在 Debian 上,使用 Nginx + SSL 时,检测配置是否正确的常用方法如下:
sudo nginx -t
或(如果 nginx 不在 PATH):
sudo /usr/sbin/nginx -t
✅ 正常输出示例:
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: configuration file /etc/nginx/nginx.conf test is successful
❌ 如果有错误,会直接指出文件和行号。
常见 SSL 配置项(在 server 块中):
listen 443 ssl;
ssl_certificate /etc/nginx/ssl/example.com.crt;
ssl_certificate_key /etc/nginx/ssl/example.com.key;
检查:
openssl x509 -noout -modulus -in cert.crt | openssl md5
openssl rsa -noout -modulus -in key.key | openssl md5
两个 md5 值必须一致。
修改配置后:
sudo nginx -t
sudo systemctl reload nginx
或:
sudo service nginx reload
sudo ss -tulnp | grep nginx
应看到:
LISTEN 0 128 0.0.0.0:443
openssl s_client -connect localhost:443
sudo tail -f /var/log/nginx/error.log
常见 SSL 错误:
cannot load certificateSSL_CTX_use_PrivateKey_file failedSSL routines:SSL23_GET_SERVER_HELLOsudo apt install ssl-cert
或使用:
sudo certbot --nginx
如果你愿意,可以把 nginx 的 SSL 配置片段 或 报错信息 发出来,我可以帮你精准分析。