配置Apache Tomcat SSL后,如何隐藏8443端口访问站点
问题
当访问www.example.com时,Tomcat会重定向到www.example.com:8443并显示端口号,希望访问站点时不显示8443端口。当前环境为Tomcat 9.0.68,已部署应用并配置SSL使用8443端口,相关配置如下:
当前server.xml配置
<Connector port="80" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="8443" /> <Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxThreads="150" SSLEnabled="true"> <SSLHostConfig> <Certificate certificateFile="conf/cert.pem" certificateKeyFile="conf/privkey.pem" certificateChainFile="conf/chain.pem" /> </SSLHostConfig> </Connector>
当前web.xml配置
<security-constraint> <web-resource-collection> <web-resource-name>HTTPSOnly</web-resource-name> <url-pattern>/*</url-pattern> </web-resource-collection> <user-data-constraint> <transport-guarantee>CONFIDENTIAL</transport-guarantee> </user-data-constraint> </security-constraint>
解决方案
方法一:将Tomcat SSL端口改为标准HTTPS端口443
HTTPS的默认端口是443,浏览器访问时会自动省略该端口,无需手动输入。操作步骤:
- 修改
server.xml中的SSL Connector配置,将port="8443"改为port="443":
<Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxThreads="150" SSLEnabled="true"> <SSLHostConfig> <Certificate certificateFile="conf/cert.pem" certificateKeyFile="conf/privkey.pem" certificateChainFile="conf/chain.pem" /> </SSLHostConfig> </Connector>
- 同步修改HTTP Connector的
redirectPort为443:
<Connector port="80" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="443" />
- 注意:Linux/Unix系统中,1024以下的端口(如443)需要root权限才能绑定。若不想用root启动Tomcat,可通过
authbind工具授权Tomcat绑定443端口,或采用反向代理方案。
方法二:使用反向代理(如Nginx)处理端口转发
通过Nginx作为前端代理,接收80/443端口的请求并转发到Tomcat的8443端口,用户只会看到标准端口,不会暴露Tomcat的内部端口。示例Nginx配置:
server { listen 80; server_name www.example.com; # 将HTTP请求强制重定向到HTTPS return 301 https://$server_name$request_uri; } server { listen 443 ssl; server_name www.example.com; # SSL证书配置(路径需替换为实际证书路径) ssl_certificate /path/to/cert.pem; ssl_certificate_key /path/to/privkey.pem; ssl_trusted_certificate /path/to/chain.pem; # 转发请求到Tomcat的8443端口 location / { proxy_pass https://localhost:8443; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
配置完成后重启Nginx,确保Tomcat正常运行,用户访问www.example.com时地址栏不会显示8443端口。
内容的提问来源于stack exchange,提问作者Volonter123
相关产品推荐
相关产品推荐

