You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法配置Apache HTTPS代理:Exchange OWA访问出现502错误

Troubleshooting Apache 502 Bad Gateway for Exchange 2013 OWA Proxy

Let's dive into why you're seeing that 502 Bad Gateway error when proxying Exchange 2013 OWA through Apache. I’ve dealt with this exact scenario a few times, so here’s what to check and fix:

1. SSL Certificate Trust Issues Between Apache and Exchange

Apache needs to trust the SSL certificate installed on your Exchange server. If Exchange uses a self-signed cert, or the root CA for its cert isn’t in Apache’s trusted store, Apache will refuse the connection—triggering a 502.

  • Quick test (not for production): Add these lines to your VirtualHost config to temporarily bypass SSL verification (use this only to confirm the issue):
    SSLProxyVerify none
    SSLProxyCheckPeerCN off
    SSLProxyCheckPeerName off
    
  • Production fix: Export the root CA certificate from Exchange, then import it into Apache’s trusted certificate store (location varies by OS: /etc/ssl/certs/ on Debian/Ubuntu, /etc/pki/tls/certs/ on RHEL/CentOS).

2. Overly Broad ProxyPass Configuration

Your current config proxies the entire root path (/) to Exchange, which can cause conflicts with Apache’s default document root and may not play nicely with Exchange’s virtual directory structure. Instead, proxy only the specific Exchange paths you need.

  • Updated ProxyPass rules: Replace your existing ProxyPass/ProxyPassReverse lines with these:
    ProxyPass /owa https://192.168.1.50/owa
    ProxyPassReverse /owa https://192.168.1.50/owa
    ProxyPass /ecp https://192.168.1.50/ecp
    ProxyPassReverse /ecp https://192.168.1.50/ecp
    # Add other paths like /ews, /autodiscover if you need them
    

3. Missing Apache Modules

Double-check that you’ve enabled all required proxy and SSL modules. Without these, Apache can’t handle reverse proxying over HTTPS.

  • Debian/Ubuntu: Run these commands to enable modules and restart Apache:
    a2enmod proxy proxy_http ssl
    systemctl restart apache2
    
  • RHEL/CentOS: Verify modules are loaded with:
    httpd -M | grep -E 'proxy|ssl'
    
    If any are missing, edit /etc/httpd/conf.modules.d/00-proxy.conf and /etc/httpd/conf.modules.d/00-ssl.conf to enable them, then restart httpd.

4. Network Connectivity Problems

A 502 often means Apache can’t reach the Exchange server at all. Test this directly from the Apache server:

  • Run curl -v https://192.168.1.50/owa and check the output. If you see connection timeouts or "connection refused" errors:
    • Verify Exchange’s firewall allows incoming HTTPS (443) traffic from the Apache server’s IP.
    • Confirm there’s no routing issue between the two servers.

5. Fix Forwarded Protocol Headers

Exchange needs to know the original request came over HTTPS (not HTTP from the proxy). Add this line to your VirtualHost to set the correct header:

RequestHeader set X-Forwarded-Proto "https"

Full Working VirtualHost Example

Here’s a cleaned-up version of your config incorporating the fixes above:

<VirtualHost *:443>
ServerName my.domain.com
DocumentRoot /var/www/html
SSLEngine on
SSLProxyEngine on
SSLCertificateFile /var/www/certs/webmail.crt
SSLCertificateKeyFile /var/www/certs/webmail.key

# Trust Exchange's SSL cert (remove the bypass lines in production)
# SSLProxyVerify none
# SSLProxyCheckPeerCN off
# SSLProxyCheckPeerName off

ProxyRequests Off
ProxyPreserveHost on

# Tell Exchange the original request was HTTPS
RequestHeader set X-Forwarded-Proto "https"

# Proxy only necessary Exchange paths
ProxyPass /owa https://192.168.1.50/owa
ProxyPassReverse /owa https://192.168.1.50/owa
ProxyPass /ecp https://192.168.1.50/ecp
ProxyPassReverse /ecp https://192.168.1.50/ecp

ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined
</VirtualHost>

Pro Tip: Always check Apache’s error log (${APACHE_LOG_DIR}/error.log) first—it’ll give you specific details about why the 502 is happening (e.g., SSL handshake failures, connection timeouts).

内容的提问来源于stack exchange,提问作者T.G

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:16:07