You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置IBM HTTP Server(IHS)为仅代理出站SSL的反向代理

IHS反向代理仅出站SSL配置报错解决

负载均衡器监听443端口,终止SSL连接后将请求转发至IBM HTTP Server(IHS)的80端口。需将IHS配置为反向代理,把请求转发至目标服务器的443端口(HTTPS)。

流量路径:
浏览器 --443--> 负载均衡器 --80--> IHS --443--> 目标服务器

选择在IHS上配置的原因:负载均衡器不在我方管控范围内,IHS可快速按需修改目标URL。

核心需求:仅针对发往目标服务器的出站请求启用SSL,入站请求无需SSL。

错误配置及问题

最初使用的httpd.conf配置片段:

LoadModule ibm_ssl_module modules/mod_ibm_ssl.so
SSLProxyEngine on
<VirtualHost *:80>
  # ServerName webserverhostname # not needed so far
  SSLEnable # without this i get "SSL0263W: SSL Connection attempted when SSL did not initialize."
  KeyFile store.kdb # without this i get "SSL0170E: GSK could not initialize, no keyfile specified."
  SSLStashFile store.sth
  ProxyPass / https://targeturl/
  ProxyPassReverse / https://targeturl/
</VirtualHost>
SSLDisable

其中store.kdb包含目标服务器的CA证书。

但服务器持续报错:

SSL0227E: SSL Handshake Failed, Specified label could not be found in the key file, or the specified label is not a 'personal certificate' (no private key). Label='(null)'

按理解,IHS监听80端口,入站流量已由负载均衡器终止SSL,不应出现入站SSL处理失败的问题。

解决方案

调整后的正确配置:

LoadModule ibm_ssl_module modules/mod_ibm_ssl.so
SSLProxyEngine on
<VirtualHost *:80>
  # ServerName webserverhostname # not needed so far
  # SSLEnable # this would activate SSL for incoming traffic
  KeyFile store.kdb # this contains the CA certificates of the target server
  # SSLStashFile store.sth # would only be needed for incoming SSL
  ProxyPass / https://targeturl/
  ProxyPassReverse / https://targeturl/
</VirtualHost>
# SSLDisable

关键调整点

  • 移除SSLEnable:该指令用于为入站流量启用SSL,而我们的入站流量是HTTP,无需开启。
  • 注释SSLStashFile:该文件仅服务于入站SSL的密钥存储,出站请求不需要。
  • 保留KeyFile:用于验证目标服务器的CA证书,确保出站SSL连接的安全性。

内容的提问来源于stack exchange,提问作者alejandro z

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 02:35:26