【问题标题】:Forward Apache ssl port 443 to Tomcat http port将 Apache ssl 端口 443 转发到 Tomcat http 端口
【发布时间】:2019-04-19 09:55:26
【问题描述】:

我的 tomcat 在我的 linux 机器上独立运行,端口为 7778。我已将 apache 配置为在端口 443 上的 ssl 上运行。

我的 httpd.conf 如下:

    Listen 80
<VirtualHost *:80>
    ServerName www.domain.com
    Redirect / https://www.example.com
</VirtualHost> -->
ProxyPass         /  http://localhost:7778/website
ProxyPassReverse  /  http://localhost:7778/website

我的 ssl.conf 如下:

Listen 443
<VirtualHost _default_:443>
SSLEngine on
SSLCertificateFile    /path/to/certificate/file
SSLCertificateKeyFile /path/to/key
</VirtualHost>

我的 server.xml 连接器如下:

<Connector port="7778" protocol="HTTP/1.1"
                proxyName="www.domain.com" proxyPort="80" />

问题是我的 Apache 无法在 7778 端口上重定向到 Tomcat 并给出 503 错误。

【问题讨论】:

  • 为什么不能在应用上直接使用 443?
  • 尝试在 VirtualHost 中移动 ProxyPass 指令

标签: apache ssl tomcat8 proxypass


【解决方案1】:

两步:

1首先确认你的Tomcat没问题。

确保您可以连接到http://localhost:7778/website 并获得预期的响应。

然后,为了代理支持修改你的连接器:

<Connector port="7778" protocol="HTTP/1.1" proxyName="www.example.com" proxyPort="80" />

2修复您的 Apache 配置

这里我假设:

  • 当您尝试http://www.example.com 时,您将被重定向到https://www.example.com
  • 当您尝试https://www.example.com 时,您会收到来自 Tomcat 的响应

    Listen 80
    <VirtualHost *:80>
        ServerName www.example.com
        ServerAlias example.com
    
        CustomLog "logs/80_access.log" combined
        ErrorLog  "logs/80_error.log"
    
        Redirect / https://www.example.com
    </VirtualHost>
    
    <VirtualHost *:443>
        ServerName www.example.com
        ServerAlias example.com
    
        # While debugging
        LogLevel debug
        CustomLog "logs/443_access.log" combined
        ErrorLog  "logs/443_error.log"
    
        SSLEngine On
        SSLCertificateFile    /path/to/certificate/file
        SSLCertificateKeyFile /path/to/key
    
        # Proxy to Tomcat
        ProxyRequests Off
        ProxyPass        / http://localhost:7778/website
        ProxyPassReverse / http://localhost:7778/website
    
    </VirtualHost>
    

您可能需要调整的内容

  • 日志文件目录
  • 证书文件目录
  • Lo​​gLevel,调试模式一旦工作就移除
  • 确保已加载所需的模块。 apachectl -t 会通知您是否遗漏任何内容。

【讨论】:

    猜你喜欢
    • 2010-10-29
    • 2012-07-24
    • 2015-08-07
    • 2015-05-12
    • 2013-05-24
    • 1970-01-01
    • 2017-10-07
    • 1970-01-01
    • 2013-10-29
    相关资源
    最近更新 更多