Apache selects an HTTPS virtual host in two stages: first by the connection’s IP address and port, then by the requested hostname within that matching group. If no ServerName or ServerAlias matches, Apache uses the first virtual host listed for that address and port.
Last updated: October 4, 2026.
<VirtualHost *:443>
ServerName app.example.com
ServerAlias www.app.example.com
SSLEngine on
SSLCertificateFile "C:/Apache24/conf/certs/app.crt"
SSLCertificateKeyFile "C:/Apache24/conf/certs/app.key"
ProxyPass / http://127.0.0.1:8080/
ProxyPassReverse / http://127.0.0.1:8080/
</VirtualHost>Put every hostname that should reach this site in ServerName or ServerAlias. Keep competing HTTPS hosts on the same address expression and port, and give each host the certificate and proxy settings intended for it.
Verify what Apache actually loaded
Run httpd -S from the same installation used by the service. Confirm that the expected configuration file is loaded, the virtual host appears under *:443 or the intended IP, and the displayed default is understood. A clean syntax check does not prove that DNS points to this server or that the request arrived on the address group you inspected.
Apache’s name-based virtual host documentation explains that IP-and-port selection happens before name matching and that the first listed virtual host is used when no name matches.
Test DNS, SNI, and the request hostname
Resolve the hostname from the client network and verify that it reaches the expected server. Test the TLS endpoint with openssl s_client -connect server-ip:443 -servername app.example.com; the -servername value supplies SNI. Then send a normal HTTPS request using the real hostname so both SNI and the HTTP Host header agree. Test the hostname itself rather than browsing directly to the IP address, which does not represent the normal name-based request.
Specify ServerName explicitly in every virtual host; the same Apache guide warns that inherited names can produce unexpected matching. After every change, run the syntax check, restart or reload the intended Apache service, and repeat httpd -S. If a reverse proxy sits in front of Apache, confirm that its TLS and host-routing configuration is not selecting the site first. Certificate configuration is described in the official mod_ssl FAQ. For adjacent checks, see certificate-chain troubleshooting, encrypted connections, and tenant-safe background processing.