Spring Cloud Gateway对接Keycloak报No subject alternative names如何禁用校验?
开发环境禁用Keycloak SSL证书及SAN校验的可行方案
以下方案仅适用于开发环境,禁止在测试、生产等公开环境使用,避免出现安全风险:
方案1:Spring配置项直接关闭校验(最简方案)
高版本Spring Boot/Spring Cloud可以直接通过配置文件关闭SSL校验,无需修改代码:
- 在
application.yml或application.properties中加入以下配置:
spring: security: oauth2: resourceserver: jwt: issuer-uri: https://你的Keycloak地址/realms/你的realm名称 # 关闭网关层对外请求的SSL校验 server: ssl: verify: none
- 适配版本:Spring Boot 2.7+、Spring Cloud 2021.0.0+
方案2:自定义HttpClient绕过SSL校验
如果低版本框架不支持配置关闭,可以手动构造跳过校验的WebClient注入到JWT解码器中:
- 新增配置类,注册自定义的SSL跳过客户端:
import io.netty.handler.ssl.SslContextBuilder; import io.netty.handler.ssl.util.InsecureTrustManagerFactory; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.http.client.reactive.ReactorClientHttpConnector; import org.springframework.security.oauth2.jwt.NimbusReactiveJwtDecoder; import org.springframework.security.oauth2.jwt.ReactiveJwtDecoder; import org.springframework.web.reactive.function.client.WebClient; import reactor.netty.http.client.HttpClient; @Configuration public class InsecureSslConfig { @Bean public WebClient insecureWebClient() throws Exception { // 构造信任所有证书的SSL上下文 var sslContext = SslContextBuilder.forClient() .trustManager(InsecureTrustManagerFactory.INSTANCE) .build(); // 构造跳过主机名/SAN校验的HttpClient var httpClient = HttpClient.create() .secure(sslSpec -> sslSpec.sslContext(sslContext) .handlerConfigurator(handler -> handler.setHostnameVerifier((host, session) -> true))); return WebClient.builder() .clientConnector(new ReactorClientHttpConnector(httpClient)) .build(); } @Bean public ReactiveJwtDecoder reactiveJwtDecoder(WebClient insecureWebClient) { return NimbusReactiveJwtDecoder .withIssuerLocation("https://你的Keycloak地址/realms/你的realm名称") .webClient(insecureWebClient) .build(); } }
方案3:JVM参数全局关闭校验
不需要修改代码和配置,直接在服务启动时追加JVM参数即可全局关闭所有SSL校验:
- 启动参数追加:
-Dcom.sun.net.ssl.checkRevocation=false -Djdk.internal.httpclient.disableHostnameVerification=true - 注意:该参数会影响服务所有对外HTTPS请求的校验逻辑,仅适合纯本地开发场景使用。
内容的提问来源于stack exchange,提问作者Владислав Винокуров
相关产品推荐
相关产品推荐

