Apache默认支持SNI,需满足:OpenSSL≥1.0.2、mod_ssl已加载、未启用SSLStrictSNIVHostCheck on;每个域名须独立配置<VirtualHost *:443>并内嵌完整SSL指令,ServerName须匹配证书SAN,且全局配置含Listen 443和ssl_module。
确认 Apache 已启用 SNI 支持
apache 本身不额外“开启 sni”,它依赖底层 openssl 的能力。只要满足以下三点,sni 就默认可用:
- 使用的 OpenSSL 版本 ≥ 1.0.2(推荐 ≥ 1.1.1);
-
mod_ssl.so 已正确加载(检查
httpd -M | findstr ssl或apachectl -M | grep ssl); - 配置中未设置
SSLStrictSNIVHostCheck on(该指令应放在<VirtualHost>外,且通常保持默认off)。
Windows 下特别注意:libcrypto-1_1-x64.dll 和 libssl-1_1-x64.dll 必须存在于 Apache 的 bin/ 目录,否则 mod_ssl 加载失败,SNI 无法工作。
每个域名一个独立的 <VirtualHost *:443> 块
SNI 要求每个 HTTPS 域名对应一个显式、完整的虚拟主机定义,不能共用证书路径,也不能靠 ServerAlias 堆叠多个域名到同一个块里。模板如下:
<VirtualHost *:443>
ServerName example.com
ServerAlias www.example.com
DocumentRoot "D:/www/example"
SSLEngine on
SSLCertificateFile "D:/ssl/example.crt"
SSLCertificateKeyFile "D:/ssl/example.key"
SSLCertificateChainFile "D:/ssl/example.chain"
<Directory "D:/www/example">
Require all granted
</Directory>
</VirtualHost>
关键点:
-
ServerName必须是该证书 SAN 中明确包含的主域名; -
ServerAlias可添加同证书覆盖的其他域名(如 www); -
SSLCertificateFile推荐使用 Let’s Encrypt 的fullchain.pem(含证书+中间链),此时无需SSLCertificateChainFile; - 所有 SSL 指令必须写在该块内,不可提至全局或父级作用域。
全局与端口监听基础配置
确保主配置文件(如 httpd.conf)中包含以下内容,且未被注释:
Listen 443 LoadModule ssl_module modules/mod_ssl.so Include conf/extra/httpd-ssl.conf
其中 httpd-ssl.conf 至少需保证有:
Apache Superset 是一个广泛采用的开源 BI 平台,用于 SQL 探索、图表构建和仪表板交付。当代理需要查询仓库数据、组装仪表板或使用成熟的分析界面解释指标而不是临时笔记本代码时,此技能非常有用。
<IfModule ssl_module>
SSLRandomSeed startup builtin
SSLRandomSeed connect builtin
</IfModule>
注意:SSLStrictSNIVHostCheck off 应放在所有 <VirtualHost> 外(例如放在 httpd-ssl.conf 开头),否则会导致非匹配域名请求被拒绝。
验证 SNI 是否生效
配置完成后重启 Apache,用以下命令逐个测试各域名是否返回对应证书:
openssl s_client -connect example.com:443 -servername example.com -showcerts < /dev/null 2>/dev/null | openssl x509 -noout -text | grep -A1 "Subject Alternative Name"
Windows 用户可用:
echo Q | openssl s_client -connect example.com:443 -servername example.com | findstr "subject\|DNS"
若输出中显示的 DNS 名称与请求域名一致,说明 SNI 绑定成功;若始终返回第一个 <VirtualHost *:443> 的证书,则需检查块顺序、ServerName 拼写及证书 SAN 字段。

















