Apache2反向代理HTTPS SSL握手错误问题排查求助
Apache2 HTTPS反向代理故障排查
问题描述
在私有网络内将Apache2配置为网关,实现外部HTTPS流量转发至内部网络,HTTP转发功能正常,但HTTPS转发失效。
错误日志
[Tue May 02 14:52:51.347146 2023] [proxy:error] [pid 5423:tid 140612283090496] [client my.ip:17059] AH00898: Error during SSL Handshake with remote server returned by / [Tue May 02 14:52:51.347161 2023] [proxy_http:error] [pid 5423:tid 140612283090496] [client my.ip:17059] AH01097: pass request body failed to 100.100.100.100:553 (100.100.100.100) from 100.100.100.100 () [Tue May 02 14:52:51.397245 2023] [proxy:error] [pid 5423:tid 140612145747520] [client my.ip:17060] AH00898: DNS lookup failure for: 100.100.100.100:553favicon.ico returned by /favicon.ico, referer: https://example.com:2230/
当前Apache2配置
<VirtualHost *:2230> ServerName example.com ErrorLog ${APACHE_LOG_DIR}/proxy/error.log CustomLog ${APACHE_LOG_DIR}/proxy/access.log combined <Proxy *> Order deny,allow Allow from all Authtype Basic Authname "Password Required" AuthUserFile /etc/apache2/passwords Require valid-user </Proxy> SSLEngine on SSLProxyEngine on SSLProxyVerify none SSLProxyCheckPeerCN off SSLProxyCheckPeerName off SSLProxyProtocol +TLSv1 SSLCertificateFile /etc/letsencrypt/live/example.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/example.com/privkey.pem Include /etc/letsencrypt/options-ssl-apache.conf ProxyPreserveHost On ProxyPass / https://100.100.100.100:553 ProxyPassReverse / https://100.100.100.100:553 </VirtualHost>
问题排查与解决方案
1. 修复ProxyPass路径拼接错误
日志中出现100.100.100.100:553favicon.ico的DNS错误,是因为ProxyPass目标URL末尾缺少斜杠,导致Apache把端口和资源名直接拼接在一起。
修改配置中的转发规则,添加末尾斜杠:
ProxyPass / https://100.100.100.100:553/ ProxyPassReverse / https://100.100.100.100:553/
2. 调整TLS协议版本兼容性
当前配置SSLProxyProtocol +TLSv1仅启用了老旧的TLSv1版本,多数现代服务器已禁用该版本(存在安全漏洞),这会直接导致SSL握手失败(对应日志中的AH00898错误)。
建议替换为更安全且兼容的协议版本:
SSLProxyProtocol +TLSv1.2 +TLSv1.3
如果后端确实只能使用TLSv1,需确认后端服务器配置允许,但不推荐长期保留该配置。
3. 验证后端服务器连通性
从Apache服务器执行命令测试与后端的SSL握手:
curl -v https://100.100.100.100:553
检查是否能正常建立SSL连接,排查是否存在网络端口不通、后端服务未启动等问题。
4. 检查ProxyPreserveHost配置影响
ProxyPreserveHost On会将客户端请求的Host头(example.com)转发给后端,如果后端服务器的虚拟主机配置中没有匹配该ServerName,可能导致无法正确响应。可临时注释该配置,测试是否恢复正常。
内容的提问来源于stack exchange,提问作者SirSeba
相关产品推荐
相关产品推荐

