核心是获取有效证书、启用SSL模块、配置虚拟主机并强制HTTP跳转HTTPS:先用Certbot申请Let’s Encrypt证书并自动配置,再确保Listen 443、启用a2enmod ssl与headers,配置SSLEngine on及证书路径,最后在80端口VirtualHost中添加Redirect permanent实现强制跳转。

从零开始在 Apache 中配置 HTTPS,核心是获取有效证书、启用 SSL 模块、配置虚拟主机并强制 HTTPS 访问。整个过程不依赖外部控制面板,纯手动操作,适用于 Ubuntu/Debian 或 CentOS/RHEL 系统。
准备 SSL 证书(推荐 Let’s Encrypt)
使用 Certbot 是最简单可靠的方式:
- 安装 Certbot 及 Apache 插件:
sudo apt install certbot python3-certbot-apache(Ubuntu/Debian)或sudo yum install certbot python3-certbot-apache(CentOS/RHEL 8+) - 确保域名已解析到服务器 IP,并且 Apache 已运行、站点可被公网访问(Certbot 需验证域名控制权)
- 一键申请并自动配置证书:
sudo certbot --apache -d example.com -d www.example.com
它会自动修改 Apache 配置、启用 HTTPS、设置自动续期
手动配置 SSL 模块与端口
若需自定义或使用其他证书(如商业证书),请确认以下基础项已启用:
- 启用 mod_ssl:
sudo a2enmod ssl(Debian/Ubuntu)或检查/etc/httpd/conf.modules.d/00-ssl.conf(RHEL/CentOS) - 确保防火墙放行 443 端口:
sudo ufw allow 443或sudo firewall-cmd --permanent --add-port=443/tcp - 监听 443 端口需在主配置中存在(通常
/etc/apache2/ports.conf已含Listen 443)
配置 HTTPS 虚拟主机
编辑站点配置文件(如 /etc/apache2/sites-available/example.com.conf),添加或替换为:
<virtualhost>
ServerName example.com
ServerAlias www.example.com
DocumentRoot /var/www/example.com
<pre class="brush:php;toolbar:false;">SSLEngine on
SSLCertificateFile /etc/letsencrypt/live/example.com/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/example.com/privkey.pem
SSLCertificateChainFile /etc/letsencrypt/live/example.com/chain.pem
# 推荐启用现代安全协议
SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:...
SSLHonorCipherOrder on
Apache Superset 是一个广泛采用的开源 BI 平台,用于 SQL 探索、图表构建和仪表板交付。当代理需要查询仓库数据、组装仪表板或使用成熟的分析界面解释指标而不是临时笔记本代码时,此技能非常有用。
注意:Let’s Encrypt 的 fullchain.pem 可替代 cert.pem + chain.pem 组合;若用商业证书,通常只需 SSLCertificateFile(证书)和 SSLCertificateKeyFile(私钥),中间证书按厂商说明放入 SSLCACertificateFile。
强制 HTTP 自动跳转 HTTPS
在对应站点的 *:80 虚拟主机中添加重定向规则:
<virtualhost>
ServerName example.com
ServerAlias www.example.com
Redirect permanent / https://example.com/
</virtualhost>
或在 *:443 块内补充 HSTS 头增强安全性:Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"(需先启用 headers 模块:sudo a2enmod headers)
完成配置后,执行 sudo apache2ctl configtest(Debian/Ubuntu)或 sudo httpd -t(RHEL/CentOS)验证语法,再重启服务:sudo systemctl restart apache2 或 sudo systemctl restart httpd。










