You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2 5.9配置端口443反向代理时自定义配置被覆盖问题咨询

Fixing ProxyPort Override Issue in WSO2 Identity Server 5.9

I’ve dealt with this exact headache before—WSO2’s configuration system overwrites manual edits to catalina-server.xml because it generates that file dynamically from deployment.toml on startup. Your initial proxyPort placement in the [server] section was misplaced; we need to target the Tomcat HTTPS Connector directly in the TOML config to make the setting stick.

Here’s the corrected configuration to add to your deployment.toml:

[server]
hostname = "mydomain.com"
node_ip = "xxx.xxx.xxx.xxx"
# Remove the port from base_path since 443 is the default HTTPS port
base_path = "https://$ref{server.hostname}"

# Configure the Tomcat HTTPS Connector with proxyPort
[tomcat.connector.https]
port = 9443  # Keep WSO2's internal HTTPS port unchanged
proxyPort = 443
scheme = "https"
secure = true

Why this works:

  • The [tomcat.connector.https] section maps directly to the HTTPS Connector entry in catalina-server.xml. When WSO2 starts up, it will generate the Connector with the proxyPort="443" attribute included, so your reverse proxy setup will be respected.
  • Updating base_path to omit the port ensures all internal links, redirects, and metadata point to your domain on port 443 instead of the default 9443.

Quick Verification:

After restarting the server, check <WSO2_HOME>/repository/conf/tomcat/catalina-server.xml. Look for the HTTPS Connector element—it should now show:

<Connector port="9443" proxyPort="443" scheme="https" secure="true" ... />

Remember: Never edit catalina-server.xml directly in WSO2 5.x+; all Tomcat-related configurations must be managed via deployment.toml to avoid being overwritten on startup.

内容的提问来源于stack exchange,提问作者Brygom

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:52:00