You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu服务器SSL握手代理错误:Node.js应用Apache反向代理问题

Node.js应用Apache反向代理SSL配置问题解决

问题详情

运行在3000端口的Node.js Web应用无法配合Apache SSL配置正常工作,浏览器返回502 Bad Gateway错误,Apache错误日志报AH01097: pass request body failed。

Apache虚拟主机配置(/etc/apache2/domain.conf)

<VirtualHost *:443>
       
        SSLProxyEngine on
        SSLProxyVerify none
        SSLProxyCheckPeerCN off
        SSLProxyCheckPeerName off

        ProxyPreserveHost on
        ProxyPass  / https://***.es:3000/
        ProxyPassReverse   / https://***.es:3000/

        SSLEngine on
        SSLCertificateFile /certs/certificateSSL.crt
        SSLCertificateKeyFile /certs/keySSL.key
        SSLCertificateChainFile  /certs/DigiCertCA.crt

        ServerAdmin webmaster@localhost
        ServerName ***.es
        ProxyRequests Off
        ServerAlias www.***.es

     
        ErrorLog ${APACHE_LOG_DIR}/error.log
        CustomLog ${APACHE_LOG_DIR}/access.log combined

</VirtualHost>

关键错误日志(/var/log/apache2/error.log)

[Mon Jan 16 17:47:29.698548 2023] [proxy_http:error] [pid 22330:tid 140606592464640] [client ****:54470] AH01097: pass request body failed to *****:3000 (****.es) from **** ()

解决步骤

1. 确认Node.js应用的协议类型

当前代理配置指向https://***.es:3000,但多数Node.js默认应用运行在HTTP协议下:

  • 先测试本地访问Node应用:curl -I http://localhost:3000,如果能正常响应,说明应用是HTTP服务
  • 修改Apache的代理配置为HTTP目标:
    # 移除SSLProxy相关配置(因为目标是HTTP)
    # SSLProxyEngine on
    # SSLProxyVerify none
    # SSLProxyCheckPeerCN off
    # SSLProxyCheckPeerName off
    
    ProxyPass  / http://localhost:3000/
    ProxyPassReverse   / http://localhost:3000/
    

2. 修复请求体传递失败问题

针对AH01097错误,添加请求缓冲相关配置到VirtualHost块:

RequestHeader unset Expect
ProxyBufferSize 64k
ProxyBuffers 4 64k
ProxyTimeout 60

这些配置确保Apache能正确缓冲并传递请求体到后端服务。

3. 验证Apache必要模块已启用

执行以下命令启用反向代理和SSL相关模块:

a2enmod proxy proxy_http ssl headers
systemctl restart apache2

4. 检查端口可达性

确认Apache服务器能访问Node应用的3000端口:

# 如果是HTTP应用
curl -I http://localhost:3000
# 如果是HTTPS应用
openssl s_client -connect ***.es:3000

若无法访问,检查Node应用是否正常监听3000端口,或本地防火墙是否限制了端口访问。

5. 若Node应用确实使用HTTPS

如果Node应用配置了自有SSL证书,确保证书能被Apache信任:

  • 若使用自签名证书,保留SSLProxyVerify none等跳过验证的配置
  • 检查Node应用的SSL配置是否正确,确保***.es域名与证书匹配

内容的提问来源于stack exchange,提问作者IvannVerano

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 06:45:22