You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache 2.4(Windows环境)启用Brotli预压缩后首次请求缓慢及间歇性无响应问题排查求助

Apache 2.4(Windows环境)启用Brotli预压缩后首次请求缓慢及间歇性无响应问题排查求助

问题背景

我最近在自己的网站上启用了Brotli预压缩静态HTML文件,功能本身是正常的,但从那之后,Apache的所有虚拟主机都出现了响应异常——不光是专门服务这些预压缩文件的虚拟主机,所有主机都受影响。

核心症状

  • 首次加载速度极慢,重启Apache后或刚完成首次加载后点击页面,服务器还能保持响应
  • 但等待一段时间后,服务器就会变得无响应,重新连接需要7秒到45秒不等,甚至会导致浏览器连接超时

浏览器具体表现

不同浏览器显示的异常状态有差异:

  • Chrome:Timing面板显示「Initial Connection/SSL」,但连接挂起时没有任何详细信息
  • Microsoft Edge:Waterfall面板中,连接挂起时显示「Establishing secure connection ...」
  • FireFox:Timings面板标记为「Blocked」,挂起时显示「Performing TLS handshake with(我的static子域名)」或「Transferring data from connect.facebook.net」,有时Blocked时长和TLS Setup时长几乎一致

我的怀疑方向

  1. 是否和我之前遇到的「内部网络断连」问题有关?
  2. 会不会是我自身的操作导致的?我目前正在从三个不同域名发起批量异步调用(每次18个),生成HTML页面后做压缩处理并推送到其他服务器,总共要处理约5000页,CPU长期维持在80%左右,会不会是这个操作过载了Apache?
  3. 我也在Stack Overflow上找过类似问题尝试解决,但没有效果

服务器及关键配置

硬件与基础环境

  • 服务器:Apache/2.4.39 (Win64) OpenSSL/1.1.1c PHP/8.1.10
  • CPU:i7-8700 @ 3.20GHz
  • 内存:48GB可用
  • DNS TTL:3小时(因为近期准备把文件迁移到不同服务器)

httpd-default.conf 关键配置

Timeout 300

KeepAlive On

MaxKeepAliveRequests 1000

KeepAliveTimeout 40

# reqtimeout module is disabled
#<IfModule reqtimeout_module>
#  RequestReadTimeout header=20-40,MinRate=500 body=20,MinRate=500
#</IfModule>

httpd-ssl.conf 关键配置

SSLSessionCacheTimeout  300

SSLUseStapling Off

HostnameLookups Off

EnableSendfile Off

EnableMMAP Off

<VirtualHost *:443>

Protocols h2 h2c http/1.1

...

SSLEngine on

...

SSLHonorCipherOrder on

SSLProtocol ALL -SSLv2 -SSLv3 -TLSv1 -TLSv1.1

SSLCipherSuite ECDH+AESGCM:ECDH+CHACHA20:DH+AESGCM:ECDH+AES256:DH+AES256:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS

</VirtualHost>

已尝试的排查步骤

  • 将<VirtualHost *:443>改为<VirtualHost 0.0.0.0:443>(我只用IPv4),无改善
  • 关闭防火墙,排除防火墙影响,问题依旧
  • 执行openssl s_client -connect www.filmfix.com:443 -status -servername www.filmfix.com,输出如下:
CONNECTED(000001B8)
depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=1 C = US, O = Let's Encrypt, CN = R3
verify return:1
depth=0 CN = *.my_domainname_dot_com
verify return:1
OCSP response: no response sent
---
Certificate chain
0 s:CN = *.my_domainname_dot_com
i:C = US, O = Let's Encrypt, CN = R3
1 s:C = US, O = Let's Encrypt, CN = R3
i:C = US, O = Internet Security Research Group, CN = ISRG Root X1
2 s:C = US, O = Internet Security Research Group, CN = ISRG Root X1
i:O = Digital Signature Trust Co., CN = DST Root CA X3
---
Server certificate
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
subject=CN = *.my_domainname_dot_com
issuer=C = US, O = Let's Encrypt, CN = R3
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: RSA-PSS
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 5026 bytes and written 406 bytes
Verification error: unable to get local issuer certificate
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Server public key is 4096 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 20 (unable to get local issuer certificate)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol  : TLSv1.3
Cipher    : TLS_AES_256_GCM_SHA384
Session-ID: 3D6884662...
Session-ID-ctx:
Resumption PSK: 5EA6E2B7D...
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 300 (seconds)
TLS session ticket:
0000 ... 3i.
Start Time: 1691621025
Timeout   : 7200 (sec)
Verify return code: 20 (unable to get local issuer certificate)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol  : TLSv1.3
Cipher    : TLS_AES_256_GCM_SHA384
Session-ID: 9BFE3...
Session-ID-ctx:
Resumption PSK: 38FFBF004D...
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 300 (seconds)
TLS session ticket:
0000 - a9 01 cb ...   a2 40   ....)..d...!.4.@
Start Time: 1691621025
Timeout   : 7200 (sec)
Verify return code: 20 (unable to get local issuer certificate)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
  • 执行httpd -D DUMP_RUN_CFG,输出如下:
C:\64bit\Apache24\bin>httpd -D DUMP_RUN_CFG

ServerRoot: "C:/64bit/Apache24"
Main DocumentRoot: "C:/64bit/htdocs"
Main ErrorLog: "E:/log-files/apache/error_.log"
Mutex rewrite-map: using_defaults
Mutex ssl-stapling-refresh: using_defaults
Mutex ssl-stapling: using_defaults
Mutex proxy: using_defaults
Mutex ssl-cache: using_defaults
Mutex default: dir="C:/64bit/Apache24/logs/" mechanism=default
PidFile: "C:/64bit/Apache24/logs/httpd.pid"
Define: DUMP_RUN_CFG

求助需求

希望各位能帮忙分析可能的原因,以及给出对应的解决思路或方案,非常感谢!

备注:内容来源于stack exchange,提问作者MeSo2

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 16:24:29