You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache2反向代理:解决自定义端口HTTP转HTTPS/443的重定向问题

问题:Apache反向代理保留8788端口访问时出现安全连接失败

场景说明

  • 旧Web服务器仅在8788端口运行HTTP服务,需通过Debian系统的Apache反向代理对外提供服务
  • 客户端与代理间需加密通信(HTTPS),代理以HTTP/8788请求旧服务器
  • 已将oldserver.example.com的DNS指向反向代理IP,http://oldserver.example.com和https://oldserver.example.com访问正常

异常现象

访问http://oldserver.example.com:8788时,浏览器会自动重定向至https://oldserver.example.com:8788,并显示「安全连接失败」错误。但使用wget测试时一切正常。

wget测试输出

wget -v http://oldserver.example.com:8788
--2022-09-14 14:36:15--  http://oldserver.example.com:8788/
Resolving oldserver.example.com (oldserver.example.com)... X.X.X.X
Connecting to oldserver.example.com (oldserver.example.com)|X.X.X.X|:8788... connected.
HTTP request sent, awaiting response... 302 Found
Location: https://oldserver.example.com/ [following]
--2022-09-14 14:36:15--  https://oldserver.example.com/
Connecting to oldserver.example.com (oldserver.example.com)|X.X.X.X|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 11628 (11K) [text/html]
Saving to: 'index.html'

index.html.3                                        100%[=================================================================================================================>]  11.36K  --.-KB/s    in 0s

2022-09-14 14:36:15 (42.0 MB/s) - 'index.html' saved [11628/11628]

配置文件

/etc/apache2/sites-available/oldserver.conf

<VirtualHost *:80 *:8788>
    ServerName oldserver.example.com
    include /etc/apache2/xyz/general.conf
    include /etc/apache2/xyz/redirect-ssl.conf
    ErrorLog ${APACHE_LOG_DIR}/error_oldserver.log
    CustomLog ${APACHE_LOG_DIR}/access_oldserver.log combined
</VirtualHost>


<IfModule mod_ssl.c>
    <VirtualHost *:443>
            ServerName oldserver.example.com

            ErrorLog ${APACHE_LOG_DIR}/error_oldserver.log
            CustomLog ${APACHE_LOG_DIR}/access_oldserver.log combined

            include /etc/apache2/xyz/general.conf
            include /etc/apache2/xyz/ssl.conf
            include /etc/apache2/xyz/revproxy.conf
            ProxyPass / http://Y.Y.Y.Y:8788/
            ProxyPassreverse / http://Y.Y.Y.Y:8788/
    </Virtualhost>
</IfModule>

/etc/apache2/xyz/general.conf

ServerAdmin system@example.com
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined
Protocols h2 http/1.1
DocumentRoot /var/www/html
ErrorDocument 500 https://reverseproxy.example.com/
ErrorDocument 503 https://reverseproxy.example.com/

/etc/apache2/xyz/redirect-ssl.conf

RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^/?(.*) https://%{SERVER_NAME}/$1 [R,L]

/etc/apache2/xyz/revproxy.conf

ProxyPreserveHost On
ProxyRequests Off
SSLProxyEngine on

/etc/apache2/xyz/ssl.conf

#####▒| SSL #####

SSLEngine on
Header always set Strict-Transport-Security "max-age=15768000"

SSLCertificateFile      /etc/ssl/wildcard.example.com.crt
SSLCertificateKeyFile   /etc/ssl/wildcard.example.com.key

<FilesMatch "\.(cgi|shtml|phtml|php)$">
SSLOptions +StdEnvVars
</FilesMatch>
<Directory /usr/lib/cgi-bin>
SSLOptions +StdEnvVars
</Directory>
BrowserMatch "MSIE [2-6]" \
        nokeepalive ssl-unclean-shutdown \
        downgrade-1.0 force-response-1.0
BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown

日志信息

/var/log/apache2/error_oldserver.log无内容,/var/log/apache2/error.log中有以下错误:

[Wed Sep 14 14:43:53.497291 2022] [proxy_http:error] [pid 36806:tid 139808714381056] (20014)Internal error (specific information not available): [client Z.Z.Z.Z:51225] AH01102: error reading status line from remote server Y.Y.Y.Y:8788, referer: https://oldserver.example.com/

无法访问旧服务器日志,寻求解决办法。


解决方案

问题根源

  1. HSTS强制跳转:ssl.conf中配置的Strict-Transport-Security头会让浏览器强制将该域名的所有HTTP请求转为HTTPS,包括8788端口,而代理未在8788端口配置SSL服务,导致连接失败。
  2. 重写规则未适配端口:原重写规则未对8788端口做特殊处理,加上浏览器HSTS缓存,最终触发错误的HTTPS/8788请求。
  3. 错误日志的原因:浏览器向8788端口发送HTTPS请求,代理误将其转发给仅支持HTTP的旧服务器,导致读取响应状态行失败。

修复步骤

1. 修改重写规则,指定端口跳转

编辑/etc/apache2/xyz/redirect-ssl.conf,让8788端口的HTTP请求直接跳转到443端口的HTTPS:

RewriteEngine On
RewriteCond %{HTTPS} !=on
# 针对8788端口的HTTP请求,跳转至标准HTTPS端口
RewriteCond %{SERVER_PORT} ^8788$
RewriteRule ^/?(.*) https://%{SERVER_NAME}/$1 [R=301,L]
# 80端口的HTTP请求保持原有跳转逻辑
RewriteCond %{SERVER_PORT} ^80$
RewriteRule ^/?(.*) https://%{SERVER_NAME}/$1 [R=301,L]

2. 清除浏览器HSTS缓存(临时处理)

如果浏览器已经缓存了HSTS规则,需要手动清除对应域名的HSTS缓存:

  • Chrome:chrome://net-internals/#hsts → 找到「Delete domain security policies」输入域名后删除
  • Firefox:about:config → 搜索network.stricttransportsecurity.preloadlist设为false,重启后恢复(或直接清除浏览器缓存)

也可以在80/8788的VirtualHost中临时添加HSTS过期头,覆盖缓存:

# 在<VirtualHost *:80 *:8788>区块内添加
Header always set Strict-Transport-Security "max-age=0"

待用户浏览器缓存更新后,再移除该配置。

3. 验证配置并重启Apache

# 检查配置语法是否正确
apache2ctl configtest
# 重启服务生效
systemctl restart apache2

4. 可选:支持HTTPS/8788访问(若业务需求)

如果必须保留https://oldserver.example.com:8788的访问方式,需添加对应的SSL VirtualHost:

<IfModule mod_ssl.c>
    <VirtualHost *:8788>
            ServerName oldserver.example.com

            ErrorLog ${APACHE_LOG_DIR}/error_oldserver_8788.log
            CustomLog ${APACHE_LOG_DIR}/access_oldserver_8788.log combined

            include /etc/apache2/xyz/general.conf
            include /etc/apache2/xyz/ssl.conf
            include /etc/apache2/xyz/revproxy.conf
            ProxyPass / http://Y.Y.Y.Y:8788/
            ProxyPassreverse / http://Y.Y.Y.Y:8788/
    </Virtualhost>
</IfModule>

注意:需确保服务器防火墙开放8788端口的TCP流量,且SSL证书覆盖该域名。

验证标准

  • 访问http://oldserver.example.com:8788,自动跳转至https://oldserver.example.com并正常显示页面
  • 浏览器无「安全连接失败」提示
  • /var/log/apache2/error.log不再出现AH01102错误

内容的提问来源于stack exchange,提问作者Ben5469

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 05:40:52