You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WampServer搭配Symfony 2时HTTPS无法正常工作求助

问题排查:Symfony2 本地HTTPS配置失效

问题背景

本地Symfony2应用在HTTP模式下可正常访问,将security.yml中access_control的全局requires_channel从http改为https后,页面无法访问。相关配置如下:

HTTP模式下的access_control配置

access_control:
        # URL of FOSUserBundle which need to be available to anonymous users
        - { path: ^/_wdt, role: IS_AUTHENTICATED_ANONYMOUSLY }
        - { path: ^/_profiler, role: IS_AUTHENTICATED_ANONYMOUSLY }

        - { path: ^/register, role: IS_AUTHENTICATED_ANONYMOUSLY }
        - { path: ^/resetting, role: IS_AUTHENTICATED_ANONYMOUSLY }

        # Secured part of the site
        # This config requires being logged for the whole site and having the admin role for the admin part.
        # Change these rules to adapt them to your needs
        - { path: ^/admin, role: ROLE_ADMIN }


        - { path: ^/user/login$, role: IS_AUTHENTICATED_ANONYMOUSLY }
        - { path: ^/user/logout$, role: IS_AUTHENTICATED_ANONYMOUSLY }
        - { path: ^/user/login_check$, role: IS_AUTHENTICATED_ANONYMOUSLY }

        - { path: ^/user$, role: ROLE_USER }

        - { path: ^/acv$, role: ROLE_USER }
        - { path: ^/urba$, role: ROLE_USER }
        - { path: ^/design$, role: ROLE_USER }
        - { path: ^/distrib$, role: ROLE_USER }
        - { path: ^/flux$, role: ROLE_USER }
        - { path: ^/product$, role: ROLE_USER }


        - { path: ^/.*, role: IS_AUTHENTICATED_ANONYMOUSLY ,requires_channel: http}

HTTPS模式下修改后的access_control配置

access_control:
        # URL of FOSUserBundle which need to be available to anonymous users
        - { path: ^/_wdt, role: IS_AUTHENTICATED_ANONYMOUSLY }
        - { path: ^/_profiler, role: IS_AUTHENTICATED_ANONYMOUSLY }

        - { path: ^/register, role: IS_AUTHENTICATED_ANONYMOUSLY }
        - { path: ^/resetting, role: IS_AUTHENTICATED_ANONYMOUSLY }

        # Secured part of the site
        # This config requires being logged for the whole site and having the admin role for the admin part.
        # Change these rules to adapt them to your needs
        - { path: ^/admin, role: ROLE_ADMIN }


        - { path: ^/user/login$, role: IS_AUTHENTICATED_ANONYMOUSLY }
        - { path: ^/user/logout$, role: IS_AUTHENTICATED_ANONYMOUSLY }
        - { path: ^/user/login_check$, role: IS_AUTHENTICATED_ANONYMOUSLY }

        - { path: ^/user$, role: ROLE_USER }

        - { path: ^/acv$, role: ROLE_USER }
        - { path: ^/urba$, role: ROLE_USER }
        - { path: ^/design$, role: ROLE_USER }
        - { path: ^/distrib$, role: ROLE_USER }
        - { path: ^/flux$, role: ROLE_USER }
        - { path: ^/product$, role: ROLE_USER }


        - { path: ^/.*, role: IS_AUTHENTICATED_ANONYMOUSLY ,requires_channel: https}

当前Apache虚拟主机配置

HTTP虚拟主机

<VirtualHost *:80>
    ServerName artogreen
    DocumentRoot "c:/wamp64/www/artogreen/web"
    <Directory  "c:/wamp64/www/artogreen/web">
        Options +Indexes +Includes +FollowSymLinks +MultiViews
        AllowOverride None
        Require all granted
        Order allow,deny
        allow from all
        <IfModule mod_rewrite.c>
            RewriteEngine On
            RewriteCond %{REQUEST_FILENAME} !-f
            RewriteRule ^(.*)$ /app_dev.php [QSA,L]
        </IfModule>
    </Directory>
</VirtualHost>

