CentOS系统中Apache服务无法启动/重启的问题排查与解决请求
Apache无法重启:httpd.service启动失败的原因与解决办法
问题情况
之前运行正常的Apache突然无法重启,执行apachectl configtest返回符号查找错误:
/usr/local/apache/bin/httpd: undefined symbol: apr_crypto_init
systemctl status httpd.service输出如下:
httpd.service - Web server Apache Loaded: loaded (/usr/lib/systemd/system/httpd.service; enabled; vendor preset: disabled) Active: failed (Result: exit-code) since Tue 2022-10-04 22:36:27 CST; 1min 24s ago Process: 13030 ExecStop=/usr/local/apache/bin/apachectl graceful-stop (code=exited, status=127) Process: 3911 ExecStart=/usr/local/apache/bin/apachectl start (code=exited, status=127) Main PID: 851 (code=exited, status=0/SUCCESS) Oct 04 22:36:27 hwsrv-985893.hostwindsdns.com systemd[1]: Starting Web server Apache... Oct 04 22:36:27 hwsrv-985893.hostwindsdns.com apachectl[3911]: /usr/local/apache/bin/httpd: symbol lookup error: /usr/local/apache/bin/httpd: undefined symbol: apr_crypto_init Oct 04 22:36:27 hwsrv-985893.hostwindsdns.com systemd[1]: httpd.service: control process exited, code=exited status=127 Oct 04 22:36:27 hwsrv-985893.hostwindsdns.com systemd[1]: Failed to start Web server Apache. Oct 04 22:36:27 hwsrv-985893.hostwindsdns.com systemd[1]: Unit httpd.service entered failed state. Oct 04 22:36:27 hwsrv-985893.hostwindsdns.com systemd[1]: httpd.service failed.
journalctl -xe输出未包含Apache启动失败的相关有效信息,仅显示SSH暴力破解日志:
Oct 04 22:51:54 hwsrv-985893.hostwindsdns.com kernel: net_ratelimit: 75 callbacks suppressed Oct 04 22:51:56 hwsrv-985893.hostwindsdns.com sshd[4063]: Failed password for root from 61.177.172.114 port 36803 ssh2 Oct 04 22:51:56 hwsrv-985893.hostwindsdns.com sshd[4065]: Failed password for root from 218.92.0.195 port 33236 ssh2 Oct 04 22:51:56 hwsrv-985893.hostwindsdns.com sshd[4063]: Received disconnect from 61.177.172.114 port 36803:11: [preauth] Oct 04 22:51:56 hwsrv-985893.hostwindsdns.com sshd[4063]: Disconnected from 61.177.172.114 port 36803 [preauth] Oct 04 22:51:56 hwsrv-985893.hostwindsdns.com sshd[4063]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=61.177.172.114 user=root Oct 04 22:51:56 hwsrv-985893.hostwindsdns.com sshd[4065]: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root" Oct 04 22:51:59 hwsrv-985893.hostwindsdns.com sshd[4065]: Failed password for root from 218.92.0.195 port 33236 ssh2 Oct 04 22:51:59 hwsrv-985893.hostwindsdns.com sshd[4065]: Received disconnect from 218.92.0.195 port 33236:11: [preauth] Oct 04 22:51:59 hwsrv-985893.hostwindsdns.com sshd[4065]: Disconnected from 218.92.0.195 port 33236 [preauth] Oct 04 22:51:59 hwsrv-985893.hostwindsdns.com sshd[4065]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=218.92.0.195 user=root Oct 04 22:51:59 hwsrv-985893.hostwindsdns.com kernel: net_ratelimit: 65 callbacks suppressed Oct 04 22:52:05 hwsrv-985893.hostwindsdns.com kernel: net_ratelimit: 77 callbacks suppressed
问题根源
报错undefined symbol: apr_crypto_init本质是httpd无法找到APR(Apache运行时库)加密模块的初始化函数,常见原因包括:
- APR/APR-util版本不兼容:近期更新过APR库,但httpd基于旧版APR编译,导致符号匹配失败
- 加密库丢失或损坏:APR加密相关库(如
libaprutil-1.so)被误删、损坏,或系统无法识别库路径 - httpd编译配置问题:编译时启用了加密支持,但运行环境缺少对应库依赖
解决办法
办法1:检查并修复APR库依赖
- 查找系统中APR-util库的位置:
find / -name "libaprutil-1.so*"
- 验证httpd是否能识别该库:
ldd /usr/local/apache/bin/httpd | grep aprutil
若未找到库路径,需添加到动态链接配置:
- 编辑
/etc/ld.so.conf.d/apr.conf,写入库所在路径(例如/usr/local/apr/lib) - 执行
ldconfig更新缓存
办法2:重新编译APR与httpd(源码编译环境适用)
- 卸载现有不兼容的APR/APR-util:
# 源码安装环境,进入APR源码目录执行 make uninstall # 包管理器环境(以CentOS为例) yum remove apr apr-util
- 下载并编译匹配版本的APR和APR-util:
# 下载APR(版本需与httpd编译时一致,示例版本) wget https://dlcdn.apache.org/apr/apr-1.7.4.tar.gz tar zxvf apr-1.7.4.tar.gz cd apr-1.7.4 ./configure --prefix=/usr/local/apr make && make install # 下载APR-util wget https://dlcdn.apache.org/apr/apr-util-1.6.3.tar.gz tar zxvf apr-util-1.6.3.tar.gz cd apr-util-1.6.3 ./configure --prefix=/usr/local/apr-util --with-apr=/usr/local/apr make && make install
- 重新编译httpd并指定APR路径:
cd httpd源码目录 ./configure --prefix=/usr/local/apache --with-apr=/usr/local/apr --with-apr-util=/usr/local/apr-util make && make install
办法3:回滚APR版本(近期更新过APR时适用)
若更新APR后出现问题,直接回滚至之前正常版本:
- 包管理器环境(CentOS):
yum downgrade apr apr-util
- 源码安装环境:重新编译旧版本APR并安装
办法4:检查httpd编译配置
确认编译时是否启用加密支持,若需要则重新编译时添加--enable-crypto选项:
./configure --prefix=/usr/local/apache --with-apr=/usr/local/apr --with-apr-util=/usr/local/apr-util --enable-crypto
验证修复
执行apachectl configtest,若返回Syntax OK则重启httpd:
systemctl restart httpd.service
再通过systemctl status httpd.service确认服务状态正常。
内容的提问来源于stack exchange,提问作者johnoula
相关产品推荐
相关产品推荐

