Apache配置SSL/HTTPS仅Chrome可用问题求助
问题:Apache反向代理NextJS仅Chrome可访问,其他浏览器超时
我在AWS EC2 Ubuntu实例上运行端口3000的NextJS服务,通过Apache将443端口流量反向代理至该应用。目前仅Chrome浏览器能正常访问,其他浏览器均无响应直至超时。
现有Apache配置
<VirtualHost *:443> ServerName domain.com ProxyPreserveHost On ProxyPass / http://localhost:3000/ ProxyPassReverse / http://localhost:3000/ SSLEngine on SSLCertificateFile /etc/ssl/certs/www_domain_com.crt SSLCertificateKeyFile /etc/ssl/private/domain_private.key SSLCertificateChainFile /etc/ssl/certs/www_domain_com.ca-bundle </VirtualHost>
Apache最新日志
[Thu Jan 25 20:11:21.975521 2024] [mpm_event:notice] [pid 2267:tid 140152490424192] AH00492: caught SIGWINCH, shutting down gracefully [Thu Jan 25 20:11:22.062393 2024] [mpm_event:notice] [pid 2367:tid 139778842716032] AH00489: Apache/2.4.52 (Ubuntu) OpenSSL/3.0.2 configured -- resuming normal operations [Thu Jan 25 20:11:22.062521 2024] [core:notice] [pid 2367:tid 139778842716032] AH00094: Command line: '/usr/sbin/apache2'
解决步骤
1. 确保代理模块完整加载
NextJS依赖WebSocket进行热更新和部分交互,其他浏览器对WebSocket的处理逻辑与Chrome不同,需确保Apache启用相关代理模块:
sudo a2enmod proxy proxy_http proxy_wstunnel sudo systemctl restart apache2
2. 添加WebSocket代理规则
在VirtualHost配置中补充WebSocket反向代理规则,避免因WS连接失败导致页面加载超时:
<VirtualHost *:443> ServerName domain.com ProxyPreserveHost On # 普通HTTP请求代理 ProxyPass / http://localhost:3000/ ProxyPassReverse / http://localhost:3000/ # NextJS WebSocket热更新代理 ProxyPass /_next/webpack-hmr ws://localhost:3000/_next/webpack-hmr ProxyPassReverse /_next/webpack-hmr ws://localhost:3000/_next/webpack-hmr SSLEngine on SSLCertificateFile /etc/ssl/certs/www_domain_com.crt SSLCertificateKeyFile /etc/ssl/private/domain_private.key SSLCertificateChainFile /etc/ssl/certs/www_domain_com.ca-bundle </VirtualHost>
修改后重启Apache生效:sudo systemctl restart apache2
3. 优化SSL兼容性
部分旧浏览器可能不兼容Apache默认SSL配置,补充以下参数提升兼容性:
SSLEngine on # 禁用不安全的旧协议 SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 # 使用兼容主流浏览器的加密套件 SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384 SSLHonorCipherOrder off SSLCompression off # 启用OCSP stapling提升加载速度 SSLUseStapling on SSLStaplingCache "shmcb:logs/ssl_stapling(128000)"
4. 确认NextJS绑定地址
确保NextJS服务绑定到所有网卡(0.0.0.0),避免仅绑定localhost导致的隐性连接问题:
next start -H 0.0.0.0 -p 3000
5. 排查详细日志
若以上步骤未解决问题,开启Apache代理调试日志定位具体错误:
在VirtualHost中添加:
LogLevel info proxy:debug
重启Apache后查看错误日志:tail -f /var/log/apache2/error.log
内容的提问来源于stack exchange,提问作者nikita_trifan
相关产品推荐
相关产品推荐

