akeneo / pim-community-dev

[Community Development Repository] The open source Product Information Management (PIM)
http://www.akeneo.com
Other
952 stars 514 forks source link

Akeneo images are not loading (ns_error_dom_bad_uri, ns_error_unexpected) #20347

Closed MS-INTAR closed 9 months ago

MS-INTAR commented 10 months ago

:bug: I'm reporting a Bug :bug:

After logging into Akeneo CE 6.0.108 images are not displayed. Everything worked until I added certificate to nginx configuration. PIM installed with Docker.

obraz obraz obraz

nginx sites-available conf `server { listen 80; listen [::]:80; server_name 192.168.0.78;

    return 301 https://192.168.0.78$request_uri;

} server { listen 443 ssl http2; server_name 192.168.0.78;

    access_log /var/log/nginx/akeneo.prod-access.log;
    error_log /var/log/nginx/akeneo.prod-error.log;

    ssl_certificate         /etc/nginx/ssl/crt.pem;
    ssl_certificate_key     /etc/nginx/ssl/private.key;
    ssl_trusted_certificate /etc/nginx/ssl/crt.pem;

    ssl_session_cache shared:SSL:50m;
    ssl_session_timeout 5m;
    ssl_stapling on;
    ssl_stapling_verify on;

    ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
    ssl_ciphers "ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4";

    location / {
    proxy_pass  http://127.0.0.1:8080$request_uri;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Host $host;
    proxy_set_header Host $host;
    proxy_set_header X-Scheme https;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-Proto https;
    proxy_set_header X-Forwarded-Port 443;
    proxy_set_header X-Secure on;
    proxy_set_header Accept-Encoding "";
    proxy_set_header Connection "";
    proxy_http_version 1.1;
    proxy_read_timeout 7200s;
    proxy_send_timeout 7200s;
}

}`

MS-INTAR commented 9 months ago

solved

nginx sites-available conf add_header 'Content-Security-Policy' 'upgrade-insecure-requests';