You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

网站访问出现ERR_SSL_PROTOCOL_ERROR问题求助

Apache SSL协议错误(ERR_SSL_PROTOCOL_ERROR)排查与解决

问题现象

访问https://pmadmin.qno.de时,浏览器返回错误:

Diese Website kann keine sichere Verbindung bereitstellen
pmadmin.qno.de hat eine ungültige Antwort gesendet.
Versuche, die Windows-Netzwerkdiagnose auszuführen.
ERR_SSL_PROTOCOL_ERROR

服务器环境

  • 系统:Ubuntu 22.04.4 LTS
  • Apache版本:2.4.52-1ubuntu4.8
  • OpenSSL版本:3.0.2-0ubuntu1.15

相关命令输出:

root@bywater ~ # cat /etc/lsb-release
DISTRIB_ID=Ubuntu
DISTRIB_RELEASE=22.04
DISTRIB_CODENAME=jammy
DISTRIB_DESCRIPTION="Ubuntu 22.04.4 LTS"
root@bywater ~ # dpkg -l apache2
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name           Version           Architecture Description
+++-==============-=================-============-=================================
ii  apache2        2.4.52-1ubuntu4.8 amd64        Apache HTTP Server
root@bywater ~ # dpkg -l openssl
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name           Version           Architecture Description
+++-==============-=================-============-====================================================
ii  openssl        3.0.2-0ubuntu1.15 amd64        Secure Sockets Layer toolkit - cryptographic utility

日志信息

access.log

2003:e9:4f12:6d00:4539:bdd0:36ce:1851 - - [18/Mar/2024:20:21:02 +0100] "\x16\x03\x01\x02\x11\x01" 400 488 "-" "-"
2003:e9:4f12:6d00:4539:bdd0:36ce:1851 - - [18/Mar/2024:20:21:02 +0100] "\x16\x03\x01\x02\x11\x01" 400 488 "-" "-"

ssl_engine.log

[Mon Mar 18 20:21:02.357687 2024] [core:debug] [pid 595065] protocol.c(1449): [client 2003:e9:4f12:6d00:4539:bdd0:36ce:1851:49640] AH00566: request failed: malformed request line
[Mon Mar 18 20:21:02.434954 2024] [core:debug] [pid 595066] protocol.c(1449): [client 2003:e9:4f12:6d00:4539:bdd0:36ce:1851:49642] AH00566: request failed: malformed request line

error.log无相关条目。

Apache SSL虚拟主机配置

文件路径:/etc/apache2/sites-enabled/a02-phpmyadmin-le-ssl.conf

<IfModule mod_ssl.c>
<VirtualHost 65.21.136.15:443 [2a01:04f9:003b:25b0:0009:0006:0001:0a02]:443>
    HttpProtocolOptions Unsafe

    ServerAdmin webmaster@qno.de
    DocumentRoot  /srv/phpmyadmin_html
    ServerName pmadmin.qno.de

    ErrorLog /var/log/apache2/a02_phpmyadmin/error.log
    CustomLog /var/log/apache2/a02_phpmyadmin/access.log combined

    AddDefaultCharset UTF-8
    AddOutputFilterByType DEFLATE text/html text/plain text/xml
    DirectoryIndex index.php index.html

    SSLProtocol TLSv1.3 TLSv1.2
    SSLHonorCipherOrder On
    SSLCompression off

    SSLCipherSuite 'RC4-SHA:AES128-SHA:HIGH:MEDIUM:!aNULL:!MD5:!SHA1'

    ErrorLog /var/log/apache2/a02_phpmyadmin/ssl_engine.log
    LogLevel debug
    
    SSLCertificateFile /etc/letsencrypt/live/pmadmin.qno.de/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/pmadmin.qno.de/privkey.pem
    
    <Directory /srv/phpmyadmin_html>
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>
</IfModule>

