本地curl请求server-status返回301,需适配New Relic监控要求
解决New Relic监控httpd时/server-status返回301的问题
问题根源分析
当前curl -I http://localhost/server-status返回301,核心原因有两点:
- 80端口VirtualHost的全局HTTPS重定向:所有HTTP请求都会被强制跳转到HTTPS,包括localhost的/server-status请求
- /server-status的访问控制限制:现有配置仅允许
domain.tld来源访问,localhost不在允许范围内 - 额外潜在影响:OWASP模块(如mod_security)的安全规则可能拦截localhost的请求
解决方案
1. 修改80端口VirtualHost配置,放行localhost的/server-status请求
在<VirtualHost *:80>块中,优先处理localhost的server-status请求,避免被全局重定向拦截:
<VirtualHost *:80> ServerName domain.tld # 优先处理localhost的server-status请求,跳过HTTPS重定向 <Location /server-status> SetHandler server-status Order allow,deny Deny from all Allow from localhost 127.0.0.1 ::1 </Location> # 全局HTTPS重定向(排除/server-status路径) RewriteEngine on RewriteCond %{SERVER_NAME} =domain.tld RewriteCond %{REQUEST_URI} !^/server-status$ RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent] # 保留原有domain.tld的访问权限,同时添加localhost <Location /server-status> SetHandler server-status Order allow,deny Deny from all Allow from domain.tld localhost 127.0.0.1 ::1 </Location> </VirtualHost>
2. 在443端口VirtualHost中添加server-status配置(可选但推荐)
确保HTTPS下的localhost请求也能访问server-status,避免后续测试或监控出现问题:
<VirtualHost *:443> ServerName domain.tld # 保留原有所有配置... # 添加localhost访问server-status的权限 <Location /server-status> SetHandler server-status # 兼容新旧Apache权限语法 Order allow,deny Allow from localhost 127.0.0.1 ::1 Require ip localhost 127.0.0.1 ::1 </Location> # 保留原有所有配置... </VirtualHost>
3. 排查OWASP模块的拦截规则
如果修改上述配置后仍返回非200状态,检查OWASP mod_security的规则是否拦截了请求:
- 临时关闭该路径的mod_security规则测试:
<Location /server-status> SecRuleEngine Off </Location>
- 若测试有效,可进一步细化规则,仅允许localhost来源的请求绕过安全检查。
验证步骤
- 重启Apache服务:
sudo systemctl restart apache2 # 或CentOS/RHEL系统:sudo systemctl restart httpd
- 再次执行测试命令:
curl -I http://localhost/server-status 2>/dev/null | head -n 1
正常情况下应返回HTTP/1.1 200 OK。
内容的提问来源于stack exchange,提问作者DarkDead
相关产品推荐
相关产品推荐

