You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache反向代理Mattermost(WebSocket)连接故障排查求助

Mattermost Apache反向代理配置故障排查

环境信息

  • Server A:运行Apache2的Web服务器、反向代理及互联网网关
  • Server B:Mattermost服务器(内网IP:192.168.100.15)

错误现象

  • 外部通过代理访问时,页面提示:请检查您的连接,Mattermost不可用。若问题持续,请联系管理员启用WebSocket端口。
  • 局域网内修改Windows hosts文件(添加192.168.100.15 teamchat.domain.xyz)后可正常访问Mattermost

Apache2错误日志

[Thu Jul 25 14:03:53.339846 2024] [proxy:error] [pid 96487] [client 79.187.92.58:56685] AH00898: Error during SSL Handshake with remote server returned by /api/v4/websocket
[Thu Jul 25 14:03:54.282932 2024] [proxy:error] [pid 94790] (20014)Internal error (specific information not available): [client 79.187.92.58:57806] AH01084: pass request body failed to 192.168.100.15:443 (192.168.100.15)
[Thu Jul 25 14:03:54.282986 2024] [proxy:error] [pid 94790] [client 79.187.92.58:57806] AH00898: Error during SSL Handshake with remote server returned by /api/v4/websocket
[Thu Jul 25 14:03:55.219146 2024] [proxy:error] [pid 94787] (20014)Internal error (specific information not available): [client 79.187.92.58:55088] AH01084: pass request body failed to 192.168.100.15:443 (192.168.100.15)
[Thu Jul 25 14:03:55.219175 2024] [proxy:error] [pid 94787] [client 79.187.92.58:55088] AH00898: Error during SSL Handshake with remote server returned by /api/v4/websocket

当前虚拟主机配置

<VirtualHost *:80>
    ServerName teamchat.domain.xyz
    Redirect permanent / https://teamchat.domain.xyz
</VirtualHost>


<VirtualHost *:443>
    ServerName teamchat.domain.xyz

    SSLEngine on
    SSLProxyEngine On
    SSLCertificateFile /var/www/html/domain/ssl/domain.xyz.crt
    SSLCertificateKeyFile /var/www/html/domain/ssl/domain.xyz.key
    # SSLCertificateChainFile /var/www/html/domain/ssl/domain.xyz.bundle

    ErrorLog /var/log/apache2/mattermost-error.log
    CustomLog /var/log/apache2/mattermost-access.log combined

    ProxyPreserveHost On
    ProxyRequests Off

    RewriteEngine On
    RewriteCond %{REQUEST_URI} ^/api/v[0-9]+/(users/)?websocket [NC,OR]
    RewriteCond %{HTTP:UPGRADE} ^WebSocket$ [NC,OR]
    RewriteCond %{HTTP:CONNECTION} ^Upgrade$ [NC]
    RewriteRule .* wss://192.168.100.15:443%{REQUEST_URI} [P,QSA,L]

    <LocationMatch "^/api/v(?<apiversion>[0-9]+)/(?<apiusers>users/)?websocket$">
        Require all granted
        ProxyPass wss://192.168.100.15:443/api/v%{env:MATCH_APIVERSION}/%{env:MATCH_APIUSERS}websocket
        ProxyPassReverse wss://192.168.100.15:443/api/v%{env:MATCH_APIVERSION}/%{env:MATCH_APIUSERS}websocket
        ProxyPassReverseCookieDomain 192.168.100.15 teamchat.domain.xyz
    </LocationMatch>

    <Location />
        Require all granted
        ProxyPass https://192.168.100.15/
        ProxyPassReverse https://192.168.100.15/
        ProxyPassReverseCookieDomain 192.168.100.15 teamchat.domain.xyz
    </Location>
</VirtualHost>

版本信息

  • Apache版本:Apache/2.4.38 (Debian)
  • Mattermost版本:7.4.0

排查与修复方案

1. 核心问题定位

日志中的AH00898: Error during SSL Handshake with remote server表明Apache在与Mattermost服务器(192.168.100.15:443)建立SSL连接时失败。结合局域网直接访问正常的情况,核心原因是:

  • 局域网通过hosts映射用域名访问时,Mattermost的证书是针对teamchat.domain.xyz签发的,证书验证通过;
  • Apache代理时直接用IP访问Mattermost的443端口,证书中的域名与IP不匹配,触发SSL握手失败。

2. 修复步骤

方案一:修改Apache代理配置,使用域名而非IP访问Mattermost

在Server A的/etc/hosts中添加内网域名映射:

192.168.100.15 teamchat.domain.xyz

然后修改虚拟主机配置中的代理目标,将所有192.168.100.15替换为teamchat.domain.xyz:

# 替换RewriteRule中的目标
RewriteRule .* wss://teamchat.domain.xyz:443%{REQUEST_URI} [P,QSA,L]

# 替换LocationMatch中的ProxyPass目标
ProxyPass wss://teamchat.domain.xyz:443/api/v%{env:MATCH_APIVERSION}/%{env:MATCH_APIUSERS}websocket
ProxyPassReverse wss://teamchat.domain.xyz:443/api/v%{env:MATCH_APIVERSION}/%{env:MATCH_APIUSERS}websocket

# 替换Location /中的ProxyPass目标
ProxyPass https://teamchat.domain.xyz/
ProxyPassReverse https://teamchat.domain.xyz/

方案二:禁用Apache对后端SSL证书的验证(仅临时测试用)

如果暂时无法修改hosts或证书,可添加以下指令跳过后端证书验证(生产环境不推荐,会降低安全性):

# 在<VirtualHost *:443>块内添加
SSLProxyVerify none
SSLProxyCheckPeerCN off
SSLProxyCheckPeerName off
SSLProxyCheckPeerExpire off

方案三:修改Mattermost配置,使用HTTP接收代理请求

如果内网环境安全,可将Mattermost配置为监听HTTP端口(如8065),避免SSL握手问题:

  1. 修改Mattermost的config.json:
    "ServiceSettings": {
      "ListenAddress": ":8065",
      "ConnectionSecurity": "None"
    }
    
  2. 重启Mattermost服务;
  3. 修改Apache虚拟主机配置,将代理目标改为http://192.168.100.15:8065,同时将WebSocket规则中的wss://改为ws://。

3. 额外优化建议

  • 启用Apache的mod_proxy_wstunnel模块(WebSocket代理依赖):
    a2enmod proxy_wstunnel
    systemctl restart apache2
    
  • 确保Mattermost的config.json中SiteURL设置为https://teamchat.domain.xyz,与外部访问域名一致。

内容的提问来源于stack exchange,提问作者Karol

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 11:14:53