求助:GoDaddy域名在AWS EC2与ELB上的SSL证书配置问题
Hey Dan, let's work through this issue step by step—you were right to suspect your initial Route 53 setup was bypassing the ALB, and switching to an alias was the correct move. Let's diagnose why both protocols are now failing and fix them:
First, Validate Your ALB Alias & Route 53 Setup
- Confirm your Route 53 A record is using an alias that points directly to your Application Load Balancer (not an EC2 instance or other resource). Run
dig atlasvehicles.comin your terminal—if it returns the ALB's DNS entries (not your EC2 IP), the alias is configured correctly. - Check that your Route 53 hosted zone matches your domain exactly (no typos) and that the alias is set to use the ALB's dual-stack endpoint (supports both IPv4 and IPv6) for maximum compatibility.
Check ALB Listener & Security Group Configuration
Your ALB needs properly configured listeners to handle both HTTP and HTTPS traffic:
- HTTP (Port 80):
- Either set up a redirect to HTTPS (port 443) for better security, or configure it to forward traffic to your EC2 instance's application port (e.g., 80, 3000).
- Ensure the ALB's security group allows inbound traffic on port 80 from
0.0.0.0/0.
- HTTPS (Port 443):
- Confirm the listener is using your valid ACM certificate (check that the certificate is issued, not pending validation).
- Configure it to forward traffic to your EC2 instance's application port (your EC2 doesn't need to handle SSL directly when using an ALB).
- Ensure the ALB's security group allows inbound traffic on port 443 from
0.0.0.0/0.
Verify EC2 & Target Group Health
- EC2 Security Group: Your instance's security group should allow inbound traffic from the ALB's security group (not the entire internet) on your app's listening port. This ensures only the ALB can send traffic to your EC2.
- Target Group Health Checks: Go to the AWS Console > EC2 > Target Groups and check if your EC2 instance is marked as "healthy". If it's unhealthy:
- Make sure the health check path matches a URL that returns a 200 OK response from your app (e.g.,
/or/health). - Adjust the health check timeout/intervals if your app takes a moment to respond.
- Confirm the target group is using the correct port for your application.
- Make sure the health check path matches a URL that returns a 200 OK response from your app (e.g.,
Check GoDaddy Nameserver Propagation
Nameserver changes can take up to 48 hours to propagate globally, though it's usually faster. Run dig ns atlasvehicles.com to confirm the nameservers listed match the ones from your Route 53 hosted zone. If propagation isn't complete, that could explain why traffic stopped working after your alias change.
Quick Test to Isolate the Issue
Grab your ALB's DNS name from the AWS Console and try accessing it directly via HTTP and HTTPS:
- If the ALB works directly, the problem is with Route 53 or nameserver propagation.
- If the ALB doesn't work, the issue lies with your ALB listeners, target group, or EC2 configuration.
Let me know what you find from these checks, and we can refine the fix further!
内容的提问来源于stack exchange,提问作者Dan J Clarke

