diff --git a/nginx.conf.gateway b/nginx.conf.gateway index f24c008..e1dc95f 100644 --- a/nginx.conf.gateway +++ b/nginx.conf.gateway @@ -21,8 +21,6 @@ http { tcp_nopush on; tcp_nodelay on; keepalive_timeout 65; - proxy_ssl_verify on; - proxy_ssl_trusted_certificate /etc/nginx/certs/bzpt_sys-internal.crt; # Gzip 压缩1 gzip on; gzip_vary on; @@ -36,6 +34,7 @@ http { # 认证中心 (IdentityServer4) upstream auth_server { server sys-api:19902; + proxy_ssl_verify off; # 关闭证书验证 } # Sys 系统 API @@ -46,6 +45,7 @@ http { # Lmg 系统 API upstream lmg_api { server lmg-api:19903; + proxy_ssl_verify off; # 关闭证书验证 } # Sys 系统 UI @@ -64,8 +64,8 @@ http { server_name 106.52.199.114; # 替换为您的域名或IP # --- SSL 配置 --- - ssl_certificate /etc/nginx/certs/bzpt_sys-internal.crt; - ssl_certificate_key /etc/nginx/certs/bzpt_sys-internal.key; + ssl_certificate /etc/nginx/certs/gateway.crt; + ssl_certificate_key /etc/nginx/certs/gateway.key; ssl_protocols TLSv1.2 TLSv1.3; ssl_prefer_server_ciphers on; ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;