You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server 2019上Apache 2.4 SSL配置失败求助

Apache 2.4(Windows Server 2019)SSL配置启动失败问题排查与解决

我在公司网络的Windows Server 2019虚拟机上部署了Apache 2.4,HTTP服务正常,但配置HTTPS的SSL时遇到服务无法启动的问题。

通过MMC添加证书管理单元生成证书请求后,提交给管理员收到以下文件:

certnew.cer   
certnew.p7b   
intermediate.cer
root.cer

我查阅资料后得出的结论(修正错误点后):

  • .cer与.crt文件本质相同,仅编码可能有差异,可替换使用并修改扩展名;
  • 错误:提交的证书请求文件(CSR)不是私钥,私钥是生成CSR时本地证书存储中保存的密钥文件,CSR仅用于向CA申请证书;
  • Apache 2.4与旧版本SSL配置有差异,需参考对应版本的指南;
  • 需在主配置文件启用SSL,并在httpd-ssl.conf中配置证书信息。

当前httpd-ssl.conf的相关配置如下:

<VirtualHost *:443>

#   General setup for the virtual host
DocumentRoot "${SRVROOT}/htdocs"
ServerName <servername>
ServerAdmin <internal email>
ErrorLog "${SRVROOT}/logs/error.log"
TransferLog "${SRVROOT}/logs/access.log"

#   SSL Engine Switch:
#   Enable/Disable SSL for this virtual host.
SSLEngine on

#   Server Certificate:
#   Point SSLCertificateFile at a PEM encoded certificate.  If
#   the certificate is encrypted, then you will be prompted for a
#   pass phrase.  Note that a kill -HUP will prompt again.  Keep
#   in mind that if you have both an RSA and a DSA certificate you
#   can configure both in parallel (to also allow the use of DSA
#   ciphers, etc.)
#   Some ECC cipher suites (http://www.ietf.org/rfc/rfc4492.txt)
#   require an ECC certificate which can also be configured in
#   parallel.
SSLCertificateFile "${SRVROOT}/conf/primary.crt"
#SSLCertificateFile "${SRVROOT}/conf/server-dsa.crt"
#SSLCertificateFile "${SRVROOT}/conf/server-ecc.crt"

#   Server Private Key:
#   If the key is not combined with the certificate, use this
#   directive to point at the key file.  Keep in mind that if
#   you've both a RSA and a DSA private key you can configure
#   both in parallel (to also allow the use of DSA ciphers, etc.)
#   ECC keys, when in use, can also be configured in parallel
SSLCertificateKeyFile "${SRVROOT}/conf/private.key"
#SSLCertificateKeyFile "${SRVROOT}/conf/server-dsa.key"
#SSLCertificateKeyFile "${SRVROOT}/conf/server-ecc.key"

#   Server Certificate Chain:
#   Point SSLCertificateChainFile at a file containing the
#   concatenation of PEM encoded CA certificates which form the
#   certificate chain for the server certificate. Alternatively
#   the referenced file can be the same as SSLCertificateFile
#   when the CA certificates are directly appended to the server
#   certificate for convenience.
SSLCertificateChainFile "${SRVROOT}/conf/certificate.crt"

#   Certificate Authority (CA):
#   Set the CA certificate verification path where to find CA
#   certificates for client authentication or alternatively one
#   huge file containing all of them (file must be PEM encoded)
#   Note: Inside SSLCACertificatePath you need hash symlinks
#         to point to the certificate files. Use the provided
#         Makefile to update the hash symlinks after changes.
#SSLCACertificatePath "${SRVROOT}/conf/root.cer"
SSLCACertificateFile "${SRVROOT}/conf/root.cer"

</VirtualHost>

将收到的证书文件及提交的私钥文件重命名为配置中指定的名称后,启用SSL时Apache服务无法启动。命令行启动httpd.exe后,错误日志信息如下:

[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] AH02577: Init: SSLPassPhraseDialog builtin is not supported on Win32 (key file D:/Apache24/conf/private.key)
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] AH02311: Fatal error initialising mod_ssl, exiting. See D:/Apache24/logs/error.log for more information
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] AH02564: Failed to configure encrypted (?) private key <servername>:443:0, check D:/Apache24/conf/private.key
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error (Type=PKCS8_PRIV_KEY_INFO)
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D08303A:asn1 encoding routines:asn1_template_noexp_d2i:nested asn1 error
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error (Type=RSAPrivateKey)
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:04093004:rsa routines:old_rsa_priv_decode:RSA lib
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error (Type=PKCS8_PRIV_KEY_INFO)
AH00016: Configuration Failed

问题根源与解决步骤

1. 核心问题定位

从错误日志可判断两个关键问题:

  • Windows平台不支持Apache内置的密码弹窗,若私钥加密会直接启动失败;
  • ASN.1编码错误说明私钥文件格式不符合Apache要求(大概率是误将CSR文件当成私钥,或私钥为DER编码而非PEM)。

2. 导出正确的私钥文件

生成CSR时,MMC已在本地证书存储中创建对应私钥,需从本地导出:

  • 打开MMC -> 添加证书管理单元(选择「计算机账户」);
  • 进入「个人」->「证书」,找到与CSR匹配的证书(需先导入管理员返回的certnew.cer);
  • 右键证书 -> 所有任务 -> 导出;
  • 选择「是,导出私钥」,格式选PKCS #12,设置导出密码,保存为.pfx文件。

3. 转换为Apache支持的PEM格式

使用OpenSSL工具执行以下命令:

  • 导出无加密私钥:
    openssl pkcs12 -in yourcert.pfx -nocerts -out private.key -nodes
    
  • 导出服务器证书:
    openssl pkcs12 -in yourcert.pfx -nokeys -out primary.crt
    
  • 将中间证书和根证书转换为PEM格式(若原文件为DER编码):
    openssl x509 -inform der -in intermediate.cer -out intermediate.pem
    openssl x509 -inform der -in root.cer -out root.pem
    

4. 配置证书链

将intermediate.pem的内容追加到primary.crt末尾,或单独设置SSLCertificateChainFile指向intermediate.pem,无需重复配置根证书。

5. 修正配置并验证

确保httpd-ssl.conf中路径指向转换后的PEM文件,执行命令检查配置语法:

httpd.exe -t

语法无误后启动Apache服务即可。

内容的提问来源于stack exchange,提问作者Anseur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 23:50:25