系统检测结果

Apache配置校验

root@bywater ~ # apache2ctl -t
Syntax OK

虚拟主机信息

root@bywater ~ # apache2ctl -S
VirtualHost configuration:
[2a01:4f9:3b:25b0:9:6:1:a02]:443 pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin-le-ssl.conf:2)
[2a01:4f9:3b:25b0:9:6:1:a02]:80 pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin.conf:1)
[2a01:4f9:3b:25b0:9:6:1:b01]:80 www.sk-koenig-tegel.de (/etc/apache2/sites-enabled/b01-tegel.conf:2)
[2a01:4f9:3b:25b0:9:6:1:b01]:443 www.sk-koenig-tegel.de (/etc/apache2/sites-enabled/b01-tegel.conf:28)
65.21.136.15:80        is a NameVirtualHost
         default server pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin.conf:1)
         port 80 namevhost pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin.conf:1)
         port 80 namevhost www.sk-koenig-tegel.de (/etc/apache2/sites-enabled/b01-tegel.conf:2)
                 alias sk-koenig-tegel.de
65.21.136.15:443       is a NameVirtualHost
         default server pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin-le-ssl.conf:2)
         port 443 namevhost pmadmin.qno.de (/etc/apache2/sites-enabled/a02-phpmyadmin-le-ssl.conf:2)
         port 443 namevhost www.sk-koenig-tegel.de (/etc/apache2/sites-enabled/b01-tegel.conf:28)
                 alias sk-koenig-tegel.de
ServerRoot: "/etc/apache2"
Main DocumentRoot: "/var/www/html"
Main ErrorLog: "/var/log/apache2/error.log"
Mutex ssl-cache: using_defaults
Mutex default: dir="/var/run/apache2/" mechanism=default
Mutex mpm-accept: using_defaults
Mutex watchdog-callback: using_defaults
Mutex rewrite-map: using_defaults
Mutex ssl-stapling-refresh: using_defaults
Mutex ssl-stapling: using_defaults
PidFile: "/var/run/apache2/apache2.pid"
Define: DUMP_VHOSTS
Define: DUMP_RUN_CFG
User: name="www-data" id=33
Group: name="www-data" id=33

端口监听

root@bywater ~ # netstat -tlpn|grep 443
tcp6       0      0 :::443                  :::*                    LISTEN      268958/apache2

OpenSSL连接测试

root@bywater ~ # openssl s_client -tls1_3 -connect pmadmin.qno.de:443 -6
CONNECTED(00000003)
4087D64E7E7F0000:error:0A00010B:SSL routines:ssl3_get_record:wrong version number:../ssl/record/ssl3_record.c:354:
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 5 bytes and written 248 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)

外部Nmap扫描

root@raspberry ~ # nmap -6 -sT -sV -p 443 pmadmin.qno.de
Starting Nmap 7.70 ( https://nmap.org ) at 2024-03-18 20:35 CET
Nmap scan report for pmadmin.qno.de (2a01:4f9:3b:25b0:9:6:1:a02)
Host is up (0.041s latency).
Other addresses for pmadmin.qno.de (not scanned): 65.21.136.15

PORT    STATE SERVICE   VERSION
443/tcp open  ssl/https Apache/2.4.52 (Ubuntu)

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 18.28 seconds
root@raspberry ~ # nmap -4 -sT -sV -p 443 pmadmin.qno.de
Starting Nmap 7.70 ( https://nmap.org ) at 2024-03-18 20:36 CET
Nmap scan report for pmadmin.qno.de (65.21.136.15)
Host is up (0.038s latency).
Other addresses for pmadmin.qno.de (not scanned): 2a01:4f9:3b:25b0:9:6:1:a02
rDNS record for 65.21.136.15: bywater.qno.de

PORT    STATE SERVICE   VERSION
443/tcp open  ssl/https Apache/2.4.52 (Ubuntu)

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 18.17 seconds

解决方案

从日志和测试结果分析,问题核心是Apache的SSL虚拟主机未正确处理TLS握手请求,反而将其当作普通HTTP请求解析,导致"malformed request line"错误。以下是针对性修复步骤:

  1. 确认mod_ssl模块加载状态
    执行命令确保SSL模块已启用并重启Apache:

    a2enmod ssl
    apache2ctl restart
    

    即使配置文件包含<IfModule mod_ssl.c>,仍需确保模块实际加载,否则虚拟主机不会启用SSL功能。

  2. 修复CipherSuite配置
    当前配置的SSLCipherSuite包含不安全算法RC4,且与TLSv1.3不兼容。替换为兼容TLSv1.2和TLSv1.3的标准配置:

    SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
    SSLProtocol TLSv1.3 TLSv1.2
    SSLHonorCipherOrder Off
    

    TLSv1.3不支持SSLHonorCipherOrder,需设置为Off。

  3. 移除HttpProtocolOptions Unsafe
    该选项会放宽HTTP协议限制,可能干扰TLS握手流程,建议删除此配置行。

  4. 检查证书文件权限
    确保Apache用户(www-data)能读取证书文件:

    chown -R root:www-data /etc/letsencrypt/live/pmadmin.qno.de/
    chmod -R 750 /etc/letsencrypt/live/pmadmin.qno.de/
    
  5. 重启Apache并重新测试

    apache2ctl restart
    openssl s_client -connect pmadmin.qno.de:443
    

    若握手成功,浏览器访问即可恢复正常。


内容的提问来源于stack exchange,提问作者Christian H. Kuhn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 10:38:09