You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Jetty 11搭建的HTTP/3 Server无响应问题求助

Jetty 11 HTTP/3测试服务器无法正常响应的调整方案

问题背景

基于Jetty 11和Java 11搭建HTTP/3测试服务器,代码参考官方文档实现,服务器启动无报错,但Chrome访问https://localhost:3443/无响应,服务器无访问日志记录。相关信息如下:

实现代码

public class HTTP3Server {
    public static void main(String[] args) {
        Server server = new Server();

        // The SSL Context
        SslContextFactory.Server sslContextFactory = new SslContextFactory.Server();
        sslContextFactory.setKeyStorePath("/etc/java/keystore.jks");
        sslContextFactory.setKeyStorePassword("password");

        // The HTTP configuration object
        HttpConfiguration httpConfig = new HttpConfiguration();
        SecureRequestCustomizer src = new SecureRequestCustomizer();
        src.setSniHostCheck(false);
        httpConfig.addCustomizer(src);

        // Create and configure the HTTP/3 connector.
        HTTP3ServerConnectionFactory h3Factory = new HTTP3ServerConnectionFactory(httpConfig);
        HTTP3ServerConnector connector = new HTTP3ServerConnector(server, sslContextFactory, h3Factory);
        connector.setPort(3443);
        server.addConnector(connector);

        // Create and configure a ResourceHandler.
        ResourceHandler handler = new ResourceHandler();

        // Configure the directory where static resources are located.
        handler.setBaseResource(Resource.newResource("/var/www/"));

        // Configure directory listing.
        handler.setDirectoriesListed(false);

        // Configure welcome files.
        handler.setWelcomeFiles(new String[]{"index.html"});

        // Configure whether to accept range requests.
        handler.setAcceptRanges(true);
        server.setHandler(handler);

        // Start server
        server.start();
    }
}

环境与状态信息

  • 密钥库在HTTP/1.1、HTTP/2环境可正常使用
  • /var/www/index.html文件存在
  • 服务器启动日志(无警告/错误):
2023-05-25 10:31:06.305:INFO :oejs.Server:main: jetty-11.0.15; built: 2023-04-11T18:37:53.775Z; git: 5bc5e562c8d05c5862505aebe5cf83a61bdbcb96; jvm 11.0.19+7-post-Ubuntu-0ubuntu122.04.1
2023-05-25 10:31:06.338:INFO :oejhs.HTTP3ServerConnector:main: HTTP/3+QUIC support is experimental and not suited for production use.
2023-05-25 10:31:06.623:INFO :oejus.SslContextFactory:main: x509=X509@4af0df05(localhost,h=[icl test],a=[],w=[]) for Server@674bd420[provider=null,keyStore=file:///etc/java/keystore.jks,trustStore=null]
2023-05-25 10:31:06.661:INFO :oejs.AbstractConnector:main: Started HTTP3ServerConnector@4bd31064{h3, (h3)}{0.0.0.0:3443}
2023-05-25 10:31:06.733:INFO :oejs.Server:main: Started Server@30c93896{STARTING}[11.0.15,sto=0] @1189ms
  • UDP 3443端口状态为open|filtered,TCP 3443端口关闭

调整方案

1. 补充服务器线程等待逻辑

当前代码仅调用server.start(),主线程启动后直接退出,导致服务器进程终止。需在启动代码后添加线程等待:

// 启动后添加以下代码,让主线程等待Jetty服务线程
server.join();

2. 开启Chrome的HTTP/3支持

Chrome默认未启用HTTP/3实验特性,需手动开启:

  • 地址栏输入chrome://flags/#enable-quic
  • 将Experimental QUIC protocol设置为Enabled
  • 重启浏览器

3. 验证SSL证书的QUIC兼容性

HTTP/3依赖QUIC协议,需确保证书满足:

  • 证书包含访问域名(如localhost)的SAN(Subject Alternative Name)字段
  • 若使用自签名证书,需在Chrome中导入信任:
    1. 打开chrome://settings/certificates
    2. 切换到Authorities标签,导入密钥库导出的证书并设置信任

4. 确保UDP端口可正常访问

open|filtered状态可能是防火墙限制导致UDP包无法到达:

  • 临时关闭服务器端防火墙(如sudo ufw disable),或添加UDP端口放行规则:
    sudo ufw allow 3443/udp
    
  • 用nc工具测试连通性:
    服务器端执行nc -ul 3443,客户端执行nc -u localhost 3443,能收发数据则端口正常

5. 添加HTTP/1.1回退连接器(可选验证)

为确认资源处理逻辑无问题,可同时添加HTTP/1.1的HTTPS连接器:

// 添加HTTP/1.1的HTTPS连接器
HttpConnectionFactory http11Factory = new HttpConnectionFactory(httpConfig);
SslConnectionFactory sslFactory = new SslConnectionFactory(sslContextFactory, http11Factory.getProtocol());
ServerConnector httpConnector = new ServerConnector(server, sslFactory, http11Factory);
httpConnector.setPort(8443);
server.addConnector(httpConnector);

访问https://localhost:8443/,若能正常返回页面,说明问题集中在HTTP3/QUIC层。


内容的提问来源于stack exchange,提问作者lepe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 22:53:08