Apache2.4 RewriteRule 作为远程 Apache2.2 服务器的代理

Apache2.4 RewriteRule 作为远程 Apache2.2 服务器的代理

我们有一个带有 URL 的旧应用程序https://www2.devDocApp.com/ 正在Ubuntu8so 上运行,并且apache2.2不支持 TLS 1.2,我们apache2.2在 Ubuntu 8 机器上很难升级和使用 openSSL,所以现在我们使用的是代理apache服务器(devapp01带有 Apache/2.4.29(Win64)的 Windows 2012 VM),它将所有请求重定向到https://www2.devDocApp.com/

以下是我用来设置代理服务器的 apache 配置devapp01

<VirtualHost *:443>
Header always set Strict-Transport-Security "max-age=63072000; includeSubdomains; preload" 
DocumentRoot "C:/apache/htdocs"
ServerName  devapp01    
#ErrorLog "|bin/rotatelogs.exe -l -f C:/apache/logs/apache_error_log.%m-%d-%y-%I-%M-%S.log 86400"
#TransferLog "|bin/rotatelogs.exe -l -f C:/apache/logs/apache_transfer_log.%m-%d-%y-%I-%M-%S.log 86400"

SSLEngine on

#SSLProtocol -ALL +TLSv1 +TLSv1.1 +TLSv1.2 
#SSLHonorCipherOrder on
#SSLCipherSuite "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA+RC4 EECDH EDH+aRSA RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS"
#SSLCompression off

SSLProtocol -ALL TLSv1.2
SSLCertificateFile "C:/apache/conf/server.cer"
SSLCertificateKeyFile "C:/apache/conf/server.key"
#SSLCertificateChainFile "C:/apache/conf/server-ca.cer"
SSLCACertificateFile "C:/apache/conf/ca.cer"
SSLVerifyClient optional
SSLVerifyDepth  3

<FilesMatch "\.(cgi|shtml|phtml|php)$">
    SSLOptions +StdEnvVars
</FilesMatch>
<Directory "C:/apache/cgi-bin">
    SSLOptions +StdEnvVars
</Directory>

#CustomLog "|bin/rotatelogs.exe C:/apache/logs/ssl_request.%m-%d-%Y_%H_%M_%S.log 86400" \
#          "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"

ProxyRequests Off
<Proxy *>
Order deny,allow
Allow from all
</Proxy>
#ProxyPass should be prior to any other Proxy directives
ProxyPass   /DocApp https://www2.devDocApp.com/ 
SSLProxyEngine on

RewriteEngine On        
RewriteRule  ^/DocApp$  https://www2.devDocApp.com/  [R,L]  

RequestHeader set X_SSL_CLIENT_M_SERIAL "%{SSL_CLIENT_M_SERIAL}s"
RequestHeader set X_FORWARDED_PROTO "https" env=HTTPS
RequestHeader set SslSubject "%{SSL_CLIENT_S_DN}s"

</VirtualHost>

当我在浏览器中点击代理 apache URL 时,https://devapp01/DocApp/它会重定向到该 URL https://www2.devDocApp.com/,我该如何让它工作,使得浏览器中的 URL 始终适用 https://devapp01/DocApp/<Page>于所有嵌套路径,https://devapp01/DocApp/page1 https://devapp01/DocApp/page2/page1而不是重定向到https://www2.devDocApp.com/page1https://www2.devDocApp.com/page2

答案1

这将执行重定向:

RewriteEngine On        
RewriteRule  ^/DocApp$  https://www2.devDocApp.com/  [R,L]  

删除它。这ProxyPass已经起到作用了。

答案2

你应该用这种方式尝试代理

RewriteEngine  on
RewriteRule    "^DocApp/(.*)$"  "https://www2.devDocApp.com/DocApp/$1"  [P]
ProxyPassReverse "/DocApp/" "http://www2.devDocApp.com/DocApp/"

我们添加了一个 ProxyPassReverse 指令来确保后端发出的任何重定向都正确传递给客户端。

这里有更好的信息: https://httpd.apache.org/docs/2.4/rewrite/proxy.html

相关内容