Ubuntu环境下启用SSL后ProxyPass功能失效问题排查
Hey there, let’s walk through troubleshooting your SSL proxy issue step by step. You had a working HTTP proxy setup between your Web and App EC2 instances, but after switching to HTTPS (forcing 443) and creating a new proxy-ssl-host.conf, things broke. Let’s cover the most likely culprits and fixes:
1. Make Sure Apache’s SSL & Proxy Modules Are Enabled
First off, double-check that the necessary Apache modules are turned on—this is a super common oversight when switching to SSL. Run these commands on your Web server:
sudo a2enmod ssl sudo a2enmod proxy_http sudo a2enmod proxy
If any module was disabled, restart Apache to apply changes:
sudo systemctl restart apache2
2. Validate Your proxy-ssl-host.conf Configuration
Your new SSL proxy config needs specific directives to handle HTTPS and forward traffic to the App server. A solid baseline setup should look like this (swap in your actual domain, cert paths, and App server details):
return (<VirtualHost *:443> ServerName your-domain.com SSLEngine on SSLCertificateFile /path/to/your/ssl-cert.pem SSLCertificateKeyFile /path/to/your/private-key.pem # Proxy rules to route traffic to the App server ProxyPass /app-endpoint http://your-app-ec2-ip:app-port/ ProxyPassReverse /app-endpoint http://your-app-ec2-ip:app-port/ # Logs for debugging (critical for troubleshooting!) ErrorLog ${APACHE_LOG_DIR}/ssl-proxy-error.log CustomLog ${APACHE_LOG_DIR}/ssl-proxy-access.log combined </VirtualHost> )
Don’t forget to enable this config file with:
sudo a2ensite proxy-ssl-host.conf
Common mistakes here include:
- Missing the
SSLEngine online (Apache won’t enable SSL for this vhost without it) - Typing the wrong path to your SSL certificate/key (check file permissions too—Apache needs read access!)
- Mismatched
ProxyPassandProxyPassReverseroutes (these need to mirror each other to handle redirects correctly)
3. Check Ports.conf & HTTP-to-HTTPS Redirects
Your ports.conf must be set to listen on 443 for HTTPS. Confirm it has this line:
Listen 443 https
Also, make sure you’re redirecting all HTTP (port 80) traffic to HTTPS—otherwise users might hit broken HTTP routes, or your proxy might not handle the transition properly. Add this to your httpd.conf or a separate redirect vhost file:
return (<VirtualHost *:80> ServerName your-domain.com Redirect permanent / https://your-domain.com/ </VirtualHost> )
4. Verify EC2 Security Groups & Firewalls
Network issues are another big culprit here:
- On your Web EC2 instance: Ensure its security group allows inbound HTTPS (443) traffic from your client IP (or 0.0.0.0/0 if it’s a public site)
- On your App EC2 instance: Restrict inbound traffic to its service port only to the Web server’s private IP (no need to expose it publicly)
- On the Web server, check if ufw/iptables is blocking 443:
sudo ufw status
5. Test Direct Connectivity to the App Server
From your Web server, test if you can reach the App server directly (bypassing Apache proxy) using curl:
curl http://your-app-ec2-ip:app-port/your-test-page
If this fails, the problem is with network connectivity between the two instances—not your proxy config. Double-check route tables, security groups, or any internal firewalls on the App server.
6. Dig Into Apache Logs for Clues
When all else fails, the logs will tell you exactly what’s wrong. Check these files on your Web server:
tail -f /var/log/apache2/ssl-proxy-error.log tail -f /var/log/apache2/error.log
You’ll see errors like invalid cert paths, proxy timeouts, or missing modules—super helpful for narrowing down the issue.
If you’re still stuck, share the exact error message you’re getting (e.g., 503 Service Unavailable, SSL Handshake Failed) and the full content of your proxy-ssl-host.conf—that’ll help zero in on the problem faster!
内容的提问来源于stack exchange,提问作者OtagoHarbour

