Apache2反向代理:解决自定义端口HTTP转HTTPS/443的重定向问题
问题:Apache反向代理保留8788端口访问时出现安全连接失败
场景说明
- 旧Web服务器仅在8788端口运行HTTP服务,需通过Debian系统的Apache反向代理对外提供服务
- 客户端与代理间需加密通信(HTTPS),代理以HTTP/8788请求旧服务器
- 已将
oldserver.example.com的DNS指向反向代理IP,http://oldserver.example.com和https://oldserver.example.com访问正常
异常现象
访问http://oldserver.example.com:8788时,浏览器会自动重定向至https://oldserver.example.com:8788,并显示「安全连接失败」错误。但使用wget测试时一切正常。
wget测试输出
wget -v http://oldserver.example.com:8788 --2022-09-14 14:36:15-- http://oldserver.example.com:8788/ Resolving oldserver.example.com (oldserver.example.com)... X.X.X.X Connecting to oldserver.example.com (oldserver.example.com)|X.X.X.X|:8788... connected. HTTP request sent, awaiting response... 302 Found Location: https://oldserver.example.com/ [following] --2022-09-14 14:36:15-- https://oldserver.example.com/ Connecting to oldserver.example.com (oldserver.example.com)|X.X.X.X|:443... connected. HTTP request sent, awaiting response... 200 OK Length: 11628 (11K) [text/html] Saving to: 'index.html' index.html.3 100%[=================================================================================================================>] 11.36K --.-KB/s in 0s 2022-09-14 14:36:15 (42.0 MB/s) - 'index.html' saved [11628/11628]
配置文件
/etc/apache2/sites-available/oldserver.conf
<VirtualHost *:80 *:8788> ServerName oldserver.example.com include /etc/apache2/xyz/general.conf include /etc/apache2/xyz/redirect-ssl.conf ErrorLog ${APACHE_LOG_DIR}/error_oldserver.log CustomLog ${APACHE_LOG_DIR}/access_oldserver.log combined </VirtualHost> <IfModule mod_ssl.c> <VirtualHost *:443> ServerName oldserver.example.com ErrorLog ${APACHE_LOG_DIR}/error_oldserver.log CustomLog ${APACHE_LOG_DIR}/access_oldserver.log combined include /etc/apache2/xyz/general.conf include /etc/apache2/xyz/ssl.conf include /etc/apache2/xyz/revproxy.conf ProxyPass / http://Y.Y.Y.Y:8788/ ProxyPassreverse / http://Y.Y.Y.Y:8788/ </Virtualhost> </IfModule>
/etc/apache2/xyz/general.conf
ServerAdmin system@example.com ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined Protocols h2 http/1.1 DocumentRoot /var/www/html ErrorDocument 500 https://reverseproxy.example.com/ ErrorDocument 503 https://reverseproxy.example.com/
/etc/apache2/xyz/redirect-ssl.conf
RewriteEngine On RewriteCond %{HTTPS} !=on RewriteRule ^/?(.*) https://%{SERVER_NAME}/$1 [R,L]
/etc/apache2/xyz/revproxy.conf
ProxyPreserveHost On ProxyRequests Off SSLProxyEngine on
/etc/apache2/xyz/ssl.conf
#####▒| SSL ##### SSLEngine on Header always set Strict-Transport-Security "max-age=15768000" SSLCertificateFile /etc/ssl/wildcard.example.com.crt SSLCertificateKeyFile /etc/ssl/wildcard.example.com.key <FilesMatch "\.(cgi|shtml|phtml|php)$"> SSLOptions +StdEnvVars </FilesMatch> <Directory /usr/lib/cgi-bin> SSLOptions +StdEnvVars </Directory> BrowserMatch "MSIE [2-6]" \ nokeepalive ssl-unclean-shutdown \ downgrade-1.0 force-response-1.0 BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown
日志信息
/var/log/apache2/error_oldserver.log无内容,/var/log/apache2/error.log中有以下错误:
[Wed Sep 14 14:43:53.497291 2022] [proxy_http:error] [pid 36806:tid 139808714381056] (20014)Internal error (specific information not available): [client Z.Z.Z.Z:51225] AH01102: error reading status line from remote server Y.Y.Y.Y:8788, referer: https://oldserver.example.com/
无法访问旧服务器日志,寻求解决办法。
解决方案
问题根源
- HSTS强制跳转:
ssl.conf中配置的Strict-Transport-Security头会让浏览器强制将该域名的所有HTTP请求转为HTTPS,包括8788端口,而代理未在8788端口配置SSL服务,导致连接失败。 - 重写规则未适配端口:原重写规则未对8788端口做特殊处理,加上浏览器HSTS缓存,最终触发错误的HTTPS/8788请求。
- 错误日志的原因:浏览器向8788端口发送HTTPS请求,代理误将其转发给仅支持HTTP的旧服务器,导致读取响应状态行失败。
修复步骤
1. 修改重写规则,指定端口跳转
编辑/etc/apache2/xyz/redirect-ssl.conf,让8788端口的HTTP请求直接跳转到443端口的HTTPS:
RewriteEngine On RewriteCond %{HTTPS} !=on # 针对8788端口的HTTP请求,跳转至标准HTTPS端口 RewriteCond %{SERVER_PORT} ^8788$ RewriteRule ^/?(.*) https://%{SERVER_NAME}/$1 [R=301,L] # 80端口的HTTP请求保持原有跳转逻辑 RewriteCond %{SERVER_PORT} ^80$ RewriteRule ^/?(.*) https://%{SERVER_NAME}/$1 [R=301,L]
2. 清除浏览器HSTS缓存(临时处理)
如果浏览器已经缓存了HSTS规则,需要手动清除对应域名的HSTS缓存:
- Chrome:
chrome://net-internals/#hsts→ 找到「Delete domain security policies」输入域名后删除 - Firefox:
about:config→ 搜索network.stricttransportsecurity.preloadlist设为false,重启后恢复(或直接清除浏览器缓存)
也可以在80/8788的VirtualHost中临时添加HSTS过期头,覆盖缓存:
# 在<VirtualHost *:80 *:8788>区块内添加 Header always set Strict-Transport-Security "max-age=0"
待用户浏览器缓存更新后,再移除该配置。
3. 验证配置并重启Apache
# 检查配置语法是否正确 apache2ctl configtest # 重启服务生效 systemctl restart apache2
4. 可选:支持HTTPS/8788访问(若业务需求)
如果必须保留https://oldserver.example.com:8788的访问方式,需添加对应的SSL VirtualHost:
<IfModule mod_ssl.c> <VirtualHost *:8788> ServerName oldserver.example.com ErrorLog ${APACHE_LOG_DIR}/error_oldserver_8788.log CustomLog ${APACHE_LOG_DIR}/access_oldserver_8788.log combined include /etc/apache2/xyz/general.conf include /etc/apache2/xyz/ssl.conf include /etc/apache2/xyz/revproxy.conf ProxyPass / http://Y.Y.Y.Y:8788/ ProxyPassreverse / http://Y.Y.Y.Y:8788/ </Virtualhost> </IfModule>
注意:需确保服务器防火墙开放8788端口的TCP流量,且SSL证书覆盖该域名。
验证标准
- 访问
http://oldserver.example.com:8788,自动跳转至https://oldserver.example.com并正常显示页面 - 浏览器无「安全连接失败」提示
/var/log/apache2/error.log不再出现AH01102错误
内容的提问来源于stack exchange,提问作者Ben5469
相关产品推荐
相关产品推荐

