Apache 2.4(Windows环境)启用Brotli预压缩后首次请求缓慢及间歇性无响应问题排查求助
Apache 2.4(Windows环境)启用Brotli预压缩后首次请求缓慢及间歇性无响应问题排查求助
问题背景
我最近在自己的网站上启用了Brotli预压缩静态HTML文件,功能本身是正常的,但从那之后,Apache的所有虚拟主机都出现了响应异常——不光是专门服务这些预压缩文件的虚拟主机,所有主机都受影响。
核心症状
- 首次加载速度极慢,重启Apache后或刚完成首次加载后点击页面,服务器还能保持响应
- 但等待一段时间后,服务器就会变得无响应,重新连接需要7秒到45秒不等,甚至会导致浏览器连接超时
浏览器具体表现
不同浏览器显示的异常状态有差异:
- Chrome:Timing面板显示「Initial Connection/SSL」,但连接挂起时没有任何详细信息
- Microsoft Edge:Waterfall面板中,连接挂起时显示「Establishing secure connection ...」
- FireFox:Timings面板标记为「Blocked」,挂起时显示「Performing TLS handshake with(我的static子域名)」或「Transferring data from connect.facebook.net」,有时Blocked时长和TLS Setup时长几乎一致
我的怀疑方向
- 是否和我之前遇到的「内部网络断连」问题有关?
- 会不会是我自身的操作导致的?我目前正在从三个不同域名发起批量异步调用(每次18个),生成HTML页面后做压缩处理并推送到其他服务器,总共要处理约5000页,CPU长期维持在80%左右,会不会是这个操作过载了Apache?
- 我也在Stack Overflow上找过类似问题尝试解决,但没有效果
服务器及关键配置
硬件与基础环境
- 服务器:Apache/2.4.39 (Win64) OpenSSL/1.1.1c PHP/8.1.10
- CPU:i7-8700 @ 3.20GHz
- 内存:48GB可用
- DNS TTL:3小时(因为近期准备把文件迁移到不同服务器)
httpd-default.conf 关键配置
Timeout 300 KeepAlive On MaxKeepAliveRequests 1000 KeepAliveTimeout 40 # reqtimeout module is disabled #<IfModule reqtimeout_module> # RequestReadTimeout header=20-40,MinRate=500 body=20,MinRate=500 #</IfModule>
httpd-ssl.conf 关键配置
SSLSessionCacheTimeout 300 SSLUseStapling Off HostnameLookups Off EnableSendfile Off EnableMMAP Off <VirtualHost *:443> Protocols h2 h2c http/1.1 ... SSLEngine on ... SSLHonorCipherOrder on SSLProtocol ALL -SSLv2 -SSLv3 -TLSv1 -TLSv1.1 SSLCipherSuite ECDH+AESGCM:ECDH+CHACHA20:DH+AESGCM:ECDH+AES256:DH+AES256:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS </VirtualHost>
已尝试的排查步骤
- 将
<VirtualHost *:443>改为<VirtualHost 0.0.0.0:443>(我只用IPv4),无改善 - 关闭防火墙,排除防火墙影响,问题依旧
- 执行
openssl s_client -connect www.filmfix.com:443 -status -servername www.filmfix.com,输出如下:
CONNECTED(000001B8) depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1 verify error:num=20:unable to get local issuer certificate verify return:1 depth=1 C = US, O = Let's Encrypt, CN = R3 verify return:1 depth=0 CN = *.my_domainname_dot_com verify return:1 OCSP response: no response sent --- Certificate chain 0 s:CN = *.my_domainname_dot_com i:C = US, O = Let's Encrypt, CN = R3 1 s:C = US, O = Let's Encrypt, CN = R3 i:C = US, O = Internet Security Research Group, CN = ISRG Root X1 2 s:C = US, O = Internet Security Research Group, CN = ISRG Root X1 i:O = Digital Signature Trust Co., CN = DST Root CA X3 --- Server certificate -----BEGIN CERTIFICATE----- ... -----END CERTIFICATE----- subject=CN = *.my_domainname_dot_com issuer=C = US, O = Let's Encrypt, CN = R3 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA-PSS Server Temp Key: X25519, 253 bits --- SSL handshake has read 5026 bytes and written 406 bytes Verification error: unable to get local issuer certificate --- New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384 Server public key is 4096 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 20 (unable to get local issuer certificate) --- --- Post-Handshake New Session Ticket arrived: SSL-Session: Protocol : TLSv1.3 Cipher : TLS_AES_256_GCM_SHA384 Session-ID: 3D6884662... Session-ID-ctx: Resumption PSK: 5EA6E2B7D... PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 300 (seconds) TLS session ticket: 0000 ... 3i. Start Time: 1691621025 Timeout : 7200 (sec) Verify return code: 20 (unable to get local issuer certificate) Extended master secret: no Max Early Data: 0 --- read R BLOCK --- Post-Handshake New Session Ticket arrived: SSL-Session: Protocol : TLSv1.3 Cipher : TLS_AES_256_GCM_SHA384 Session-ID: 9BFE3... Session-ID-ctx: Resumption PSK: 38FFBF004D... PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 300 (seconds) TLS session ticket: 0000 - a9 01 cb ... a2 40 ....)..d...!.4.@ Start Time: 1691621025 Timeout : 7200 (sec) Verify return code: 20 (unable to get local issuer certificate) Extended master secret: no Max Early Data: 0 --- read R BLOCK
- 执行
httpd -D DUMP_RUN_CFG,输出如下:
C:\64bit\Apache24\bin>httpd -D DUMP_RUN_CFG ServerRoot: "C:/64bit/Apache24" Main DocumentRoot: "C:/64bit/htdocs" Main ErrorLog: "E:/log-files/apache/error_.log" Mutex rewrite-map: using_defaults Mutex ssl-stapling-refresh: using_defaults Mutex ssl-stapling: using_defaults Mutex proxy: using_defaults Mutex ssl-cache: using_defaults Mutex default: dir="C:/64bit/Apache24/logs/" mechanism=default PidFile: "C:/64bit/Apache24/logs/httpd.pid" Define: DUMP_RUN_CFG
求助需求
希望各位能帮忙分析可能的原因,以及给出对应的解决思路或方案,非常感谢!
备注:内容来源于stack exchange,提问作者MeSo2
相关产品推荐
相关产品推荐

