简体   繁体   English

从Nginx将Certbot从HTTP重定向到HTTPS无效

[英]Certbot Redirection of HTTP to HTTPS from Nginx is not working

I'm setting ssl server on Nginx with proxy_pass to apache. 我在Nginx上将ssl服务器设置为apache的proxy_pass。

The code was recreated by certbot and is not working. 该代码已由certbot重新创建,无法正常工作。 I can't find out what's wrong. 我找不到问题所在。

I've also tried to replace $host by $server_name and other suggestions from forum with no success. 我还尝试用$ server_name替换$ host以及论坛中的其他建议,但均未成功。

    server {
        server_name biofit.blog www.biofit.blog;
        listen [::]:443 ssl ipv6only=on; # managed by Certbot
        listen 443 ssl; # managed by Certbot
        ssl_certificate                 /etc/letsencrypt/live/gekko.winsum.ws/fullchain.pem; # managed by Certbot
        ssl_certificate_key /etc/letsencrypt/live/gekko.winsum.ws/privkey.pem; # managed by Certbot
        include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
        ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

        location / {
                proxy_buffers 8 32k;
                proxy_buffer_size 64k;
                proxy_pass http://biofit.blog:81;
                proxy_set_header Host $http_host;
                proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                proxy_set_header X-NginX-Proxy true;
                proxy_http_version 1.1;
                proxy_set_header Upgrade $http_upgrade;
                proxy_set_header Connection "upgrade";
                proxy_read_timeout 86400s;
                proxy_send_timeout 86400s;
        }
    }

    server {
       if ($host = www.biofit.blog) {
           return 301 https://$host$request_uri;
        } # managed by Certbot
      if ($host = biofit.blog) {
            return 301 https://$host$request_uri;
        } # managed by Certbot

        listen 80;
        listen [::]:80;
        server_name biofit.blog www.biofit.blog;
        return 404; # managed by Certbot
    }

The expected output of ssl should pass to apache running on port 81, but not: ERR_TOO_MANY_REDIRECTS ssl的预期输出应传递给在端口81上运行的apache,而不是:ERR_TOO_MANY_REDIRECTS

it's not recommended to use if statement try this: 不建议使用if语句尝试以下操作:

    server {

        listen 80;
        listen [::]:80;
        server_name biofit.blog www.biofit.blog;
        rewrite     ^   https://$server_name$request_uri? permanent;
        return 404; # managed by Certbot
    }

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM