You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Apache2服务器上正确配置多域名SSL证书(先部署主域名)

Fixing Apache SSL Configuration for Your Multi-Domain Certificate (Main Domain Only)

Let's get your SSL setup sorted for maindomain.com using that multi-domain certificate you purchased. I'll walk you through each file you mentioned, plus a few critical checks to resolve your configuration issues:

Step 1: Securely Place Your Certificate Files

First, move your certificate files to Apache's standard SSL directories (this avoids permission headaches):

  • Copy 115155984.crt to /etc/ssl/certs/
  • Copy 115155984.ca-bundle to /etc/ssl/certs/
  • Make sure your private key file (e.g., maindomain.key) is in /etc/ssl/private/ and locked down with tight permissions:
    chmod 600 /etc/ssl/private/maindomain.key
    chown root:www-data /etc/ssl/private/maindomain.key
    

Step 2: Update ports.conf

Ensure Apache is listening on port 443 for HTTPS traffic. Open /etc/apache2/ports.conf and verify these lines exist:

Listen 80
Listen 443 https

Step 3: Verify Global SSL Settings in apache2.conf

Check that the SSL module is loaded and basic security settings are configured. Add or update this block if missing:

<IfModule ssl_module>
    # Disable outdated protocols for security
    SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
    # Use strong cipher suites
    SSLCipherSuite HIGH:!aNULL:!MD5:!3DES
    SSLHonorCipherOrder on
    SSLCompression off
    SSLSessionTickets on
</IfModule>

Also confirm the SSL module is enabled with:

a2enmod ssl

Step 4: Configure the Virtual Host in maindomain.com.conf

This is where most issues crop up. Replace your existing config with this tailored setup (adjust paths to match your server):

# Redirect HTTP to HTTPS
<VirtualHost *:80>
    ServerName maindomain.com
    ServerAlias www.maindomain.com
    Redirect permanent / https://maindomain.com/
</VirtualHost>

# HTTPS Virtual Host
<VirtualHost *:443>
    ServerName maindomain.com
    ServerAlias www.maindomain.com

    # Basic site settings (update these to your actual paths)
    DocumentRoot /var/www/maindomain.com/public_html
    ErrorLog ${APACHE_LOG_DIR}/maindomain.com-error.log
    CustomLog ${APACHE_LOG_DIR}/maindomain.com-access.log combined

    # SSL Certificate Configuration
    SSLEngine on
    SSLCertificateFile /etc/ssl/certs/115155984.crt
    SSLCertificateKeyFile /etc/ssl/private/maindomain.key  # Replace with your private key path
    SSLCertificateChainFile /etc/ssl/certs/115155984.ca-bundle
</VirtualHost>

Step 5: Test and Apply Changes

Before restarting, validate your config to catch syntax errors:

apache2ctl configtest

If you see Syntax OK, enable the site (if not already done) and restart Apache:

a2ensite maindomain.com.conf
systemctl restart apache2

Key Notes

  • Since this is a multi-domain certificate, you can add sitea.com and siteb.com later by updating the ServerAlias line or creating separate virtual hosts—no need to reissue the certificate.
  • If you still get errors, check Apache's error logs (/var/log/apache2/error.log) for specific details (e.g., missing files, permission issues).

内容的提问来源于stack exchange,提问作者mlclm

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:20:28