排查Nginx SSL证书告警应聚焦三类典型错误:证书加载失败(如路径不存在、私钥不匹配)、链验证失败(中间证书缺失或顺序错误)、运行时匹配异常(SNI不匹配、证书过期),warn或error级别日志即可捕获,无需debug。

排查 Nginx error_log 中因 SSL 证书错误引发的告警,关键不是泛查日志,而是聚焦三类典型报错模式:证书加载失败、链验证失败、运行时匹配异常。这些错误在 warn 或 error 级别即可捕获,无需开启 debug。
识别证书加载阶段的硬性错误
这类错误出现在 Nginx 启动或重载时,直接阻断服务,error_log 中会明确提示路径或格式问题:
-
文件路径错误:如
SSL_CTX_use_certificate_chain_file("/etc/nginx/ssl/fullchain.pem") failed (SSL: error:02001002:system library:fopen:No such file or directory)—— 检查ssl_certificate路径是否存在、Nginx 进程是否有读取权限(ls -l /etc/nginx/ssl/) -
私钥不匹配:如
SSL_CTX_use_PrivateKey_file("/etc/nginx/ssl/key.pem") failed (SSL: error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch)—— 用openssl x509 -noout -modulus -in cert.pem | openssl md5和openssl rsa -noout -modulus -in key.pem | openssl md5对比输出是否一致 -
私钥加密未解密:如
SSL_CTX_use_PrivateKey_file() failed (SSL: error:0909006C:PEM routines:get_name:no start line)—— 表明私钥被密码保护,需先用openssl rsa -in key.pem -out key_decrypted.pem解密(生产环境慎用)
定位证书链完整性问题
客户端无法建立信任时,错误常出现在访问阶段,error_log 可能不直接报错,但 access_log 中会伴随 400 或连接中断,需结合 openssl s_client 验证:
- 执行
openssl s_client -connect yourdomain.com:443 -servername yourdomain.com -showcerts 2>/dev/null | openssl crl2pkcs7 -nocrl -certfile /dev/stdin | openssl pkcs7 -print_certs -noout,确认输出中包含服务器证书 + 所有中间证书,且末尾为可信根(如 ISRG Root X1) - 若
openssl verify -CAfile /etc/ssl/certs/ca-certificates.crt fullchain.pem报unable to get local issuer certificate,说明中间证书缺失或顺序颠倒 —— 应确保ssl_certificate指向的文件中,证书顺序为:服务器证书 → 中间证书(可多个),不包含根证书 - Nginx 日志中偶见
SSL_do_handshake() failed (SSL: error:1417A0C1:...no shared cipher),表面是套件问题,实则可能是客户端因证书链不全而提前终止握手
捕捉运行时证书不匹配告警
这类问题多发生在 SNI 场景或多域名共用 IP 的配置中,错误较隐蔽,但 error_log 在 warn 级别即会记录:
-
SSL certificate does not match the server name:表示请求的Host或 SNI 名称与当前 server 块中server_name不匹配,且该块又启用了 SSL —— 检查是否漏配server_name,或存在多个server块监听同一端口但未正确区分域名 -
no suitable certificate found for SSL client authentication:若启用双向认证(ssl_client_certificate),但客户端未提供证书或证书不可信 —— 此类告警属预期行为,无需修复配置,但需确认业务是否真需双向认证 - 证书过期前 30 天,Nginx 会发出
warn级日志:SSL: PEM_read_bio_X509_AUX("/etc/nginx/ssl/cert.pem") failed (SSL: error:0909006C:...)或更明确的certificate is expired提示 —— 建议用openssl x509 -in cert.pem -enddate -noout主动检查有效期


















