配置IBM HTTP Server(IHS)为仅代理出站SSL的反向代理
IHS反向代理仅出站SSL配置报错解决
负载均衡器监听443端口,终止SSL连接后将请求转发至IBM HTTP Server(IHS)的80端口。需将IHS配置为反向代理,把请求转发至目标服务器的443端口(HTTPS)。
流量路径:
浏览器 --443--> 负载均衡器 --80--> IHS --443--> 目标服务器
选择在IHS上配置的原因:负载均衡器不在我方管控范围内,IHS可快速按需修改目标URL。
核心需求:仅针对发往目标服务器的出站请求启用SSL,入站请求无需SSL。
错误配置及问题
最初使用的httpd.conf配置片段:
LoadModule ibm_ssl_module modules/mod_ibm_ssl.so SSLProxyEngine on <VirtualHost *:80> # ServerName webserverhostname # not needed so far SSLEnable # without this i get "SSL0263W: SSL Connection attempted when SSL did not initialize." KeyFile store.kdb # without this i get "SSL0170E: GSK could not initialize, no keyfile specified." SSLStashFile store.sth ProxyPass / https://targeturl/ ProxyPassReverse / https://targeturl/ </VirtualHost> SSLDisable
其中store.kdb包含目标服务器的CA证书。
但服务器持续报错:
SSL0227E: SSL Handshake Failed, Specified label could not be found in the key file, or the specified label is not a 'personal certificate' (no private key). Label='(null)'
按理解,IHS监听80端口,入站流量已由负载均衡器终止SSL,不应出现入站SSL处理失败的问题。
解决方案
调整后的正确配置:
LoadModule ibm_ssl_module modules/mod_ibm_ssl.so SSLProxyEngine on <VirtualHost *:80> # ServerName webserverhostname # not needed so far # SSLEnable # this would activate SSL for incoming traffic KeyFile store.kdb # this contains the CA certificates of the target server # SSLStashFile store.sth # would only be needed for incoming SSL ProxyPass / https://targeturl/ ProxyPassReverse / https://targeturl/ </VirtualHost> # SSLDisable
关键调整点
- 移除
SSLEnable:该指令用于为入站流量启用SSL,而我们的入站流量是HTTP,无需开启。 - 注释
SSLStashFile:该文件仅服务于入站SSL的密钥存储,出站请求不需要。 - 保留
KeyFile:用于验证目标服务器的CA证书,确保出站SSL连接的安全性。
内容的提问来源于stack exchange,提问作者alejandro z
相关产品推荐
相关产品推荐

