You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS 7环境下Apache部署Django应用HTTPS配置故障排查求助

问题分析与解决方案

Let's tackle your issues step by step, focusing on the critical errors first:

1. 核心问题:Permission Denied(权限拒绝)

Even though you changed the ownership of your app directory to apache:apache, CentOS sets the default home directory (/home/centos) to 700 permissions (drwx------), which means only the centos user can access it. The apache user can't even enter the /home/centos folder, let alone read files inside it.

Fix:

  • First, add the apache user to the centos group to grant access:
    sudo usermod -aG centos apache
    
  • Update the home directory permissions to allow group users to enter:
    sudo chmod g+x /home/centos
    
  • Ensure your app directory has proper read/execute permissions for the group:
    sudo chmod -R g+rx /home/centos/path_to_my_app
    

2. SELinux 限制(容易忽略的关键点)

CentOS's SELinux is likely blocking Apache from accessing files in /home/centos (since it's not the default web root). You need to set the correct SELinux context:

sudo semanage fcontext -a -t httpd_sys_content_t "/home/centos/path_to_my_app(/.*)?"
sudo restorecon -Rv /home/centos/path_to_my_app

3. mod_mime_magic 错误

The AH01512 error happens because mod_mime_magic is trying to read your wsgi.py file to detect its MIME type, but it can't access it (related to the permission/SELinux issues above). Alternatively, you can just disable this module since it's not necessary for most setups:

  • Edit /etc/httpd/conf.modules.d/00-mime.conf
  • Comment out the line:
    # LoadModule mime_magic_module modules/mod_mime_magic.so
    

4. SSL 证书警告(非致命但建议修复)

The AH01906 warning means your self-signed certificate is marked as a CA certificate, which isn't ideal for a server cert. Regenerate your certificate without CA attributes:

sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/apache-selfsigned.key -out /etc/ssl/certs/apache-selfsigned.crt

When prompted, set the Common Name to my_app_dns (match your ServerName), and you can leave other fields blank.

Final Steps

After applying these fixes:

  1. Restart Apache to apply all changes:
    sudo systemctl restart httpd
    
  2. Verify Apache is running properly:
    sudo systemctl status httpd
    
  3. Check the error logs again to confirm no remaining issues:
    tail -f /var/log/httpd/ssl_error_log
    

内容的提问来源于stack exchange,提问作者Tristan Tran

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 18:37:29