NGINX反向代理ssl

时间:2017-08-05 04:27:25

标签: ssl nginx amazon-ec2 reverse-proxy

决定尝试在我的EC2实例上配置SSL ..它进展不顺利。下面是我启用的网站的配置文件。我在这做错了什么?该网址升级为https,但在尝试连接时超时。我已经验证了正确的proxy_pass IP和端口。

server {                                                                                
        listen 80;                                                                      

        server_name example.com;                                                         
        location / {                                                                    
                return 404;                                                             
        }                                                                               
}                                                                                       

server {                                                                                
        listen 80;                                                                      
        listen 443 ssl;                                                                 

        server_name my.example.com;                                             

        ssl_certificate /etc/letsencrypt/live/my.example.com/fullchain.pem;     
        ssl_certificate_key /etc/letsencrypt/live/my.example.com/privkey.pem;   

        location / {                                                                    
                proxy_set_header Host $host;                                            
                proxy_set_header X-Real-IP $remote_addr;                                
                proxy_set_header X-Forwarded-for $remote_addr;                          
                proxy_pass http://172.17.0.2:8080;                                      
        }                                                                               

        location /.well-known {                                                         
                root /var/www/html;                                                     
        }                                                                               
}                                 

我使用letsencrypt.org和certbot来验证和安装我的证书。

0 个答案:

没有答案