SSL虚拟主机

<VirtualHost _default_:443>

#   General setup for the virtual host
DocumentRoot "c:/wamp/www/"
ServerName localhost:443
ServerAdmin admin@example.com
ErrorLog "c:/wamp64/bin/apache/Apache2.4.51/logs/ssl_error.log"
TransferLog "c:/wamp64/bin/apache/Apache2.4.51/logs/ssl_access.log"

#   SSL Engine Switch:
#   Enable/Disable SSL for this virtual host.
SSLEngine on

#   Server Certificate:
SSLCertificateFile "c:/wamp64/bin/apache/Apache2.4.51/conf/cert/certificat.crt"

#   Server Private Key:
SSLCertificateKeyFile "c:/wamp64/bin/apache/Apache2.4.51/conf/key/private.key"

#   SSL Engine Options:
SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire
<FilesMatch "\.(cgi|shtml|phtml|php)$">
    SSLOptions +StdEnvVars
</FilesMatch>
<Directory "c:/wamp/www/">
    SSLOptions +StdEnvVars
</Directory>

<Directory  "c:/wamp64/www/">
    Options Indexes FollowSymLinks Includes ExecCGI
    AllowOverride All
    Require all granted
</Directory>
<Directory  "c:/wamp64/www/artogreen/">
    Options Indexes FollowSymLinks MultiViews
    AllowOverride All
    Require all granted
</Directory>

#   SSL Protocol Adjustments:
BrowserMatch "MSIE [2-5]" \
         nokeepalive ssl-unclean-shutdown \
         downgrade-1.0 force-response-1.0

#   Per-Server Logging:
CustomLog "C:/wamp64/bin/apache/Apache2.4.51/logs/ssl_request.log" \
          "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"

</VirtualHost>

问题排查与修复方案

1. 修正SSL虚拟主机的DocumentRoot与ServerName

当前SSL虚拟主机的根目录指向c:/wamp/www/,和HTTP虚拟主机的c:/wamp64/www/artogreen/web不一致,且未指向Symfony的web入口目录;同时ServerName为localhost:443,和HTTP的artogreen不统一,导致域名解析与路径匹配错误。

修改后的SSL虚拟主机头部配置:

<VirtualHost *:443>
#   General setup for the virtual host
DocumentRoot "c:/wamp64/www/artogreen/web"
ServerName artogreen:443
ServerAdmin admin@example.com
ErrorLog "c:/wamp64/bin/apache/Apache2.4.51/logs/ssl_error.log"
TransferLog "c:/wamp64/bin/apache/Apache2.4.51/logs/ssl_access.log"

2. 添加Symfony路由重写规则到SSL虚拟主机

HTTP虚拟主机中配置了rewrite规则将非文件请求转发到app_dev.php,但SSL虚拟主机缺少该配置,导致请求无法正确路由到Symfony入口文件。

在SSL虚拟主机的<Directory "c:/wamp64/www/artogreen/web">块中添加重写规则:

<Directory  "c:/wamp64/www/artogreen/web">
    Options Indexes FollowSymLinks MultiViews
    AllowOverride All
    Require all granted
    <IfModule mod_rewrite.c>
        RewriteEngine On
        RewriteCond %{REQUEST_FILENAME} !-f
        RewriteRule ^(.*)$ /app_dev.php [QSA,L]
    </IfModule>
</Directory>

3. 确保Symfony能识别HTTPS请求

在Symfony的config.yml中添加信任本地代理配置,确保应用能正确识别HTTPS请求:

framework:
    trusted_proxies: ['127.0.0.1']
    trusted_hosts: ['artogreen']

4. 验证SSL证书与密钥有效性

确保SSL证书certificat.crt和私钥private.key文件路径正确,且证书与密钥匹配。可通过以下命令验证:

openssl x509 -noout -modulus -in certificat.crt | openssl md5
openssl rsa -noout -modulus -in private.key | openssl md5

两个命令输出的哈希值需一致。


内容的提问来源于stack exchange,提问作者user3735247

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 18:10:26