启用ssl模块并设置ssl证书后,Apache 2.4.9失败

Lip*_*ika 11 php ssl ssl-certificate apache2.4 osx-yosemite

尝试设置ssl证书后,Apache会抛出以下错误:

[ssl:emerg] [pid 30907] AH02572: Failed to configure at least one certificate and key for localhost:443
[ssl:emerg] [pid 30907] SSL Library Error: error:140A80B1:SSL routines:SSL_CTX_check_private_key:no certificate assigned
[ssl:emerg] [pid 30907] AH02312: Fatal error initialising mod_ssl, exiting.
Run Code Online (Sandbox Code Playgroud)

我使用MAC OS:Yosemite,PHP 5.5.20,Apache 2.4.9

并按照以下步骤从(http://www.akadia.com/services/ssh_test_certificate.html)生成我的ssl证书

cd /etc/apache2/
sudo mkdir certs                                        
cd certs                                                
sudo openssl genrsa -des3 -out server.key 1024          
sudo openssl req -new -key server.key -out server.csr

  Country Name (2 letter code) [GB]:US
  State or Province Name (full name) [Berkshire]:California 
  Locality Name (eg, city) [Newbury]:LA
  Organization Name (eg, company) [My Company Ltd]:Company
  Organizational Unit Name (eg, section) []:
  Common Name (eg, your name or your server's hostname) []:dev.test.local
  Email Address []:username@gmail.com
  Please enter the following 'extra' attributes
  to be sent with your certificate request
  A challenge password []:
  An optional company name []:

sudo cp server.key server.key.org     
sudo openssl rsa -in server.key.org -out server.key
sudo openssl x509 -req -days 730 -in server.csr -signkey server.key -out server.crt  
Run Code Online (Sandbox Code Playgroud)

接下来,我为我的apache配置文件设置了以下内容:

等/ apache2的/ httpd.conf中:

LoadModule ssl_module libexec/apache2/mod_ssl.so
LoadModule socache_shmcb_module libexec/apache2/mod_socache_shmcb.so
Include /private/etc/apache2/extra/httpd-ssl.conf
Run Code Online (Sandbox Code Playgroud)

等/ apache2的/额外/的httpd-ssl.conf中:

Listen 443
SSLPassPhraseDialog  builtin
<VirtualHost _default_:443>
SSLEngine on
Mutex sysvsem default # Added after seeing mutex issues for apache 2.4, http://stackoverflow.com/questions/13969272/apache-sslmutex-issue
Run Code Online (Sandbox Code Playgroud)

等/ apache2的/额外/的httpd-vhosts.conf:

<VirtualHost *:443>

    ServerName dev.test.local
    DocumentRoot "/Users/username/Sites/test/public"

    <Directory "/Users/username/Sites/test/public">
         Options Indexes FollowSymLinks MultiViews
         AllowOverride All
         Order allow,deny
         allow from all
    </Directory>

    SSLEngine on       
    SSLCertificateFile    /etc/apache2/certs/server.crt
    SSLCertificateKeyFile /etc/apache2/certs/server.key

</VirtualHost>
Run Code Online (Sandbox Code Playgroud)

重新启动并运行apache config test后,看起来好像没有问题:

sudo apachectl restart
sudo apachectl configtest
[Tue Jan 06 13:56:01.480270 2015] [so:warn] [pid 31636] AH01574: module php5_module is already loaded, skipping
Syntax OK
Run Code Online (Sandbox Code Playgroud)

非常感谢帮助,如果需要,我很乐意提供更多信息.

小智 5

我遇到了同样的问题。现在我解决了。

你包括

/private/etc/apache2/extra/httpd-ssl.conf 
Run Code Online (Sandbox Code Playgroud)

在 httpd.conf 中。

所以你仍然需要在'httpd-ssl.conf'中设置以下键

SSLCertificateFile "path to your crt"
SSLCertificateKeyFile "path to your key"
Run Code Online (Sandbox Code Playgroud)

希望它有帮助。


小智 5

我今天在升级到 MacOS High Sierra 10.13.6 版后遇到了这个问题。在升级之前,我的带有 SSL 的虚拟主机运行良好。然后今天,当我尝试启动 Apache Web 服务器时,出现以下错误:

[Fri Jul 20 10:51:06.021778 2018] [ssl:emerg] [pid 2236] AH02572: Failed to configure at least one certificate and key for work.localweb.com:80
[Fri Jul 20 10:51:06.022024 2018] [ssl:emerg] [pid 2236] SSL Library Error: error:140A80B1:SSL routines:SSL_CTX_check_private_key:no certificate assigned
[Fri Jul 20 10:51:06.022037 2018] [ssl:emerg] [pid 2236] AH02312: Fatal error initialising mod_ssl, exiting.
AH00016: Configuration Failed
Run Code Online (Sandbox Code Playgroud)

检查我的 apache 版本,现在是 2.4.33。显然,在此版本中,您需要将 SSLCertificateFile 和 SSLCertificateKeyFile 条目放在虚拟主机本身中。因此,我从 extra/httpd-ssl.conf 复制了条目并将其放入我配置的每个 SSL 虚拟主机中。

<VirtualHost *:443>
  ServerAdmin me@mymail.com
  ServerName work.localweb.com
  SSLCertificateFile "/private/etc/apache2/server.crt"
  SSLCertificateKeyFile "/private/etc/apache2/server.key"
  ......
</VirtualHost>
Run Code Online (Sandbox Code Playgroud)

然后启动再次工作。