网站访问出现ERR_SSL_PROTOCOL_ERROR问题求助
问题现象
访问https://pmadmin.qno.de时,浏览器返回错误:
Diese Website kann keine sichere Verbindung bereitstellen
pmadmin.qno.de hat eine ungültige Antwort gesendet.
Versuche, die Windows-Netzwerkdiagnose auszuführen.
ERR_SSL_PROTOCOL_ERROR
服务器环境
- 系统:Ubuntu 22.04.4 LTS
- Apache版本:2.4.52-1ubuntu4.8
- OpenSSL版本:3.0.2-0ubuntu1.15
相关命令输出:
root@bywater ~ # cat /etc/lsb-release DISTRIB_ID=Ubuntu DISTRIB_RELEASE=22.04 DISTRIB_CODENAME=jammy DISTRIB_DESCRIPTION="Ubuntu 22.04.4 LTS" root@bywater ~ # dpkg -l apache2 Desired=Unknown/Install/Remove/Purge/Hold | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description +++-==============-=================-============-================================= ii apache2 2.4.52-1ubuntu4.8 amd64 Apache HTTP Server root@bywater ~ # dpkg -l openssl Desired=Unknown/Install/Remove/Purge/Hold | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description +++-==============-=================-============-==================================================== ii openssl 3.0.2-0ubuntu1.15 amd64 Secure Sockets Layer toolkit - cryptographic utility
日志信息
access.log
2003:e9:4f12:6d00:4539:bdd0:36ce:1851 - - [18/Mar/2024:20:21:02 +0100] "\x16\x03\x01\x02\x11\x01" 400 488 "-" "-" 2003:e9:4f12:6d00:4539:bdd0:36ce:1851 - - [18/Mar/2024:20:21:02 +0100] "\x16\x03\x01\x02\x11\x01" 400 488 "-" "-"
ssl_engine.log
[Mon Mar 18 20:21:02.357687 2024] [core:debug] [pid 595065] protocol.c(1449): [client 2003:e9:4f12:6d00:4539:bdd0:36ce:1851:49640] AH00566: request failed: malformed request line [Mon Mar 18 20:21:02.434954 2024] [core:debug] [pid 595066] protocol.c(1449): [client 2003:e9:4f12:6d00:4539:bdd0:36ce:1851:49642] AH00566: request failed: malformed request line
error.log无相关条目。
Apache SSL虚拟主机配置
文件路径:/etc/apache2/sites-enabled/a02-phpmyadmin-le-ssl.conf
<IfModule mod_ssl.c> <VirtualHost 65.21.136.15:443 [2a01:04f9:003b:25b0:0009:0006:0001:0a02]:443> HttpProtocolOptions Unsafe ServerAdmin webmaster@qno.de DocumentRoot /srv/phpmyadmin_html ServerName pmadmin.qno.de ErrorLog /var/log/apache2/a02_phpmyadmin/error.log CustomLog /var/log/apache2/a02_phpmyadmin/access.log combined AddDefaultCharset UTF-8 AddOutputFilterByType DEFLATE text/html text/plain text/xml DirectoryIndex index.php index.html SSLProtocol TLSv1.3 TLSv1.2 SSLHonorCipherOrder On SSLCompression off SSLCipherSuite 'RC4-SHA:AES128-SHA:HIGH:MEDIUM:!aNULL:!MD5:!SHA1' ErrorLog /var/log/apache2/a02_phpmyadmin/ssl_engine.log LogLevel debug SSLCertificateFile /etc/letsencrypt/live/pmadmin.qno.de/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/pmadmin.qno.de/privkey.pem <Directory /srv/phpmyadmin_html> AllowOverride All Require all granted </Directory> </VirtualHost> </IfModule>
系统检测结果
Apache配置校验
root@bywater ~ # apache2ctl -t Syntax OK
虚拟主机信息
root@bywater ~ # apache2ctl -S VirtualHost configuration: [2a01:4f9:3b:25b0:9:6:1:a02]:443 pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin-le-ssl.conf:2) [2a01:4f9:3b:25b0:9:6:1:a02]:80 pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin.conf:1) [2a01:4f9:3b:25b0:9:6:1:b01]:80 www.sk-koenig-tegel.de (/etc/apache2/sites-enabled/b01-tegel.conf:2) [2a01:4f9:3b:25b0:9:6:1:b01]:443 www.sk-koenig-tegel.de (/etc/apache2/sites-enabled/b01-tegel.conf:28) 65.21.136.15:80 is a NameVirtualHost default server pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin.conf:1) port 80 namevhost pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin.conf:1) port 80 namevhost www.sk-koenig-tegel.de (/etc/apache2/sites-enabled/b01-tegel.conf:2) alias sk-koenig-tegel.de 65.21.136.15:443 is a NameVirtualHost default server pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin-le-ssl.conf:2) port 443 namevhost pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin-le-ssl.conf:2) port 443 namevhost www.sk-koenig-tegel.de (/etc/apache2/sites-enabled/b01-tegel.conf:28) alias sk-koenig-tegel.de ServerRoot: "/etc/apache2" Main DocumentRoot: "/var/www/html" Main ErrorLog: "/var/log/apache2/error.log" Mutex ssl-cache: using_defaults Mutex default: dir="/var/run/apache2/" mechanism=default Mutex mpm-accept: using_defaults Mutex watchdog-callback: using_defaults Mutex rewrite-map: using_defaults Mutex ssl-stapling-refresh: using_defaults Mutex ssl-stapling: using_defaults PidFile: "/var/run/apache2/apache2.pid" Define: DUMP_VHOSTS Define: DUMP_RUN_CFG User: name="www-data" id=33 Group: name="www-data" id=33
端口监听
root@bywater ~ # netstat -tlpn|grep 443 tcp6 0 0 :::443 :::* LISTEN 268958/apache2
OpenSSL连接测试
root@bywater ~ # openssl s_client -tls1_3 -connect pmadmin.qno.de:443 -6 CONNECTED(00000003) 4087D64E7E7F0000:error:0A00010B:SSL routines:ssl3_get_record:wrong version number:../ssl/record/ssl3_record.c:354: --- no peer certificate available --- No client certificate CA names sent --- SSL handshake has read 5 bytes and written 248 bytes Verification: OK --- New, (NONE), Cipher is (NONE) Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 0 (ok)
外部Nmap扫描
root@raspberry ~ # nmap -6 -sT -sV -p 443 pmadmin.qno.de Starting Nmap 7.70 ( https://nmap.org ) at 2024-03-18 20:35 CET Nmap scan report for pmadmin.qno.de (2a01:4f9:3b:25b0:9:6:1:a02) Host is up (0.041s latency). Other addresses for pmadmin.qno.de (not scanned): 65.21.136.15 PORT STATE SERVICE VERSION 443/tcp open ssl/https Apache/2.4.52 (Ubuntu) Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 18.28 seconds root@raspberry ~ # nmap -4 -sT -sV -p 443 pmadmin.qno.de Starting Nmap 7.70 ( https://nmap.org ) at 2024-03-18 20:36 CET Nmap scan report for pmadmin.qno.de (65.21.136.15) Host is up (0.038s latency). Other addresses for pmadmin.qno.de (not scanned): 2a01:4f9:3b:25b0:9:6:1:a02 rDNS record for 65.21.136.15: bywater.qno.de PORT STATE SERVICE VERSION 443/tcp open ssl/https Apache/2.4.52 (Ubuntu) Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 18.17 seconds
解决方案
从日志和测试结果分析,问题核心是Apache的SSL虚拟主机未正确处理TLS握手请求,反而将其当作普通HTTP请求解析,导致"malformed request line"错误。以下是针对性修复步骤:
确认mod_ssl模块加载状态
执行命令确保SSL模块已启用并重启Apache:a2enmod ssl apache2ctl restart即使配置文件包含
<IfModule mod_ssl.c>,仍需确保模块实际加载,否则虚拟主机不会启用SSL功能。修复CipherSuite配置
当前配置的SSLCipherSuite包含不安全算法RC4,且与TLSv1.3不兼容。替换为兼容TLSv1.2和TLSv1.3的标准配置:SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384 SSLProtocol TLSv1.3 TLSv1.2 SSLHonorCipherOrder OffTLSv1.3不支持
SSLHonorCipherOrder,需设置为Off。移除HttpProtocolOptions Unsafe
该选项会放宽HTTP协议限制,可能干扰TLS握手流程,建议删除此配置行。检查证书文件权限
确保Apache用户(www-data)能读取证书文件:chown -R root:www-data /etc/letsencrypt/live/pmadmin.qno.de/ chmod -R 750 /etc/letsencrypt/live/pmadmin.qno.de/重启Apache并重新测试
apache2ctl restart openssl s_client -connect pmadmin.qno.de:443若握手成功,浏览器访问即可恢复正常。
内容的提问来源于stack exchange,提问作者Christian H. Kuhn

