Tomcat8配置http://8080转https://8443失败,实际定向至https://8080
Tomcat 8 HTTP转HTTPS重定向端口错误问题
问题现象
配置将http://server:8080重定向至https://server:8443,但实际出现http://server:8080被重定向到https://server:8080的异常。清理浏览器缓存后首次访问正常,再次访问则错误复现。
已配置的文件如下:
conf/server.xml
<Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="8443" maxPostSize="8388608" /> <Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxThreads="150" SSLEnabled="true" scheme="https" secure="true" clientAuth="false" sslProtocol="TLS" maxPostSize="8388608" ... Certificate settings... URIEncoding="UTF-8" compression="force" compressableMimeType="text/html,text/xml,text/plain,text/javascript,text/css"/>
conf/web.xml
<security-constraint> <web-resource-collection> <web-resource-name>server</web-resource-name> <url-pattern>/*</url-pattern> </web-resource-collection> <user-data-constraint> <transport-guarantee>CONFIDENTIAL</transport-guarantee> </user-data-constraint> </security-constraint>
解决方案
方案1:替换security-constraint为自定义Filter(更可控)
用自定义Servlet Filter手动处理重定向,规避Tomcat内置逻辑的端口识别问题:
- 创建重定向Filter类:
public class HttpsRedirectFilter implements Filter { @Override public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException { HttpServletRequest req = (HttpServletRequest) request; HttpServletResponse res = (HttpServletResponse) response; if (!req.isSecure()) { // 构造正确的HTTPS地址 String redirectUrl = String.format("https://%s:8443%s", req.getServerName(), req.getRequestURI()); if (req.getQueryString() != null) { redirectUrl += "?" + req.getQueryString(); } // 使用302临时重定向,避免浏览器缓存错误地址 res.sendRedirect(redirectUrl); } else { chain.doFilter(request, response); } } @Override public void init(FilterConfig filterConfig) throws ServletException {} @Override public void destroy() {} }
- 在
web.xml中注册Filter(替换原有的security-constraint):
<filter> <filter-name>HttpsRedirectFilter</filter-name> <filter-class>你的包路径.HttpsRedirectFilter</filter-class> </filter> <filter-mapping> <filter-name>HttpsRedirectFilter</filter-name> <url-pattern>/*</url-pattern> </filter-mapping>
方案2:调整Tomcat Connector配置
若坚持使用security-constraint,补充以下配置:
- 在HTTP Connector中显式指定
scheme="http":
<Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="8443" scheme="http" maxPostSize="8388608" />
- 在HTTPS Connector中添加
proxyPort="8443":
<Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxThreads="150" SSLEnabled="true" scheme="https" secure="true" proxyPort="8443" clientAuth="false" sslProtocol="TLS" maxPostSize="8388608" ... Certificate settings... URIEncoding="UTF-8" compression="force" compressableMimeType="text/html,text/xml,text/plain,text/javascript,text/css"/>
方案3:禁用浏览器缓存重定向响应
在HTTP Connector中添加sendRedirectBody="false",减少浏览器错误缓存重定向地址的概率:
<Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="8443" sendRedirectBody="false" maxPostSize="8388608" />
内容的提问来源于stack exchange,提问作者Chris M
相关产品推荐
相关产品推荐

