You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Apache Tomcat SSL后,如何隐藏8443端口访问站点

问题

当访问www.example.com时,Tomcat会重定向到www.example.com:8443并显示端口号,希望访问站点时不显示8443端口。当前环境为Tomcat 9.0.68,已部署应用并配置SSL使用8443端口,相关配置如下:

当前server.xml配置

<Connector port="80" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="8443" />

<Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150" SSLEnabled="true">
  <SSLHostConfig>
    <Certificate certificateFile="conf/cert.pem"
                 certificateKeyFile="conf/privkey.pem"
                 certificateChainFile="conf/chain.pem" />
  </SSLHostConfig>
</Connector>

当前web.xml配置

<security-constraint>
    <web-resource-collection>
        <web-resource-name>HTTPSOnly</web-resource-name>
        <url-pattern>/*</url-pattern>
    </web-resource-collection>
    <user-data-constraint>
        <transport-guarantee>CONFIDENTIAL</transport-guarantee>
    </user-data-constraint>
</security-constraint>
解决方案

方法一:将Tomcat SSL端口改为标准HTTPS端口443

HTTPS的默认端口是443,浏览器访问时会自动省略该端口,无需手动输入。操作步骤:

  1. 修改server.xml中的SSL Connector配置,将port="8443"改为port="443":
<Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150" SSLEnabled="true">
  <SSLHostConfig>
    <Certificate certificateFile="conf/cert.pem"
                 certificateKeyFile="conf/privkey.pem"
                 certificateChainFile="conf/chain.pem" />
  </SSLHostConfig>
</Connector>
  1. 同步修改HTTP Connector的redirectPort为443:
<Connector port="80" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="443" />
  1. 注意:Linux/Unix系统中,1024以下的端口(如443)需要root权限才能绑定。若不想用root启动Tomcat,可通过authbind工具授权Tomcat绑定443端口,或采用反向代理方案。

方法二:使用反向代理(如Nginx)处理端口转发

通过Nginx作为前端代理,接收80/443端口的请求并转发到Tomcat的8443端口,用户只会看到标准端口,不会暴露Tomcat的内部端口。示例Nginx配置:

server {
    listen 80;
    server_name www.example.com;
    # 将HTTP请求强制重定向到HTTPS
    return 301 https://$server_name$request_uri;
}

server {
    listen 443 ssl;
    server_name www.example.com;

    # SSL证书配置(路径需替换为实际证书路径)
    ssl_certificate /path/to/cert.pem;
    ssl_certificate_key /path/to/privkey.pem;
    ssl_trusted_certificate /path/to/chain.pem;

    # 转发请求到Tomcat的8443端口
    location / {
        proxy_pass https://localhost:8443;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

配置完成后重启Nginx,确保Tomcat正常运行,用户访问www.example.com时地址栏不会显示8443端口。

内容的提问来源于stack exchange,提问作者Volonter123

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 18:55:34