apache开启ocsp stapling需同时配置sslstapling on和sslstaplingcache shmcb路径,确保mod_ssl已加载、证书链完整、中间证书含有效ocsp uri,且缓存路径存在并具写权限;验证须用openssl s_client -status命令确认返回“successful (0x0)”。
apache 的 mod_ssl 支持 ocsp 装订(ocsp stapling),但默认不启用,需手动配置。开启后,服务器会在 tls 握手时主动提供证书状态响应,提升性能并保护用户隐私。
确认环境与依赖
确保满足以下前提:
- Apache 版本 ≥ 2.3.3(推荐 2.4.8+);运行
apache2 -v或httpd -v查看版本 -
mod_ssl已加载:执行apachectl -M | grep ssl,应看到ssl_module (shared) - 证书链完整:必须提供服务器证书 + 中间证书(合并为一个文件或用
SSLCertificateChainFile指定) - 根 CA 证书可访问:OCSP 响应验证需要信任的根证书,通常由系统 CA 存储提供;若不可靠,可显式指定
SSLStaplingCache并确保路径正确
启用 OCSP Stapling 的核心配置
在 HTTPS 虚拟主机(<virtualhost></virtualhost>)内添加以下指令:
-
SSLStapling on:启用装订功能(必须) -
SSLStaplingCache "shmcb:/var/run/apache2/stapling_cache(128000)":定义共享内存缓存。路径需存在且 Apache 有写权限;Ubuntu/Debian 默认目录是/var/run/apache2/,CentOS/RHEL 常用/var/run/httpd/ -
SSLUseStapling on(旧版 Apache 2.4.7 及以前):部分老版本需此指令替代SSLStapling;新版统一用SSLStapling即可
示例片段:
<virtualhost><br> ServerName example.com<br> SSLEngine on<br> SSLCertificateFile /etc/ssl/certs/example.com.crt<br> SSLCertificateKeyFile /etc/ssl/private/example.com.key<br> SSLCertificateChainFile /etc/ssl/certs/intermediate.pem<br> SSLStapling on<br> SSLStaplingCache "shmcb:/var/run/apache2/stapling_cache(128000)"<br></virtualhost>
验证是否生效
重启 Apache 后,用 OpenSSL 命令检查:
openssl s_client -connect example.com:443 -status -servername example.com 2>&1 | grep -i "OCSP response"
若输出中包含 OCSP Response Status: successful (0x0) 和有效时间戳,说明装订已成功返回。注意:-servername 参数必须与证书域名一致,否则可能因 SNI 不匹配导致失败。
常见问题处理
-
“stapling_unknown” 或无 OCSP 响应:检查中间证书是否完整(缺失会导致无法定位 OCSP URL);可用
openssl x509 -in cert.pem -text -noout | grep OCSP确认证书含有效Authority Information Access字段 -
缓存路径报错(Permission denied):确保
/var/run/apache2/目录存在、属主为www-data(Ubuntu)或apache(CentOS),权限为755 -
SELinux 阻止写入缓存(CentOS/RHEL):运行
setsebool -P httpd_can_network_connect 1并确认httpd_can_network_connect_db等相关布尔值未误关











