CentOS 8下Httpd服务器ERR_BAD_SSL_CLIENT_AUTH_CERT问题排查
问题描述
我在CentOS 8的httpd服务器上部署了Flask应用,要求客户端提供有效证书,将DN、CN、SERIAL等SSL变量传递给Flask做访问校验,无效证书需跳转至/site/public/failed错误页。目前只有我的证书能通过Apache校验并正常访问,但同公司同CA的同事访问时出现ERR_BAD_SSL_CLIENT_AUTH_CERT错误及空白页。对比日志发现:
- 我的证书校验深度到2
- 同事的证书仅校验深度0,且日志显示错误
EE certificate key too weak,SSL握手失败
相关配置及日志如下:
Apache配置
Listen ip:443 ##SSLPassPhraseDialog exec:/usr/libexec/httpd-ssl-pass-dialog SSLSessionCache shmcb:/run/httpd/sslcache(512000) SSLSessionCacheTimeout 300 SSLRandomSeed startup file:/dev/urandom 256 SSLRandomSeed connect builtin SSLCryptoDevice builtin ##SSLCipherSuite PROFILE=SYSTEM ##SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256 ##SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!3DES:!MD5:!PSK SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 -TLSv1.3 SSLHonorCipherOrder on SSLCompression off WSGIPythonHome /home/path/to/venv WSGIRestrictStdin Off WSGIRestrictStdout Off <VirtualHost ip:443> ServerName app.com ErrorLog /etc/httpd/logs/sshproxy-secure.error_log CustomLog /etc/httpd/logs/sshproxy-secure.access_log ssl_combined SSLEngine on SSLCertificateFile /home/path/to/crt.crt SSLCertificateKeyFile /home/path/to/some_key.key SSLCACertificateFile /etc/pki/tls/main_ca.crt SSLCACertificateFile /path/to/more/ca.crt WSGIDaemonProcess sshproxy threads=20 processes=2 python-path=/home/path/to/venv/lib/python3.10/site-packages #user=user1 group=group1 threads=5 #WSGIPythonPath /opt/sshproxy/lib/python2.7/site-packages WSGIScriptAlias / /home/path/to/wsgi-script/sshproxy-webserver-wsgi.py WSGIScriptReloading On <Directory /home/path/to/app> WSGIProcessGroup sshproxy WSGIApplicationGroup %{GLOBAL} Require all granted </Directory> #<Location /> # SSLRequireSSL #Require ip 126.16.13.20 126.16.18. #</Location> SSLVerifyClient optional SSLVerifyDepth 5 SSLOptions +StdEnvVars </VirtualHost>
我的访问日志
[Mon Aug 29 08:36:54.406586 2022] [ssl:debug] [pid 17586:tid 140176105887488] ssl_engine_kernel.c(2330): [client 126.189.244.168:60496] AH02043: SSL virtual host for servername app.com found [Mon Aug 29 08:36:54.406615 2022] [ssl:debug] [pid 17586:tid 140176105887488] ssl_engine_kernel.c(2330): [client 126.189.244.168:60496] AH02043: SSL virtual host for servername app.com found [Mon Aug 29 08:36:54.406629 2022] [core:debug] [pid 17586:tid 140176105887488] protocol.c(2314): [client 126.189.244.168:60496] AH03155: select protocol from , choices=h2,http/1.1 for server app.com [Mon Aug 29 08:36:59.631867 2022] [ssl:debug] [pid 17586:tid 140176105887488] ssl_engine_kernel.c(1751): [client 126.189.244.168:60496] AH02275: Certificate Verification, depth 2, CRL checking mode: none (0) [subject: [Mon Aug 29 08:36:59.632161 2022] [ssl:debug] [pid 17586:tid 140176105887488] ssl_engine_kernel.c(1751): [client 126.189.244.168:60496] AH02275: Certificate Verification, depth 1, CRL checking mode: none (0) [subject: [Mon Aug 29 08:36:59.632380 2022] [ssl:debug] [pid 17586:tid 140176105887488] ssl_engine_kernel.c(1751): [client 126.189.244.168:60496] AH02275: Certificate Verification, depth 0, CRL checking mode: none (0) [subject: [Mon Aug 29 08:36:59.632679 2022] [ssl:debug] [pid 17586:tid 140176105887488] ssl_engine_kernel.c(2246): [client 126.189.244.168:60496] AH02041: Protocol: TLSv1.3, Cipher: TLS_AES_128_GCM_SHA256 (128/128 bits) [Mon Aug 29 08:36:59.633566 2022] [ssl:debug] [pid 17586:tid 140176105887488] ssl_engine_kernel.c(383): [client 126.189.244.168:60496] AH02034: Initial (No.1) HTTPS request received for child 204 (server domain:443) [Mon Aug 29 08:36:59.633893 2022] [authz_core:debug] [pid 17586:tid 140176105887488] mod_authz_core.c(820): [client 126.189.244.168:60496] AH01626: authorization result of Require all granted: granted [Mon Aug 29 08:36:59.633925 2022] [authz_core:debug] [pid 17586:tid 140176105887488] mod_authz_core.c(820): [client 126.189.244.168:60496] AH01626: authorization result of <RequireAny>: granted
同事的访问日志
[Tue Aug 30 11:01:41.293387 2022] [ssl:debug] [pid 24609:tid 140421665646336] ssl_engine_kernel.c(2330): [client 126.189.44.235:57122] AH02043: SSL virtual host for app.com [Tue Aug 30 11:01:41.293496 2022] [ssl:debug] [pid 24609:tid 140421665646336] ssl_engine_kernel.c(2330): [client 126.189.44.235:57122] AH02043: SSL virtual host for app.com [Tue Aug 30 11:01:41.293519 2022] [core:debug] [pid 24609:tid 140421665646336] protocol.c(2314): [client 126.189.44.235:57122] AH03155: select protocol from , choices=h2,http/1.1 for server [Tue Aug 30 11:01:41.476727 2022] [ssl:debug] [pid 24609:tid 140421665646336] ssl_engine_kernel.c(1751): [client 126.189.44.235:57122] AH02275: Certificate Verification, depth 0, CRL checking m [Tue Aug 30 11:01:41.476860 2022] [ssl:info] [pid 24609:tid 140421665646336] [client 126.189.44.235:57122] AH02276: Certificate Verification: Error (66): EE certificate key too weak [subject: e [Tue Aug 30 11:01:41.476988 2022] [ssl:info] [pid 24609:tid 140421665646336] [client 126.189.44.235:57122] AH02008: SSL library error 1 in handshake (server domain:443) [Tue Aug 30 11:01:41.477100 2022] [ssl:info] [pid 24609:tid 140421665646336] SSL Library Error: error:1417C086:SSL routines:tls_process_client_certificate:certificate verify failed [Tue Aug 30 11:01:41.477120 2022] [ssl:info] [pid 24609:tid 140421665646336] [client 126.189.44.235:57122] AH01998: Connection closed to child 194 with abortive shutdown (server napupp19.corpne [Tue Aug 30 11:01:44.545107 2022] [ssl:info] [pid 24609:tid 140421573326592] [client 126.189.44.235:57125] AH01964: Connection to child 205 established (server domain:443) [Tue Aug 30 11:01:44.545572 2022] [socache_shmcb:debug] [pid 24609:tid 140421573326592] mod_socache_shmcb.c(532): AH00835: socache_shmcb_retrieve (0xea -> subcache 10) [Tue Aug 30 11:01:44.545621 2022] [socache_shmcb:debug] [pid 24609:tid 140421573326592] mod_socache_shmcb.c(917): AH00851: shmcb_subcache_retrieve found no match [Tue Aug 30 11:01:44.545634 2022] [socache_shmcb:debug] [pid 24609:tid 140421573326592] mod_socache_shmcb.c(542): AH00836: leaving socache_shmcb_retrieve successfully
分析与解答
核心原因
同事的证书在**深度0(客户端证书本身)**就触发了密钥强度校验失败的错误,导致Apache直接中断SSL握手流程,没有机会继续向上验证证书链的上级CA(深度1、深度2),所以日志仅显示深度0的校验记录。
具体细节:
- 日志中明确标记
EE certificate key too weak,说明同事的客户端证书使用的密钥长度不符合Apache的安全要求(比如RSA密钥小于2048位,或ECC密钥强度不足)。 - 你的证书密钥强度符合要求,所以Apache会完成整个证书链的验证:从客户端证书(深度0)→ 中间CA(深度1)→ 根CA(深度2),因此日志能看到完整的校验深度记录。
解决方向
- 检查证书密钥强度:让同事查看自己的证书密钥长度,确认是否低于2048位(RSA)或对应ECC算法的最小安全强度要求。
- 更换合规证书:最安全的方式是让同事重新申请符合密钥强度要求的客户端证书。
- 临时兼容配置(不推荐):如果必须兼容旧证书,可以调整Apache的SSL配置,调整密钥强度验证阈值,但会降低安全性,需谨慎操作。
内容的提问来源于stack exchange,提问作者drzejus
相关产品推荐
相关产品推荐

