Apache反向代理Mattermost(WebSocket)连接故障排查求助
Mattermost Apache反向代理配置故障排查
环境信息
- Server A:运行Apache2的Web服务器、反向代理及互联网网关
- Server B:Mattermost服务器(内网IP:192.168.100.15)
错误现象
- 外部通过代理访问时,页面提示:
请检查您的连接,Mattermost不可用。若问题持续,请联系管理员启用WebSocket端口。 - 局域网内修改Windows hosts文件(添加
192.168.100.15 teamchat.domain.xyz)后可正常访问Mattermost
Apache2错误日志
[Thu Jul 25 14:03:53.339846 2024] [proxy:error] [pid 96487] [client 79.187.92.58:56685] AH00898: Error during SSL Handshake with remote server returned by /api/v4/websocket [Thu Jul 25 14:03:54.282932 2024] [proxy:error] [pid 94790] (20014)Internal error (specific information not available): [client 79.187.92.58:57806] AH01084: pass request body failed to 192.168.100.15:443 (192.168.100.15) [Thu Jul 25 14:03:54.282986 2024] [proxy:error] [pid 94790] [client 79.187.92.58:57806] AH00898: Error during SSL Handshake with remote server returned by /api/v4/websocket [Thu Jul 25 14:03:55.219146 2024] [proxy:error] [pid 94787] (20014)Internal error (specific information not available): [client 79.187.92.58:55088] AH01084: pass request body failed to 192.168.100.15:443 (192.168.100.15) [Thu Jul 25 14:03:55.219175 2024] [proxy:error] [pid 94787] [client 79.187.92.58:55088] AH00898: Error during SSL Handshake with remote server returned by /api/v4/websocket
当前虚拟主机配置
<VirtualHost *:80> ServerName teamchat.domain.xyz Redirect permanent / https://teamchat.domain.xyz </VirtualHost> <VirtualHost *:443> ServerName teamchat.domain.xyz SSLEngine on SSLProxyEngine On SSLCertificateFile /var/www/html/domain/ssl/domain.xyz.crt SSLCertificateKeyFile /var/www/html/domain/ssl/domain.xyz.key # SSLCertificateChainFile /var/www/html/domain/ssl/domain.xyz.bundle ErrorLog /var/log/apache2/mattermost-error.log CustomLog /var/log/apache2/mattermost-access.log combined ProxyPreserveHost On ProxyRequests Off RewriteEngine On RewriteCond %{REQUEST_URI} ^/api/v[0-9]+/(users/)?websocket [NC,OR] RewriteCond %{HTTP:UPGRADE} ^WebSocket$ [NC,OR] RewriteCond %{HTTP:CONNECTION} ^Upgrade$ [NC] RewriteRule .* wss://192.168.100.15:443%{REQUEST_URI} [P,QSA,L] <LocationMatch "^/api/v(?<apiversion>[0-9]+)/(?<apiusers>users/)?websocket$"> Require all granted ProxyPass wss://192.168.100.15:443/api/v%{env:MATCH_APIVERSION}/%{env:MATCH_APIUSERS}websocket ProxyPassReverse wss://192.168.100.15:443/api/v%{env:MATCH_APIVERSION}/%{env:MATCH_APIUSERS}websocket ProxyPassReverseCookieDomain 192.168.100.15 teamchat.domain.xyz </LocationMatch> <Location /> Require all granted ProxyPass https://192.168.100.15/ ProxyPassReverse https://192.168.100.15/ ProxyPassReverseCookieDomain 192.168.100.15 teamchat.domain.xyz </Location> </VirtualHost>
版本信息
- Apache版本:Apache/2.4.38 (Debian)
- Mattermost版本:7.4.0
排查与修复方案
1. 核心问题定位
日志中的AH00898: Error during SSL Handshake with remote server表明Apache在与Mattermost服务器(192.168.100.15:443)建立SSL连接时失败。结合局域网直接访问正常的情况,核心原因是:
- 局域网通过hosts映射用域名访问时,Mattermost的证书是针对
teamchat.domain.xyz签发的,证书验证通过; - Apache代理时直接用IP访问Mattermost的443端口,证书中的域名与IP不匹配,触发SSL握手失败。
2. 修复步骤
方案一:修改Apache代理配置,使用域名而非IP访问Mattermost
在Server A的/etc/hosts中添加内网域名映射:
192.168.100.15 teamchat.domain.xyz
然后修改虚拟主机配置中的代理目标,将所有192.168.100.15替换为teamchat.domain.xyz:
# 替换RewriteRule中的目标 RewriteRule .* wss://teamchat.domain.xyz:443%{REQUEST_URI} [P,QSA,L] # 替换LocationMatch中的ProxyPass目标 ProxyPass wss://teamchat.domain.xyz:443/api/v%{env:MATCH_APIVERSION}/%{env:MATCH_APIUSERS}websocket ProxyPassReverse wss://teamchat.domain.xyz:443/api/v%{env:MATCH_APIVERSION}/%{env:MATCH_APIUSERS}websocket # 替换Location /中的ProxyPass目标 ProxyPass https://teamchat.domain.xyz/ ProxyPassReverse https://teamchat.domain.xyz/
方案二:禁用Apache对后端SSL证书的验证(仅临时测试用)
如果暂时无法修改hosts或证书,可添加以下指令跳过后端证书验证(生产环境不推荐,会降低安全性):
# 在<VirtualHost *:443>块内添加 SSLProxyVerify none SSLProxyCheckPeerCN off SSLProxyCheckPeerName off SSLProxyCheckPeerExpire off
方案三:修改Mattermost配置,使用HTTP接收代理请求
如果内网环境安全,可将Mattermost配置为监听HTTP端口(如8065),避免SSL握手问题:
- 修改Mattermost的
config.json:"ServiceSettings": { "ListenAddress": ":8065", "ConnectionSecurity": "None" } - 重启Mattermost服务;
- 修改Apache虚拟主机配置,将代理目标改为
http://192.168.100.15:8065,同时将WebSocket规则中的wss://改为ws://。
3. 额外优化建议
- 启用Apache的
mod_proxy_wstunnel模块(WebSocket代理依赖):a2enmod proxy_wstunnel systemctl restart apache2 - 确保Mattermost的
config.json中SiteURL设置为https://teamchat.domain.xyz,与外部访问域名一致。
内容的提问来源于stack exchange,提问作者Karol
相关产品推荐
相关产品推荐

