温馨提示×

怎么查debian nginxssl状态

小樊
44
2026-09-23 23:59:06
栏目: 云计算

在 Debian 上查看 Nginx 的 SSL/TLS 状态,可以从服务状态、配置是否启用 SSL、证书有效性、实际连接几个层面来查。下面按常用方式说明。


一、看 Nginx 是否在运行

systemctl status nginx

或

service nginx status

看到 active (running) 说明服务正常。


二、检查 Nginx 是否支持 / 已启用 SSL

1. 查看 Nginx 是否编译了 SSL

nginx -V 2>&1 | grep -o with-http_ssl_module

有输出说明支持 SSL。

2. 检查配置里是否启用了 SSL

nginx -T 2>/dev/null | grep -E "listen.*ssl|ssl_certificate"

常见正常输出:

listen 443 ssl;
ssl_certificate /etc/ssl/certs/xxx.crt;
ssl_certificate_key /etc/ssl/private/xxx.key;

三、检查 SSL 配置文件语法

nginx -t

输出:

nginx: configuration file /etc/nginx/nginx.conf test is successful

说明 SSL 配置语法没问题。


四、查看监听端口(是否监听 443)

ss -tlnp | grep -E ':443|:80'

或

netstat -tlnp | grep 443

看到 0.0.0.0:443 表示 HTTPS 已监听。


五、检查 SSL 证书状态(有效期)

openssl x509 -in /路径/证书.crt -noout -dates

示例:

notBefore=May  1 00:00:00 2024 GMT
notAfter =May  1 23:59:59 2025 GMT

如果是 Let’s Encrypt:

certbot certificates

六、真实测试 HTTPS 是否正常

本地测试

openssl s_client -connect localhost:443 -servername 你的域名

外部测试(推荐)

curl -I https://你的域名

或用:

nmap --script ssl-cert,ssl-enum-ciphers -p 443 你的域名

七、查看 SSL 协议 / 加密套件

nginx -T 2>/dev/null | grep -E "ssl_protocols|ssl_ciphers"

典型安全配置:

ssl_protocols TLSv1.2 TLSv1.3;

八、常见排错思路

  • ❌ 443 没监听 → 没写 listen 443 ssl;
  • ❌ 证书路径错 → nginx -t 会报错
  • ❌ 防火墙挡住 → ufw status
  • ❌ 证书过期 → openssl x509 -dates

如果你愿意,可以贴出:

  • Debian 版本
  • Nginx 配置(server 段)
  • 报错信息

我可以直接帮你定位 SSL 状态异常原因。

0 踩