is successful, reload Nginx to activate the new config:

# For systemd-based systems (Ubuntu/Debian 16.04+, RHEL/CentOS 7+)
systemctl reload nginx

# For older sysvinit systems
service nginx reload

Additional Troubleshooting Tips

  • Check certificate validity: Ensure each certificate is actually issued for its target domain. Use this command to inspect a cert:
    openssl x509 -in /etc/nginx/ssl/d2/certificate.crt -text -noout
    
    Look for the Subject field (should match domain2.com) and X509v3 Subject Alternative Name (if present, must include domain2.com).
  • Confirm client SNI support: Almost all modern browsers and HTTP clients support SNI, but if testing with an old tool (like IE < 7), it won't work. Use a modern browser or curl (v7.18.1+) to verify:
    curl -v https://domain2.com
    
    Look for a line like Server name: domain2.com in the SSL handshake logs to confirm SNI is being used.

内容的提问来源于stack exchange,提问作者Utkarsh Narain Srivastava

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 07:13:02