如何修复Apache+Let's Encrypt环境下的AH02217证书颁发者获取失败错误?
问题:Apache mod_md模块配置Let's Encrypt自动续期时服务器崩溃
背景
此前在Windows Server 2019上通过教程手动安装并更新Let's Encrypt证书,为实现自动续期,切换使用Apache mod_md模块。
操作步骤
- 为Apache生成自签名SSL证书,在Windows终端执行以下命令并填写对应证书信息:
openssl genrsa -out www.wopr.gov.key 4096 openssl req -new -out www.wopr.gov.csr -sha256 -key www.wopr.gov.key openssl x509 -req -in www.wopr.gov.csr -days 365 -signkey www.wopr.gov.key -out www.wopr.gov.crt -outform PEM
- 配置mod_md实现Let's Encrypt验证,使用以下配置文件,同时在httpd.conf中启用了headers_module、md_module等相关模块:
## Secure Apache with mod_md Let's Encrypt directives ## ServerAdmin beringer@norad.gov MDCertificateAgreement accepted MDomain www.wopr.gov MDPrivateKeys RSA 4096 SSLStaplingCache "shmcb:logs/ssl_stapling(32768)" <VirtualHost *:443> SSLEngine on ## Only enable TLS v1.3 and avoid older protocols ## SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 -TLSv1.2 SSLHonorCipherOrder off SSLSessionTickets off ## Turn on OCSP Stapling ## SSLUseStapling on ServerAdmin beringer@norad.gov DocumentRoot "path/to/document/root/public" ServerName www.wopr.gov ErrorLog "path/to/document/root/logs/error.log" TransferLog "path/to/document/root/logs/access.log" CustomLog "path/to/document/root/logs/ssl_request.log" "combined" # Turn on HTTP/2 Protocols h2 http/1.1 # Set HTTP Strict Transport Security Header always set Strict-Transport-Security "max-age=63072000" SSLCertificateFile "path/to/document/root/certificates/www.wopr.gov.crt" SSLCertificateKeyFile "path/to/document/root/certificates/www.wopr.gov.key" </VirtualHost>
问题现象及排查尝试
启动服务器获取SSL证书时发生崩溃,错误日志显示AH02217: ssl_stapling_init_cert: can't retrieve issuer certificate及AH02604错误。
- 移除配置中的
SSLCertificateFile和SSLCertificateKeyFile字段后,出现AH10085警告,AH02217错误仍存在; - 将
SSLUseStapling设为off后,AH02217错误消失,但服务器依旧崩溃。
内容的提问来源于stack exchange,提问作者Paiku Han
相关产品推荐
相关产品推荐

