HAproxy对接ADFS时根路径重定向到指定页面失败如何解决?
解决方案
核心错误点
你的配置问题出在重定向规则的目标地址缺少https://协议前缀,当前写法会被浏览器判定为相对路径,最终跳转地址会变成https://adfsstg.xxx.com/adfsstg.xxx.com/adfs/ls/IdpInitiatedSignOn.aspx,和预期不符。
额外建议:测试阶段优先使用302临时重定向,避免301永久重定向被浏览器缓存,导致后续配置修改后无法立即验证效果。
修改后的前端配置
frontend adfsstg bind 10.129.10.3:443 ssl crt /etc/ssl/certs/wildcard.pem mode http redirect scheme https if !{ ssl_fc } acl is_root path -i / # 两种写法二选一:硬编码域名或者动态取请求头的Host值适配多场景 # 写法1:固定域名 redirect code 302 location https://adfsstg.xxx.com/adfs/ls/IdpInitiatedSignOn.aspx if is_root # 写法2:动态适配域名,无需硬编码 # redirect code 302 location https://%[req.hdr(Host)]/adfs/ls/IdpInitiatedSignOn.aspx if is_root use_backend adfsstg
验证方法
配置修改完成后重载HAProxy服务,使用curl命令直接验证重定向规则是否生效:
curl -I https://adfsstg.xxx.com
正常返回结果中会包含Location: https://adfsstg.xxx.com/adfs/ls/IdpInitiatedSignOn.aspx字段,确认无误后可以把302改为301正式使用。
内容的提问来源于stack exchange,提问作者Marshall
相关产品推荐
相关产品推荐

