You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache2反向代理HTTPS SSL握手错误问题排查求助

Apache2 HTTPS反向代理故障排查

问题描述

在私有网络内将Apache2配置为网关,实现外部HTTPS流量转发至内部网络,HTTP转发功能正常,但HTTPS转发失效。

错误日志

[Tue May 02 14:52:51.347146 2023] [proxy:error] [pid 5423:tid 140612283090496] [client my.ip:17059] AH00898: Error during SSL Handshake with remote server returned by /
[Tue May 02 14:52:51.347161 2023] [proxy_http:error] [pid 5423:tid 140612283090496] [client my.ip:17059] AH01097: pass request body failed to 100.100.100.100:553 (100.100.100.100) from 100.100.100.100 ()
[Tue May 02 14:52:51.397245 2023] [proxy:error] [pid 5423:tid 140612145747520] [client my.ip:17060] AH00898: DNS lookup failure for: 100.100.100.100:553favicon.ico returned by /favicon.ico, referer: https://example.com:2230/

当前Apache2配置

<VirtualHost *:2230>
        ServerName example.com
        ErrorLog ${APACHE_LOG_DIR}/proxy/error.log
        CustomLog ${APACHE_LOG_DIR}/proxy/access.log combined

         <Proxy *>
        Order deny,allow
        Allow from all
        Authtype Basic
        Authname "Password Required"
        AuthUserFile /etc/apache2/passwords
        Require valid-user
        </Proxy>

        SSLEngine on
        SSLProxyEngine on
        SSLProxyVerify none
        SSLProxyCheckPeerCN off
        SSLProxyCheckPeerName off
        SSLProxyProtocol +TLSv1
        SSLCertificateFile /etc/letsencrypt/live/example.com/fullchain.pem
        SSLCertificateKeyFile /etc/letsencrypt/live/example.com/privkey.pem
        Include /etc/letsencrypt/options-ssl-apache.conf


        ProxyPreserveHost On
        ProxyPass / https://100.100.100.100:553
        ProxyPassReverse / https://100.100.100.100:553
</VirtualHost>

问题排查与解决方案

1. 修复ProxyPass路径拼接错误

日志中出现100.100.100.100:553favicon.ico的DNS错误,是因为ProxyPass目标URL末尾缺少斜杠,导致Apache把端口和资源名直接拼接在一起。

修改配置中的转发规则,添加末尾斜杠:

ProxyPass / https://100.100.100.100:553/
ProxyPassReverse / https://100.100.100.100:553/

2. 调整TLS协议版本兼容性

当前配置SSLProxyProtocol +TLSv1仅启用了老旧的TLSv1版本,多数现代服务器已禁用该版本(存在安全漏洞),这会直接导致SSL握手失败(对应日志中的AH00898错误)。

建议替换为更安全且兼容的协议版本:

SSLProxyProtocol +TLSv1.2 +TLSv1.3

如果后端确实只能使用TLSv1,需确认后端服务器配置允许,但不推荐长期保留该配置。

3. 验证后端服务器连通性

从Apache服务器执行命令测试与后端的SSL握手:

curl -v https://100.100.100.100:553

检查是否能正常建立SSL连接,排查是否存在网络端口不通、后端服务未启动等问题。

4. 检查ProxyPreserveHost配置影响

ProxyPreserveHost On会将客户端请求的Host头(example.com)转发给后端,如果后端服务器的虚拟主机配置中没有匹配该ServerName,可能导致无法正确响应。可临时注释该配置,测试是否恢复正常。


内容的提问来源于stack exchange,提问作者SirSeba

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 07:23:22