
我在 Nginx 反向代理後面使用 Keycloak Quay 22.0.3 和 docker-compose,但由於自動替換了 certbot 生成的證書,我遇到了一些麻煩。
我的憑證是用 certbot 產生的,完全沒問題,它說它將在 3 個月後過期,(頒發者)其 CN 是 R3,其組織是 Let's Encrypt(與其他網域一樣)。
一旦我啟動了 docker-compose 它可能使用正確的證書t時間,它使用 HTTPS,然後,突然,它被我沒有生成的一個取代,(頒發者)CN Cisco Umbrella secondary SubCA ams-SG 和組織 Cisco 以及(頒發給)組織 Cisco Systems, Inc.,而它之前是空白的,當然,連線不再是私有的( NET::ERR_CERT_AUTHORITY_INVALID
)。
這是我的 docker-compose 檔案:
version: "3.9"
services:
keycloak:
container_name: "keycloak"
image: quay.io/keycloak/keycloak:22.0.3
environment:
KC_DB: mysql
KC_DB_URL: jdbc:mysql://database_container:3306/keycloak
KC_DB_USERNAME: username
KC_DB_PASSWORD: password
KEYCLOAK_ADMIN: kc_admin
KEYCLOAK_ADMIN_PASSWORD: kc_admin_password
KC_HOSTNAME: keycloak.hostname.com
KC_HOSTNAME_STRICT_HTTPS: "false"
ports:
- "8443:8443"
volumes:
- /keycloak/certs/fullchain.pem:/etc/x509/https/tls.crt
- /keycloak/certs/privkey.pem:/etc/x509/https/tls.key
command:
start --https-certificate-file=/etc/x509/https/tls.crt --https-certificate-key-file=/etc/x509/https/tls.key --hostname-strict=false
networks:
- my_network
networks:
my_network:
name: my_network
external: true
這是我的 Nginx 設定:
server {
server_name www.keycloak.hostname.com keycloak.hostname.com;
location / {
proxy_pass https://ip_address:8443/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP \$remote_addr;
proxy_buffer_size 256k;
proxy_buffers 4 512k;
proxy_busy_buffers_size 512k;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
listen 443 ssl; # managed by Certbot
ssl_certificate /etc/letsencrypt/live/keycloak.hostname.com/fullchain.pem; # managed by Certbot
ssl_certificate_key /etc/letsencrypt/live/keycloak.hostname.com/privkey.pem; # managed by Certbot
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
}
server {
if ($host = www.keycloak.hostname.com) {
return 301 https://$host$request_uri;
} # managed by Certbot
if ($host = keycloak.hostname.com) {
return 301 https://$host$request_uri;
} # managed by Certbot
server_name www.keycloak.hostname.com keycloak.hostname.com;
listen 80;
return 404; # managed by Certbot
}
docker-compose 中使用的憑證是/etc/letsencrypt/live/keycloak.hostname.com/*
且具有 655 權限。
編輯
我忘了提及,Cisco Umbrella 頒發的憑證有效期限為 09-17-2023 至 09-22-2023。