Windows Server 2019上Apache 2.4 SSL配置失败求助
Apache 2.4(Windows Server 2019)SSL配置启动失败问题排查与解决
我在公司网络的Windows Server 2019虚拟机上部署了Apache 2.4,HTTP服务正常,但配置HTTPS的SSL时遇到服务无法启动的问题。
通过MMC添加证书管理单元生成证书请求后,提交给管理员收到以下文件:
certnew.cer certnew.p7b intermediate.cer root.cer
我查阅资料后得出的结论(修正错误点后):
- .cer与.crt文件本质相同,仅编码可能有差异,可替换使用并修改扩展名;
- 错误:提交的证书请求文件(CSR)不是私钥,私钥是生成CSR时本地证书存储中保存的密钥文件,CSR仅用于向CA申请证书;
- Apache 2.4与旧版本SSL配置有差异,需参考对应版本的指南;
- 需在主配置文件启用SSL,并在httpd-ssl.conf中配置证书信息。
当前httpd-ssl.conf的相关配置如下:
<VirtualHost *:443> # General setup for the virtual host DocumentRoot "${SRVROOT}/htdocs" ServerName <servername> ServerAdmin <internal email> ErrorLog "${SRVROOT}/logs/error.log" TransferLog "${SRVROOT}/logs/access.log" # SSL Engine Switch: # Enable/Disable SSL for this virtual host. SSLEngine on # Server Certificate: # Point SSLCertificateFile at a PEM encoded certificate. If # the certificate is encrypted, then you will be prompted for a # pass phrase. Note that a kill -HUP will prompt again. Keep # in mind that if you have both an RSA and a DSA certificate you # can configure both in parallel (to also allow the use of DSA # ciphers, etc.) # Some ECC cipher suites (http://www.ietf.org/rfc/rfc4492.txt) # require an ECC certificate which can also be configured in # parallel. SSLCertificateFile "${SRVROOT}/conf/primary.crt" #SSLCertificateFile "${SRVROOT}/conf/server-dsa.crt" #SSLCertificateFile "${SRVROOT}/conf/server-ecc.crt" # Server Private Key: # If the key is not combined with the certificate, use this # directive to point at the key file. Keep in mind that if # you've both a RSA and a DSA private key you can configure # both in parallel (to also allow the use of DSA ciphers, etc.) # ECC keys, when in use, can also be configured in parallel SSLCertificateKeyFile "${SRVROOT}/conf/private.key" #SSLCertificateKeyFile "${SRVROOT}/conf/server-dsa.key" #SSLCertificateKeyFile "${SRVROOT}/conf/server-ecc.key" # Server Certificate Chain: # Point SSLCertificateChainFile at a file containing the # concatenation of PEM encoded CA certificates which form the # certificate chain for the server certificate. Alternatively # the referenced file can be the same as SSLCertificateFile # when the CA certificates are directly appended to the server # certificate for convenience. SSLCertificateChainFile "${SRVROOT}/conf/certificate.crt" # Certificate Authority (CA): # Set the CA certificate verification path where to find CA # certificates for client authentication or alternatively one # huge file containing all of them (file must be PEM encoded) # Note: Inside SSLCACertificatePath you need hash symlinks # to point to the certificate files. Use the provided # Makefile to update the hash symlinks after changes. #SSLCACertificatePath "${SRVROOT}/conf/root.cer" SSLCACertificateFile "${SRVROOT}/conf/root.cer" </VirtualHost>
将收到的证书文件及提交的私钥文件重命名为配置中指定的名称后,启用SSL时Apache服务无法启动。命令行启动httpd.exe后,错误日志信息如下:
[Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] AH02577: Init: SSLPassPhraseDialog builtin is not supported on Win32 (key file D:/Apache24/conf/private.key) [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] AH02311: Fatal error initialising mod_ssl, exiting. See D:/Apache24/logs/error.log for more information [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] AH02564: Failed to configure encrypted (?) private key <servername>:443:0, check D:/Apache24/conf/private.key [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error (Type=PKCS8_PRIV_KEY_INFO) [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D08303A:asn1 encoding routines:asn1_template_noexp_d2i:nested asn1 error [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error (Type=RSAPrivateKey) [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:04093004:rsa routines:old_rsa_priv_decode:RSA lib [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag [Sun Oct 30 15:06:02.661255 2022] [ssl:emerg] [pid 3484:tid 512] SSL Library Error: error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error (Type=PKCS8_PRIV_KEY_INFO) AH00016: Configuration Failed
问题根源与解决步骤
1. 核心问题定位
从错误日志可判断两个关键问题:
- Windows平台不支持Apache内置的密码弹窗,若私钥加密会直接启动失败;
- ASN.1编码错误说明私钥文件格式不符合Apache要求(大概率是误将CSR文件当成私钥,或私钥为DER编码而非PEM)。
2. 导出正确的私钥文件
生成CSR时,MMC已在本地证书存储中创建对应私钥,需从本地导出:
- 打开MMC -> 添加证书管理单元(选择「计算机账户」);
- 进入「个人」->「证书」,找到与CSR匹配的证书(需先导入管理员返回的certnew.cer);
- 右键证书 -> 所有任务 -> 导出;
- 选择「是,导出私钥」,格式选
PKCS #12,设置导出密码,保存为.pfx文件。
3. 转换为Apache支持的PEM格式
使用OpenSSL工具执行以下命令:
- 导出无加密私钥:
openssl pkcs12 -in yourcert.pfx -nocerts -out private.key -nodes - 导出服务器证书:
openssl pkcs12 -in yourcert.pfx -nokeys -out primary.crt - 将中间证书和根证书转换为PEM格式(若原文件为DER编码):
openssl x509 -inform der -in intermediate.cer -out intermediate.pem openssl x509 -inform der -in root.cer -out root.pem
4. 配置证书链
将intermediate.pem的内容追加到primary.crt末尾,或单独设置SSLCertificateChainFile指向intermediate.pem,无需重复配置根证书。
5. 修正配置并验证
确保httpd-ssl.conf中路径指向转换后的PEM文件,执行命令检查配置语法:
httpd.exe -t
语法无误后启动Apache服务即可。
内容的提问来源于stack exchange,提问作者Anseur
相关产品推荐
相关产品推荐

