You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache反向代理配置问题:LDAP认证成功但显示默认页面

问题分析与解决方案

核心问题1:访问显示Apache默认页面

你的ProxyPass和ProxyPassReverse配置的路径是/arkime/,这意味着只有访问https://test-arkime.domain.com/arkime/时才会触发反向代理到Arkime服务。直接访问根路径/时,Apache会加载默认站点目录(比如/var/www/html)的内容,因此显示默认页面。

核心问题2:Location块中配置ProxyPass报错

在<Location>块内使用ProxyPass时,不能再指定路径前缀——因为<Location>已经定义了匹配的路径。比如你若写<Location /arkime/>,里面的ProxyPass应该直接写目标URLhttp://localhost:8005/,而非/arkime/ http://localhost:8005/,这就是报错“ProxyPass|ProxyPassMatch can not have a path when defined in a location”的原因。

修正后的配置示例

提供两种常见适配方案:

方案1:通过根路径/直接访问Arkime

若希望访问https://test-arkime.domain.com/直接进入Arkime,配置如下:

<VirtualHost *:443>
  ServerName test-arkime.domain.com
  SSLEngine on
  SSLCertificateFile "/opt/arkime/etc/test-arkime.crt"
  SSLCertificateKeyFile "/opt/arkime/etc/test-arkime.key"
  
  # 代理根路径到Arkime服务
  ProxyPass        / http://localhost:8005/ retry=0
  ProxyPassReverse / http://localhost:8005/
  ProxyPreserveHost On
  RequestHeader set ARKIME_USER %{REMOTE_USER}e

  # 对根路径启用LDAP认证
  <Location />
    AuthType Basic
    AuthName "Enter account credentials"
    Require valid-user
    AuthBasicProvider ldap
    AuthLDAPGroupAttribute member
    AuthLDAPSubGroupClass group
    AuthLDAPGroupAttributeIsDN On
    AuthLDAPURL ldap://ldap.domain.com:389/OU=USERS,DC=domain,DC=com?sAMAccountName?sub?(objectClass=*)
    # 修正拼写错误:domaion.com → domain.com
    AuthLDAPBindDN ldap@domain.com
    AuthLDAPBindPassword password123

    require ldap-group "CN=Users,OU=IT Users,OU=Security,OU=Groups,OU=CORP,DC=domain,DC=com"
  </Location>
</VirtualHost>

方案2:通过/arkime/路径访问Arkime

若保留/arkime/路径的代理规则,配置如下:

<VirtualHost *:443>
  ServerName test-arkime.domain.com
  SSLEngine on
  SSLCertificateFile "/opt/arkime/etc/test-arkime.crt"
  SSLCertificateKeyFile "/opt/arkime/etc/test-arkime.key"
  
  ProxyPreserveHost On
  RequestHeader set ARKIME_USER %{REMOTE_USER}e

  # 对/arkime/路径配置代理和认证
  <Location /arkime/>
    ProxyPass http://localhost:8005/ retry=0
    ProxyPassReverse http://localhost:8005/
    
    AuthType Basic
    AuthName "Enter account credentials"
    Require valid-user
    AuthBasicProvider ldap
    AuthLDAPGroupAttribute member
    AuthLDAPSubGroupClass group
    AuthLDAPGroupAttributeIsDN On
    AuthLDAPURL ldap://ldap.domain.com:389/OU=USERS,DC=domain,DC=com?sAMAccountName?sub?(objectClass=*)
    AuthLDAPBindDN ldap@domain.com
    AuthLDAPBindPassword password123

    require ldap-group "CN=Users,OU=IT Users,OU=Security,OU=Groups,OU=CORP,DC=domain,DC=com"
  </Location>
</VirtualHost>

额外注意事项

  • 修正了AuthLDAPBindDN中的拼写错误:domaion.com改为domain.com,避免LDAP绑定失败。
  • 配置完成后重启Apache服务生效:systemctl restart apache2(不同系统命令可能略有差异)。
  • 确保Arkime服务正常运行在localhost:8005,可通过curl http://localhost:8005测试连通性。

内容的提问来源于stack exchange,提问作者Dave

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 00:25:27