Nexus 앞에 리버스 프록시를 두지 않고 Jetty 가 직접 TLS 를 받게 하는 설정이다. 인증서를 JKS 키스토어로 만들어 $data-dir/etc/ssl/keystore.jks 에 두고, nexus.properties 에 HTTPS 포트와 jetty-https.xml 을 추가한다.[1] 2022년 테스트 됨.
경로 표기 — $install-dir 는 /opt/sonatype/nexus, $data-dir 는 /opt/sonatype/sonatype-work/nexus3 다 (Nexus Repository 설치 기준).
PEM 인증서와 키를 PKCS12 로 묶은 뒤 JKS 로 옮긴다. 인증서 생성은 인증서 생성 을 본다.
openssl pkcs12 -export -in $CERTIFICATE_FILE_NAME.crt -inkey $CERTIFICATE_FILE_NAME.key -out $CERTIFICATE_FILE_NAME.p12 -name "nexus"
Enter Export Password: $PASSWORD
Verifying - Enter Export Password: $PASSWORD
keytool -importkeystore -srckeystore $CERTIFICATE_FILE_NAME.p12 -srcstoretype pkcs12 -destkeystore keystore.jks -deststoretype pkcs12 -alias "nexus" -ext "SAN=DNS:$DOMAIN_NAME" -ext "BC=ca:true"
키 저장소 $CERTIFICATE_FILE_NAME.p12을(를) keystore.jks(으)로 임포트하는 중...
대상 키 저장소 비밀번호 입력: $IMPORTED_KEY_PASSWORD
새 비밀번호 다시 입력: $IMPORTED_KEY_PASSWORD
대상 키 저장소 비밀번호 입력: $PASSWORD
생성된 keystore.jks 를 $data-dir/etc/ssl/ 에 복사하고 소유자를 nexus 로 둔다.
sudo mkdir -p /opt/sonatype/sonatype-work/nexus3/etc/ssl
sudo cp keystore.jks /opt/sonatype/sonatype-work/nexus3/etc/ssl/
sudo chown -R nexus:nexus /opt/sonatype/sonatype-work/nexus3/etc/ssl
$data-dir/etc/nexus.properties 에 HTTPS 포트와 키스토어 위치를 적고, nexus-args 에 jetty-https.xml 을 붙인다. jetty-https.xml 은 $install-dir/etc/jetty/ 에 있다.
# Jetty section
application-port=8081
application-host=0.0.0.0
nexus-context-path=/
# HTTPS
application-port-ssl=8443
ssl.etc=${karaf.data}/etc/ssl
nexus-args=${jetty.etc}/jetty.xml,${jetty.etc}/jetty-http.xml,${jetty.etc}/jetty-requestlog.xml,${jetty.etc}/jetty-https.xml
HTTP 를 아예 닫으려면 nexus-args 에서 jetty-http.xml 을 뺀다.
$install-dir/etc/jetty/jetty-https.xml 에서 키스토어 비밀번호 세 개를 같은 값으로 적는다. SNI 가 필요한 인증서면 SslContextFactory$Server 클래스를 쓴다.
<!--
==== HTTPS ====
Set the following inside nexus.properties:
application-port-ssl: the port to listen for https connections
-->
<Ref refid="httpConfig">
<Set name="secureScheme">https</Set>
<Set name="securePort"><Property name="application-port-ssl" /></Set>
</Ref>
<New id="httpsConfig" class="org.eclipse.jetty.server.HttpConfiguration">
<Arg><Ref refid="httpConfig"/></Arg>
<Call name="addCustomizer">
<Arg>
<New id="secureRequestCustomizer" class="org.eclipse.jetty.server.SecureRequestCustomizer">
<!-- 7776000 seconds = 90 days -->
<Set name="stsMaxAge"><Property name="jetty.https.stsMaxAge" default="7776000"/></Set>
<Set name="stsIncludeSubDomains"><Property name="jetty.https.stsIncludeSubDomains" default="false"/></Set>
<Set name="sniHostCheck"><Property name="jetty.https.sniHostCheck" default="false"/></Set>
</New>
</Arg>
</Call>
</New>
<New id="sslContextFactory" class="org.eclipse.jetty.util.ssl.SslContextFactory$Server">
<Set name="KeyStorePath"><Property name="ssl.etc"/>/keystore.jks</Set>
<Set name="KeyStorePassword">${KEYSTORE_PASSWORD}</Set>
<Set name="KeyManagerPassword">${KEYSTORE_PASSWORD}</Set>
<Set name="TrustStorePath"><Property name="ssl.etc"/>/keystore.jks</Set>
<Set name="TrustStorePassword">${KEYSTORE_PASSWORD}</Set>
<Set name="EndpointIdentificationAlgorithm"></Set>
<Set name="NeedClientAuth"><Property name="jetty.ssl.needClientAuth" default="false"/></Set>
<Set name="WantClientAuth"><Property name="jetty.ssl.wantClientAuth" default="false"/></Set>
<Set name="IncludeProtocols">
<Array type="java.lang.String">
<Item>TLSv1.2</Item>
<Item>TLSv1.3</Item>
</Array>
</Set>
</New>
sudo firewall-cmd --permanent --add-port=8443/tcp
sudo firewall-cmd --reload
sudo systemctl restart nexus
curl -vk https://$DOMAIN_NAME:8443/ 2>&1 | grep -E 'subject|HTTP/'
접속이 되면 Settings → System → Base URL 을 https:// 주소로 바꾼다.
Configuring SSL — Inbound SSL. 2026-09-20 확인. https://help.sonatype.com/en/configuring-ssl.html ↩︎