Ubuntu系统Apache2服务器SSL证书配置报错求助:Invalid command 'SSLEngine'
Hey there, let's get this SSL deployment issue sorted out for your Django project! The error you're seeing is a common one, and it's easy to fix once you know the root cause.
What's Causing the Error?
The error message you got says:
AH00526: Syntax error on line 58 of /etc/apache2/sites-enabled/eblossom.conf: Invalid command 'SSLEngine', perhaps misspelled or defined by a module not included in the server configuration
This means Apache doesn't recognize the SSLEngine directive because the mod_ssl module isn't enabled on your server. This module is required to handle HTTPS connections and process all SSL certificate-related settings.
Step-by-Step Fixes
1. Enable the mod_ssl Module
Run this command to turn on the SSL module in Apache:
sudo a2enmod ssl
You should see a confirmation message that the module has been enabled successfully.
2. Restart Apache to Load the Module
For the module change to take effect, restart your Apache service:
sudo systemctl restart apache2 # If systemctl isn't available on your Ubuntu version, use this instead: # sudo service apache2 restart
3. Test Your Configuration Again
Run the config test command to verify the error is gone:
sudo apache2ctl configtest
If you see Syntax OK in the output, you've fixed the core issue!
Additional Tweaks for Your Django Project
Looking at your eblossom.conf file, there are a couple of adjustments needed to make your HTTPS setup work properly with Django:
a. Copy Django Configuration to the HTTPS VirtualHost
Right now, your <VirtualHost *:443> block only has SSL settings—no Django/WSGI or static/media file configurations. That means when users access your site over HTTPS, Apache won't know where to find your Django app. Copy the relevant sections from your port 80 block into the port 443 block:
<VirtualHost *:443> SSLEngine on SSLCertificateFile /home/najaaz/eblossom/eblossom_lk.crt SSLCertificateKeyFile /home/najaaz/eblossom/eblossom.lk.key SSLCertificateChainFile /home/najaaz/eblossom/eblossom_lk.ca-bundle # Add these lines from your port 80 config ServerAdmin webmaster@localhost DocumentRoot /var/www/html Alias /static /home/najaaz/eblossom/static <Directory /home/najaaz/eblossom/static> Require all granted </Directory> Alias /media /home/najaaz/eblossom/media <Directory /home/najaaz/eblossom/media> Require all granted </Directory> <Directory /home/najaaz/eblossom/eblossom> <Files wsgi.py> Require all granted </Files> </Directory> WSGIScriptAlias / /home/najaaz/eblossom/eblossom/wsgi.py WSGIDaemonProcess eblossom python-path=/home/najaaz/eblossom python-home=/home/najaaz/eblossom/venv WSGIProcessGroup eblossom </VirtualHost>
b. Ensure Apache Can Read Your SSL Certificates
Apache needs permission to access your certificate files. Set the correct ownership and permissions with these commands:
sudo chown www-data:www-data /home/najaaz/eblossom/eblossom_lk.crt /home/najaaz/eblossom/eblossom.lk.key /home/najaaz/eblossom/eblossom_lk.ca-bundle sudo chmod 644 /home/najaaz/eblossom/eblossom_lk.crt /home/najaaz/eblossom/eblossom.lk.key /home/najaaz/eblossom/eblossom_lk.ca-bundle
c. Redirect HTTP to HTTPS (Optional but Recommended)
To force all users to use the secure HTTPS version of your site, add a redirect to your port 80 VirtualHost:
<VirtualHost *:80> # Keep your existing config here, then add this line: Redirect permanent / https://eblossom.lk/ </VirtualHost>
Replace eblossom.lk with your actual domain name.
After making these changes, restart Apache again and run apache2ctl configtest to confirm everything is working as expected.
内容的提问来源于stack exchange,提问作者Najaaz

