如何在Apache2服务器上正确配置多域名SSL证书(先部署主域名)
Let's get your SSL setup sorted for maindomain.com using that multi-domain certificate you purchased. I'll walk you through each file you mentioned, plus a few critical checks to resolve your configuration issues:
Step 1: Securely Place Your Certificate Files
First, move your certificate files to Apache's standard SSL directories (this avoids permission headaches):
- Copy
115155984.crtto/etc/ssl/certs/ - Copy
115155984.ca-bundleto/etc/ssl/certs/ - Make sure your private key file (e.g.,
maindomain.key) is in/etc/ssl/private/and locked down with tight permissions:chmod 600 /etc/ssl/private/maindomain.key chown root:www-data /etc/ssl/private/maindomain.key
Step 2: Update ports.conf
Ensure Apache is listening on port 443 for HTTPS traffic. Open /etc/apache2/ports.conf and verify these lines exist:
Listen 80 Listen 443 https
Step 3: Verify Global SSL Settings in apache2.conf
Check that the SSL module is loaded and basic security settings are configured. Add or update this block if missing:
<IfModule ssl_module> # Disable outdated protocols for security SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 # Use strong cipher suites SSLCipherSuite HIGH:!aNULL:!MD5:!3DES SSLHonorCipherOrder on SSLCompression off SSLSessionTickets on </IfModule>
Also confirm the SSL module is enabled with:
a2enmod ssl
Step 4: Configure the Virtual Host in maindomain.com.conf
This is where most issues crop up. Replace your existing config with this tailored setup (adjust paths to match your server):
# Redirect HTTP to HTTPS <VirtualHost *:80> ServerName maindomain.com ServerAlias www.maindomain.com Redirect permanent / https://maindomain.com/ </VirtualHost> # HTTPS Virtual Host <VirtualHost *:443> ServerName maindomain.com ServerAlias www.maindomain.com # Basic site settings (update these to your actual paths) DocumentRoot /var/www/maindomain.com/public_html ErrorLog ${APACHE_LOG_DIR}/maindomain.com-error.log CustomLog ${APACHE_LOG_DIR}/maindomain.com-access.log combined # SSL Certificate Configuration SSLEngine on SSLCertificateFile /etc/ssl/certs/115155984.crt SSLCertificateKeyFile /etc/ssl/private/maindomain.key # Replace with your private key path SSLCertificateChainFile /etc/ssl/certs/115155984.ca-bundle </VirtualHost>
Step 5: Test and Apply Changes
Before restarting, validate your config to catch syntax errors:
apache2ctl configtest
If you see Syntax OK, enable the site (if not already done) and restart Apache:
a2ensite maindomain.com.conf systemctl restart apache2
Key Notes
- Since this is a multi-domain certificate, you can add
sitea.comandsiteb.comlater by updating theServerAliasline or creating separate virtual hosts—no need to reissue the certificate. - If you still get errors, check Apache's error logs (
/var/log/apache2/error.log) for specific details (e.g., missing files, permission issues).
内容的提问来源于stack exchange,提问作者mlclm

