You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Symfony框架下HTTP转HTTPS配置失效求助

问题:Symfony网站HTTP转HTTPS带8000端口重定向失败,出现SSL_ERROR_RX_RECORD_TOO_LONG

尝试将所有HTTP请求重定向至HTTPS并自动添加8000端口,多种配置方案均无效,当前遇到SSL_ERROR_RX_RECORD_TOO_LONG错误,曾生成证书但未使用。


现有配置情况

public目录下的.htaccess

RewriteEngine On
RewriteCond %{REQUEST_FILENAME} !-f
RewriteRule ^(.*)$ index.php [QSA,L]

根目录尝试过的.htaccess示例

示例1

RewriteCond %{HTTP:X-Forwarded-Proto} !https 
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

示例2

RewriteEngine on
RewriteBase /
RewriteCond %{HTTPS} off
RewriteRule .* https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
RewriteCond %{HTTP_HOST} !^www\. [NC]
RewriteRule .* https://www.%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
RewriteCond %{REQUEST_URI} !^/public/
RewriteRule ^(.*)$ /public/$1 [L]

示例3

RewriteEngine On

RewriteCond %{HTTPS} off

RewriteRule ^(.*)$ https://myurl [L,R=301]

RewriteCond %{HTTP_HOST} ^www\.(([a-z0-9_]+\.)?10.16.10.164)$ [NC]

RewriteRule .? http://%1%{REQUEST_URI} [R=301,L]

RewriteCond %{REQUEST_FILENAME} !-f RewriteRule ^(.*)$ web/$1 [QSA,L]

Apache的VirtualHost配置尝试

配置1

<VirtualHost *:80>
    <Location "/">
        Redirect permanent "https://%{HTTP_HOST}:8000%{REQUEST_URI}"    
    </Location>
</VirtualHost>

配置2

<VirtualHost *:80>
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^/?(.*)$ https:/myurl/$1 [NE,L,R=301
</VirtualHost>

Symfony配置

security.yaml

access_control:
    - { path: ^/, requires_channel: https}

framework.yaml

trusted_proxies: '192.0.0.1,10.0.0.0/8, myurl'
# trust *all* "X-Forwarded-*" headers
trusted_headers: ['x-forwarded-for', 'x-forwarded-host', 'x-forwarded-proto', 'x-forwarded-port', 'x-forwarded-prefix']
# or, if your proxy instead uses the "Forwarded" header
trusted_headers: ['forwarded']

有效解决方案

1. 先解决SSL_ERROR_RX_RECORD_TOO_LONG错误

该错误核心原因是HTTPS端口(8000)未正确配置SSL证书,或客户端将HTTP请求发送到了HTTPS端口:

  • 配置HTTPS的VirtualHost,监听8000端口并加载证书:
<VirtualHost *:8000>
    ServerName myurl
    DocumentRoot /path/to/your/project/public

    SSLEngine on
    SSLCertificateFile /path/to/your/certificate.crt
    SSLCertificateKeyFile /path/to/your/private.key

    # 处理Symfony路由
    RewriteEngine On
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteRule ^(.*)$ index.php [QSA,L]
</VirtualHost>
  • 启用Apache必要模块并重启服务:
a2enmod ssl rewrite
systemctl restart apache2

2. 配置HTTP到HTTPS(8000端口)的重定向

修改80端口的VirtualHost,强制所有HTTP请求跳转到带8000端口的HTTPS地址:

<VirtualHost *:80>
    ServerName myurl
    RewriteEngine On
    RewriteRule ^(.*)$ https://%{HTTP_HOST}:8000$1 [L,R=301]
</VirtualHost>

3. 调整Symfony配置

  • 移除framework.yaml中重复的trusted_headers配置,保留一行适配环境的:
trusted_proxies: '192.0.0.1,10.0.0.0/8, myurl'
trusted_headers: ['x-forwarded-for', 'x-forwarded-host', 'x-forwarded-proto', 'x-forwarded-port', 'x-forwarded-prefix']
  • 保留security.yaml中的requires_channel配置,确保Symfony内部路由强制HTTPS。

4. 清理多余配置

  • 删除根目录下的.htaccess,重定向逻辑交由Apache VirtualHost处理;
  • 保留public目录下的.htaccess,用于Symfony前端控制器路由。

验证步骤

  1. 重启Apache服务确保配置生效;
  2. 访问http://your-domain,检查是否自动跳转到https://your-domain:8000;
  3. 确认HTTPS访问正常,无SSL_ERROR_RX_RECORD_TOO_LONG错误。

内容的提问来源于stack exchange,提问作者mco

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 15:35:47