You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Cloud Gateway对接Keycloak报No subject alternative names如何禁用校验?

开发环境禁用Keycloak SSL证书及SAN校验的可行方案

以下方案仅适用于开发环境,禁止在测试、生产等公开环境使用,避免出现安全风险:

方案1:Spring配置项直接关闭校验(最简方案)

高版本Spring Boot/Spring Cloud可以直接通过配置文件关闭SSL校验,无需修改代码:

  • 在application.yml或application.properties中加入以下配置:
spring:
  security:
    oauth2:
      resourceserver:
        jwt:
          issuer-uri: https://你的Keycloak地址/realms/你的realm名称
# 关闭网关层对外请求的SSL校验
server:
  ssl:
    verify: none
  • 适配版本:Spring Boot 2.7+、Spring Cloud 2021.0.0+

方案2:自定义HttpClient绕过SSL校验

如果低版本框架不支持配置关闭,可以手动构造跳过校验的WebClient注入到JWT解码器中:

  • 新增配置类,注册自定义的SSL跳过客户端:
import io.netty.handler.ssl.SslContextBuilder;
import io.netty.handler.ssl.util.InsecureTrustManagerFactory;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.http.client.reactive.ReactorClientHttpConnector;
import org.springframework.security.oauth2.jwt.NimbusReactiveJwtDecoder;
import org.springframework.security.oauth2.jwt.ReactiveJwtDecoder;
import org.springframework.web.reactive.function.client.WebClient;
import reactor.netty.http.client.HttpClient;

@Configuration
public class InsecureSslConfig {

    @Bean
    public WebClient insecureWebClient() throws Exception {
        // 构造信任所有证书的SSL上下文
        var sslContext = SslContextBuilder.forClient()
                .trustManager(InsecureTrustManagerFactory.INSTANCE)
                .build();
        // 构造跳过主机名/SAN校验的HttpClient
        var httpClient = HttpClient.create()
                .secure(sslSpec -> sslSpec.sslContext(sslContext)
                        .handlerConfigurator(handler -> handler.setHostnameVerifier((host, session) -> true)));
        return WebClient.builder()
                .clientConnector(new ReactorClientHttpConnector(httpClient))
                .build();
    }

    @Bean
    public ReactiveJwtDecoder reactiveJwtDecoder(WebClient insecureWebClient) {
        return NimbusReactiveJwtDecoder
                .withIssuerLocation("https://你的Keycloak地址/realms/你的realm名称")
                .webClient(insecureWebClient)
                .build();
    }
}

方案3:JVM参数全局关闭校验

不需要修改代码和配置,直接在服务启动时追加JVM参数即可全局关闭所有SSL校验:

  • 启动参数追加:
    -Dcom.sun.net.ssl.checkRevocation=false -Djdk.internal.httpclient.disableHostnameVerification=true
  • 注意:该参数会影响服务所有对外HTTPS请求的校验逻辑,仅适合纯本地开发场景使用。

内容的提问来源于stack exchange,提问作者Владислав Винокуров

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.29 08:45:03