Bonjour,
tu peux nous montrer ton fichier de configuration apache ?
J’utilise ce genre de config, dans des cas similaires:
<VirtualHost *:80>
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule (.*) https://%{HTTP_HOST}%{REQUEST_URI}
</VirtualHost>
<VirtualHost *:443>
ServerAdmin blabla
ServerSignature off
Documentroot /var/www
RewriteEngine On
RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)
RewriteRule .* - [F]
ProxyRequests Off
ProxyPreserveHost On
SSLProxyEngine On
RequestHeader set X-Forwarded-Protocol "https"
Header edit Location ^http://(.*)$ https://$1
ProxyPass /app1 http://localhost:port_app1
ProxyPassReverse /app1 http://localhost:port_app1
<Location /app1>
# toutes directives utiles pour l'appli
Order deny,allow
Allow from all
</Location>
ProxyPass /app2 http://localhost:port_app2
ProxyPassReverse /app2 http://localhost:port_app2
<Location /app1>
# toutes directives utiles pour l'appli 2
Order deny,allow
Allow from all
</Location>
SSLEngine On
SSLCertificateFile blablabla
SSLCertificateKeyFile blablabla
SSLCertificateChainFile blablabla
# HSTS (mod_headers is required) (15768000 seconds = 6 months)
Header always set Strict-Transport-Security "max-age=15768000"
ErrorLog /var/log/apache2/blabla.com.log
LogLevel warn
CustomLog /var/log/apache2/blabla.com.log combined
</VirtualHost>
# modern configuration, tweak to your needs
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256
SSLHonorCipherOrder on
SSLCompression off
SSLSessionTickets off
# OCSP Stapling, only in httpd 2.3.3 and later
SSLUseStapling on
SSLStaplingResponderTimeout 5
SSLStaplingReturnResponderErrors off
SSLStaplingCache shmcb:/var/run/ocsp(128000)
Il faut activer les modules rewrite, ssl et proxy