Nginx proxy not serving assets via https
I have a Wordpress website being served by Nginx via a proxy to Apache. The website is being displayed fine but the assets are being supplied via http instead of https which is causing a few issues.
Here is my nginx conf file:
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name subdomain.website.com;
root /home/subdomain.website.com;
# SSL CERT here
ssl_certificate /etc/nginx/ssl/.../server.crt;
ssl_certificate_key /etc/nginx/ssl/.../server.key;
ssl_protocols TLSv1.2;
ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384;
ssl_prefer_server_ciphers on;
ssl_dhparam /etc/nginx/dhparams.pem;
add_header X-Frame-Options "SAMEORIGIN";
add_header X-XSS-Protection "1; mode=block";
add_header X-Content-Type-Options "nosniff";
index index.html index.htm index.php;
charset utf-8;
location / {
try_files $uri $uri/ /index.php?$query_string;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header Host $host;
proxy_pass http://127.0.0.1:8081;
proxy_set_header X-Forwarded-Proto https;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
access_log off;
error_log /var/log/nginx/subdomain.website.com-error.log error;
error_page 404 /index.php;
proxy_connect_timeout 600;
proxy_send_timeout 600;
proxy_read_timeout 600;
send_timeout 600;
location ~ /.(?!well-known).* {
deny all;
}
}
I am not quite sure what's missing from any of these rules for http files to be served via the proxy using https?
Many thanks!
wordpress apache nginx nginx-reverse-proxy
add a comment |
I have a Wordpress website being served by Nginx via a proxy to Apache. The website is being displayed fine but the assets are being supplied via http instead of https which is causing a few issues.
Here is my nginx conf file:
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name subdomain.website.com;
root /home/subdomain.website.com;
# SSL CERT here
ssl_certificate /etc/nginx/ssl/.../server.crt;
ssl_certificate_key /etc/nginx/ssl/.../server.key;
ssl_protocols TLSv1.2;
ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384;
ssl_prefer_server_ciphers on;
ssl_dhparam /etc/nginx/dhparams.pem;
add_header X-Frame-Options "SAMEORIGIN";
add_header X-XSS-Protection "1; mode=block";
add_header X-Content-Type-Options "nosniff";
index index.html index.htm index.php;
charset utf-8;
location / {
try_files $uri $uri/ /index.php?$query_string;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header Host $host;
proxy_pass http://127.0.0.1:8081;
proxy_set_header X-Forwarded-Proto https;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
access_log off;
error_log /var/log/nginx/subdomain.website.com-error.log error;
error_page 404 /index.php;
proxy_connect_timeout 600;
proxy_send_timeout 600;
proxy_read_timeout 600;
send_timeout 600;
location ~ /.(?!well-known).* {
deny all;
}
}
I am not quite sure what's missing from any of these rules for http files to be served via the proxy using https?
Many thanks!
wordpress apache nginx nginx-reverse-proxy
Most likelytry_files
might be working but the result is replaced by theproxy_pass
– Shawn C.
Nov 26 '18 at 20:42
add a comment |
I have a Wordpress website being served by Nginx via a proxy to Apache. The website is being displayed fine but the assets are being supplied via http instead of https which is causing a few issues.
Here is my nginx conf file:
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name subdomain.website.com;
root /home/subdomain.website.com;
# SSL CERT here
ssl_certificate /etc/nginx/ssl/.../server.crt;
ssl_certificate_key /etc/nginx/ssl/.../server.key;
ssl_protocols TLSv1.2;
ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384;
ssl_prefer_server_ciphers on;
ssl_dhparam /etc/nginx/dhparams.pem;
add_header X-Frame-Options "SAMEORIGIN";
add_header X-XSS-Protection "1; mode=block";
add_header X-Content-Type-Options "nosniff";
index index.html index.htm index.php;
charset utf-8;
location / {
try_files $uri $uri/ /index.php?$query_string;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header Host $host;
proxy_pass http://127.0.0.1:8081;
proxy_set_header X-Forwarded-Proto https;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
access_log off;
error_log /var/log/nginx/subdomain.website.com-error.log error;
error_page 404 /index.php;
proxy_connect_timeout 600;
proxy_send_timeout 600;
proxy_read_timeout 600;
send_timeout 600;
location ~ /.(?!well-known).* {
deny all;
}
}
I am not quite sure what's missing from any of these rules for http files to be served via the proxy using https?
Many thanks!
wordpress apache nginx nginx-reverse-proxy
I have a Wordpress website being served by Nginx via a proxy to Apache. The website is being displayed fine but the assets are being supplied via http instead of https which is causing a few issues.
Here is my nginx conf file:
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name subdomain.website.com;
root /home/subdomain.website.com;
# SSL CERT here
ssl_certificate /etc/nginx/ssl/.../server.crt;
ssl_certificate_key /etc/nginx/ssl/.../server.key;
ssl_protocols TLSv1.2;
ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384;
ssl_prefer_server_ciphers on;
ssl_dhparam /etc/nginx/dhparams.pem;
add_header X-Frame-Options "SAMEORIGIN";
add_header X-XSS-Protection "1; mode=block";
add_header X-Content-Type-Options "nosniff";
index index.html index.htm index.php;
charset utf-8;
location / {
try_files $uri $uri/ /index.php?$query_string;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header Host $host;
proxy_pass http://127.0.0.1:8081;
proxy_set_header X-Forwarded-Proto https;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
access_log off;
error_log /var/log/nginx/subdomain.website.com-error.log error;
error_page 404 /index.php;
proxy_connect_timeout 600;
proxy_send_timeout 600;
proxy_read_timeout 600;
send_timeout 600;
location ~ /.(?!well-known).* {
deny all;
}
}
I am not quite sure what's missing from any of these rules for http files to be served via the proxy using https?
Many thanks!
wordpress apache nginx nginx-reverse-proxy
wordpress apache nginx nginx-reverse-proxy
asked Nov 26 '18 at 18:30
ChikoChiko
1,17421220
1,17421220
Most likelytry_files
might be working but the result is replaced by theproxy_pass
– Shawn C.
Nov 26 '18 at 20:42
add a comment |
Most likelytry_files
might be working but the result is replaced by theproxy_pass
– Shawn C.
Nov 26 '18 at 20:42
Most likely
try_files
might be working but the result is replaced by the proxy_pass
– Shawn C.
Nov 26 '18 at 20:42
Most likely
try_files
might be working but the result is replaced by the proxy_pass
– Shawn C.
Nov 26 '18 at 20:42
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53487026%2fnginx-proxy-not-serving-assets-via-https%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53487026%2fnginx-proxy-not-serving-assets-via-https%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Most likely
try_files
might be working but the result is replaced by theproxy_pass
– Shawn C.
Nov 26 '18 at 20:42