CentOS 7环境下Apache部署Django应用HTTPS配置故障排查求助
Let's tackle your issues step by step, focusing on the critical errors first:
1. 核心问题:Permission Denied(权限拒绝)
Even though you changed the ownership of your app directory to apache:apache, CentOS sets the default home directory (/home/centos) to 700 permissions (drwx------), which means only the centos user can access it. The apache user can't even enter the /home/centos folder, let alone read files inside it.
Fix:
- First, add the
apacheuser to thecentosgroup to grant access:sudo usermod -aG centos apache - Update the home directory permissions to allow group users to enter:
sudo chmod g+x /home/centos - Ensure your app directory has proper read/execute permissions for the group:
sudo chmod -R g+rx /home/centos/path_to_my_app
2. SELinux 限制(容易忽略的关键点)
CentOS's SELinux is likely blocking Apache from accessing files in /home/centos (since it's not the default web root). You need to set the correct SELinux context:
sudo semanage fcontext -a -t httpd_sys_content_t "/home/centos/path_to_my_app(/.*)?" sudo restorecon -Rv /home/centos/path_to_my_app
3. mod_mime_magic 错误
The AH01512 error happens because mod_mime_magic is trying to read your wsgi.py file to detect its MIME type, but it can't access it (related to the permission/SELinux issues above). Alternatively, you can just disable this module since it's not necessary for most setups:
- Edit
/etc/httpd/conf.modules.d/00-mime.conf - Comment out the line:
# LoadModule mime_magic_module modules/mod_mime_magic.so
4. SSL 证书警告(非致命但建议修复)
The AH01906 warning means your self-signed certificate is marked as a CA certificate, which isn't ideal for a server cert. Regenerate your certificate without CA attributes:
sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/apache-selfsigned.key -out /etc/ssl/certs/apache-selfsigned.crt
When prompted, set the Common Name to my_app_dns (match your ServerName), and you can leave other fields blank.
Final Steps
After applying these fixes:
- Restart Apache to apply all changes:
sudo systemctl restart httpd - Verify Apache is running properly:
sudo systemctl status httpd - Check the error logs again to confirm no remaining issues:
tail -f /var/log/httpd/ssl_error_log
内容的提问来源于stack exchange,提问作者Tristan Tran

