Apache反向代理配置问题:LDAP认证成功但显示默认页面
问题分析与解决方案
核心问题1:访问显示Apache默认页面
你的ProxyPass和ProxyPassReverse配置的路径是/arkime/,这意味着只有访问https://test-arkime.domain.com/arkime/时才会触发反向代理到Arkime服务。直接访问根路径/时,Apache会加载默认站点目录(比如/var/www/html)的内容,因此显示默认页面。
核心问题2:Location块中配置ProxyPass报错
在<Location>块内使用ProxyPass时,不能再指定路径前缀——因为<Location>已经定义了匹配的路径。比如你若写<Location /arkime/>,里面的ProxyPass应该直接写目标URLhttp://localhost:8005/,而非/arkime/ http://localhost:8005/,这就是报错“ProxyPass|ProxyPassMatch can not have a path when defined in a location”的原因。
修正后的配置示例
提供两种常见适配方案:
方案1:通过根路径/直接访问Arkime
若希望访问https://test-arkime.domain.com/直接进入Arkime,配置如下:
<VirtualHost *:443> ServerName test-arkime.domain.com SSLEngine on SSLCertificateFile "/opt/arkime/etc/test-arkime.crt" SSLCertificateKeyFile "/opt/arkime/etc/test-arkime.key" # 代理根路径到Arkime服务 ProxyPass / http://localhost:8005/ retry=0 ProxyPassReverse / http://localhost:8005/ ProxyPreserveHost On RequestHeader set ARKIME_USER %{REMOTE_USER}e # 对根路径启用LDAP认证 <Location /> AuthType Basic AuthName "Enter account credentials" Require valid-user AuthBasicProvider ldap AuthLDAPGroupAttribute member AuthLDAPSubGroupClass group AuthLDAPGroupAttributeIsDN On AuthLDAPURL ldap://ldap.domain.com:389/OU=USERS,DC=domain,DC=com?sAMAccountName?sub?(objectClass=*) # 修正拼写错误:domaion.com → domain.com AuthLDAPBindDN ldap@domain.com AuthLDAPBindPassword password123 require ldap-group "CN=Users,OU=IT Users,OU=Security,OU=Groups,OU=CORP,DC=domain,DC=com" </Location> </VirtualHost>
方案2:通过/arkime/路径访问Arkime
若保留/arkime/路径的代理规则,配置如下:
<VirtualHost *:443> ServerName test-arkime.domain.com SSLEngine on SSLCertificateFile "/opt/arkime/etc/test-arkime.crt" SSLCertificateKeyFile "/opt/arkime/etc/test-arkime.key" ProxyPreserveHost On RequestHeader set ARKIME_USER %{REMOTE_USER}e # 对/arkime/路径配置代理和认证 <Location /arkime/> ProxyPass http://localhost:8005/ retry=0 ProxyPassReverse http://localhost:8005/ AuthType Basic AuthName "Enter account credentials" Require valid-user AuthBasicProvider ldap AuthLDAPGroupAttribute member AuthLDAPSubGroupClass group AuthLDAPGroupAttributeIsDN On AuthLDAPURL ldap://ldap.domain.com:389/OU=USERS,DC=domain,DC=com?sAMAccountName?sub?(objectClass=*) AuthLDAPBindDN ldap@domain.com AuthLDAPBindPassword password123 require ldap-group "CN=Users,OU=IT Users,OU=Security,OU=Groups,OU=CORP,DC=domain,DC=com" </Location> </VirtualHost>
额外注意事项
- 修正了
AuthLDAPBindDN中的拼写错误:domaion.com改为domain.com,避免LDAP绑定失败。 - 配置完成后重启Apache服务生效:
systemctl restart apache2(不同系统命令可能略有差异)。 - 确保Arkime服务正常运行在
localhost:8005,可通过curl http://localhost:8005测试连通性。
内容的提问来源于stack exchange,提问作者Dave
相关产品推荐
相关产品推荐

