Nginx多域名同IP配置不同SSL证书问题求助
This is a classic SNI-related issue! Let's break down why your current config isn't working and how to fix it properly within a single Nginx instance.
When multiple server blocks listen on the same IP:443 port, Nginx relies on SNI (Server Name Indication) to identify which domain the client is accessing and serve the matching SSL certificate. If SNI support is missing or your config has subtle mismatches, Nginx will fall back to serving the certificate from the first matching server block—which is exactly why you're seeing domain1's cert on domain2.
Step 1: Verify Nginx Supports SNI
First, confirm your Nginx installation has the SSL module enabled and uses a modern enough OpenSSL version (SNI requires OpenSSL ≥ 0.9.8f and Nginx ≥ 0.8.21). Run this command to check:
nginx -V
Look for --with-http_ssl_module in the configure arguments, and verify the linked OpenSSL version meets the requirement. Most official Nginx packages already include this support by default.
Step 2: Fix Your Nginx Config
Your original config has redundant HTTP redirect blocks, but the core fix is ensuring each HTTPS server block is explicitly tied to its domain. Here's a cleaned-up, working version:
# Unified HTTP → HTTPS redirect for all domains (cuts down on repetition) server { listen 80; server_name domain1.com domain2.com domainN.com; return 301 https://$host$request_uri; } # HTTPS config for domain1.com server { listen 443 ssl; server_name domain1.com; root /app/dist; index index.html; # Path to domain1's unique SSL certificate/key ssl_certificate /etc/nginx/ssl/d1/certificate.crt; ssl_certificate_key /etc/nginx/ssl/d1/private.key; location / { try_files $uri $uri/ /index.html; } } # HTTPS config for domain2.com server { listen 443 ssl; server_name domain2.com; root /app/dist; index index.html; # Path to domain2's unique SSL certificate/key ssl_certificate /etc/nginx/ssl/d2/certificate.crt; ssl_certificate_key /etc/nginx/ssl/d2/private.key; location / { try_files $uri $uri/ /index.html; } } # Repeat the HTTPS block pattern for domainN.com with its own cert paths
Step 3: Validate and Reload Nginx
Always check your config for syntax errors before applying changes:
nginx -t
If you see test is successful, reload Nginx to activate the new config:
# For systemd-based systems (Ubuntu/Debian 16.04+, RHEL/CentOS 7+) systemctl reload nginx # For older sysvinit systems service nginx reload
Additional Troubleshooting Tips
- Check certificate validity: Ensure each certificate is actually issued for its target domain. Use this command to inspect a cert:
Look for theopenssl x509 -in /etc/nginx/ssl/d2/certificate.crt -text -nooutSubjectfield (should match domain2.com) andX509v3 Subject Alternative Name(if present, must include domain2.com). - Confirm client SNI support: Almost all modern browsers and HTTP clients support SNI, but if testing with an old tool (like IE < 7), it won't work. Use a modern browser or
curl(v7.18.1+) to verify:
Look for a line likecurl -v https://domain2.comServer name: domain2.comin the SSL handshake logs to confirm SNI is being used.
内容的提问来源于stack exchange,提问作者Utkarsh Narain Srivastava

