You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署Comodo证书后WSS握手超时问题求助

Fixing WebSocket wss:// Handshake Timeout After Enabling Comodo SSL with Angular 2 & PHP

It sounds like you hit a super common pitfall when switching from unencrypted ws:// to encrypted wss:// WebSockets—your PHP WebSocket server isn’t set up to handle SSL/TLS connections, and just swapping the protocol in your client code won’t solve the problem. Let’s break down the fixes step by step:

Most basic PHP WebSocket implementations run on raw TCP without SSL support. The easiest and most production-friendly way to add wss:// support is to use a reverse proxy like Nginx to handle SSL termination (it’s way more optimized for this than PHP).

Example Nginx Configuration

Add this block to your Nginx config (make sure you’re listening on port 443):

server {
    listen 443 ssl;
    server_name your-domain.com;

    # Paths to your Comodo SSL files
    ssl_certificate /path/to/your/comodo-primary-cert.crt;
    ssl_certificate_key /path/to/your/private-key.key;
    # Don't forget Comodo's intermediate certificates!
    ssl_trusted_certificate /path/to/comodo-intermediate.crt;

    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;

    # Proxy wss:// requests to your local ws:// server
    location /ws {
        proxy_pass http://localhost:8080; # Replace with your PHP WS server's port
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }
}

After updating, restart Nginx. Your Angular client can now connect to wss://your-domain.com/ws.

2. Add SSL Support Directly to Your PHP WebSocket Server

If you’d rather handle SSL directly in PHP (not ideal for production due to performance), modify your server code to enable TLS encryption using stream_socket_enable_crypto.

Modified PHP Server Snippet

Right after accepting a client connection, add this code:

// After $client = stream_socket_accept($socket);
$certPath = '/path/to/your/comodo-cert.crt';
$keyPath = '/path/to/your/private-key.key';

// Enable TLS encryption for the connection
stream_socket_enable_crypto($client, true, STREAM_CRYPTO_METHOD_TLS_SERVER);

Make sure your PHP server listens on a dedicated port (e.g., 8443) and update your Angular client to connect to wss://your-domain.com:8443.

3. Verify Your Comodo Certificate Chain

A huge number of handshake failures happen because the certificate chain is incomplete. Comodo requires intermediate certificates to be installed alongside your main cert to be trusted by browsers.

  • Run openssl s_client -connect your-domain.com:443 (or your WS port if using direct SSL) to check the chain. Look for "Verify return code: 0 (ok)" in the output.
  • If there’s an error, double-check that you’ve installed all intermediate certificates provided by Comodo.

4. Check Firewall & Port Access

  • If your WebSocket server uses a non-standard port (like 8080 or 8443), confirm your server’s firewall (and any cloud firewalls, e.g., AWS Security Groups) allows inbound traffic on that port for SSL.
  • Some hosting providers block non-standard SSL ports, so check their docs or reach out to support if you’re stuck.

5. Debug with Browser DevTools

Open your browser’s Network tab, filter for "WS" connections, and inspect the failed handshake. Look for:

  • Certificate errors: Means trust issues (fix your certificate chain).
  • 502 Bad Gateway: Nginx can’t reach your PHP WebSocket server (check the proxy port and make sure the server is running).
  • Connection timed out: Firewall block or the WebSocket server isn’t listening on the correct port.

内容的提问来源于stack exchange,提问作者user715070

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:52:26