WampServer搭配Symfony 2时HTTPS无法正常工作求助
问题排查:Symfony2 本地HTTPS配置失效
问题背景
本地Symfony2应用在HTTP模式下可正常访问,将security.yml中access_control的全局requires_channel从http改为https后,页面无法访问。相关配置如下:
HTTP模式下的access_control配置
access_control: # URL of FOSUserBundle which need to be available to anonymous users - { path: ^/_wdt, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/_profiler, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/register, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/resetting, role: IS_AUTHENTICATED_ANONYMOUSLY } # Secured part of the site # This config requires being logged for the whole site and having the admin role for the admin part. # Change these rules to adapt them to your needs - { path: ^/admin, role: ROLE_ADMIN } - { path: ^/user/login$, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/user/logout$, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/user/login_check$, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/user$, role: ROLE_USER } - { path: ^/acv$, role: ROLE_USER } - { path: ^/urba$, role: ROLE_USER } - { path: ^/design$, role: ROLE_USER } - { path: ^/distrib$, role: ROLE_USER } - { path: ^/flux$, role: ROLE_USER } - { path: ^/product$, role: ROLE_USER } - { path: ^/.*, role: IS_AUTHENTICATED_ANONYMOUSLY ,requires_channel: http}
HTTPS模式下修改后的access_control配置
access_control: # URL of FOSUserBundle which need to be available to anonymous users - { path: ^/_wdt, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/_profiler, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/register, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/resetting, role: IS_AUTHENTICATED_ANONYMOUSLY } # Secured part of the site # This config requires being logged for the whole site and having the admin role for the admin part. # Change these rules to adapt them to your needs - { path: ^/admin, role: ROLE_ADMIN } - { path: ^/user/login$, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/user/logout$, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/user/login_check$, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/user$, role: ROLE_USER } - { path: ^/acv$, role: ROLE_USER } - { path: ^/urba$, role: ROLE_USER } - { path: ^/design$, role: ROLE_USER } - { path: ^/distrib$, role: ROLE_USER } - { path: ^/flux$, role: ROLE_USER } - { path: ^/product$, role: ROLE_USER } - { path: ^/.*, role: IS_AUTHENTICATED_ANONYMOUSLY ,requires_channel: https}
当前Apache虚拟主机配置
HTTP虚拟主机
<VirtualHost *:80> ServerName artogreen DocumentRoot "c:/wamp64/www/artogreen/web" <Directory "c:/wamp64/www/artogreen/web"> Options +Indexes +Includes +FollowSymLinks +MultiViews AllowOverride None Require all granted Order allow,deny allow from all <IfModule mod_rewrite.c> RewriteEngine On RewriteCond %{REQUEST_FILENAME} !-f RewriteRule ^(.*)$ /app_dev.php [QSA,L] </IfModule> </Directory> </VirtualHost>
SSL虚拟主机
<VirtualHost _default_:443> # General setup for the virtual host DocumentRoot "c:/wamp/www/" ServerName localhost:443 ServerAdmin admin@example.com ErrorLog "c:/wamp64/bin/apache/Apache2.4.51/logs/ssl_error.log" TransferLog "c:/wamp64/bin/apache/Apache2.4.51/logs/ssl_access.log" # SSL Engine Switch: # Enable/Disable SSL for this virtual host. SSLEngine on # Server Certificate: SSLCertificateFile "c:/wamp64/bin/apache/Apache2.4.51/conf/cert/certificat.crt" # Server Private Key: SSLCertificateKeyFile "c:/wamp64/bin/apache/Apache2.4.51/conf/key/private.key" # SSL Engine Options: SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire <FilesMatch "\.(cgi|shtml|phtml|php)$"> SSLOptions +StdEnvVars </FilesMatch> <Directory "c:/wamp/www/"> SSLOptions +StdEnvVars </Directory> <Directory "c:/wamp64/www/"> Options Indexes FollowSymLinks Includes ExecCGI AllowOverride All Require all granted </Directory> <Directory "c:/wamp64/www/artogreen/"> Options Indexes FollowSymLinks MultiViews AllowOverride All Require all granted </Directory> # SSL Protocol Adjustments: BrowserMatch "MSIE [2-5]" \ nokeepalive ssl-unclean-shutdown \ downgrade-1.0 force-response-1.0 # Per-Server Logging: CustomLog "C:/wamp64/bin/apache/Apache2.4.51/logs/ssl_request.log" \ "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b" </VirtualHost>
问题排查与修复方案
1. 修正SSL虚拟主机的DocumentRoot与ServerName
当前SSL虚拟主机的根目录指向c:/wamp/www/,和HTTP虚拟主机的c:/wamp64/www/artogreen/web不一致,且未指向Symfony的web入口目录;同时ServerName为localhost:443,和HTTP的artogreen不统一,导致域名解析与路径匹配错误。
修改后的SSL虚拟主机头部配置:
<VirtualHost *:443> # General setup for the virtual host DocumentRoot "c:/wamp64/www/artogreen/web" ServerName artogreen:443 ServerAdmin admin@example.com ErrorLog "c:/wamp64/bin/apache/Apache2.4.51/logs/ssl_error.log" TransferLog "c:/wamp64/bin/apache/Apache2.4.51/logs/ssl_access.log"
2. 添加Symfony路由重写规则到SSL虚拟主机
HTTP虚拟主机中配置了rewrite规则将非文件请求转发到app_dev.php,但SSL虚拟主机缺少该配置,导致请求无法正确路由到Symfony入口文件。
在SSL虚拟主机的<Directory "c:/wamp64/www/artogreen/web">块中添加重写规则:
<Directory "c:/wamp64/www/artogreen/web"> Options Indexes FollowSymLinks MultiViews AllowOverride All Require all granted <IfModule mod_rewrite.c> RewriteEngine On RewriteCond %{REQUEST_FILENAME} !-f RewriteRule ^(.*)$ /app_dev.php [QSA,L] </IfModule> </Directory>
3. 确保Symfony能识别HTTPS请求
在Symfony的config.yml中添加信任本地代理配置,确保应用能正确识别HTTPS请求:
framework: trusted_proxies: ['127.0.0.1'] trusted_hosts: ['artogreen']
4. 验证SSL证书与密钥有效性
确保SSL证书certificat.crt和私钥private.key文件路径正确,且证书与密钥匹配。可通过以下命令验证:
openssl x509 -noout -modulus -in certificat.crt | openssl md5 openssl rsa -noout -modulus -in private.key | openssl md5
两个命令输出的哈希值需一致。
内容的提问来源于stack exchange,提问作者user3735247
相关产品推荐
相关产品推荐

