You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

iOS应用本地HTTPS连接测试失败问题求助

Fixing SSL Trust Error Between iOS App and Local Tomcat Server

Hey there, let's work through this SSL error you're stuck on. That NSURLErrorDomain code: 18446744073709550416 is actually the unsigned representation of -1200, which directly links to the _kCFStreamErrorCodeKey: -9800 — this means your iOS device doesn't trust the SSL certificate from your local Tomcat server. Here's how to fix this step by step:

1. Ensure Your Self-Signed CA Root Certificate is Trusted on iPhone

This is the most common missed step:

  • Send your self-signed CA root certificate to your iPhone via AirDrop, email, or a local file share, then install it when prompted.
  • Critical: After installation, go to Settings > General > About > Certificate Trust Settings, find your CA certificate, and toggle on "Full Trust for Root Certificate". iOS won't automatically trust self-signed CAs even after installation.

2. Verify Tomcat's SSL Configuration

Double-check your Tomcat server.xml to make sure the SSL connector is set up correctly:

  • Ensure you're using the identity certificate signed by your self-signed CA, and the certificate chain is complete. Example configuration:
    <Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol"
               maxThreads="150" SSLEnabled="true">
        <SSLHostConfig>
            <Certificate certificateKeystoreFile="conf/your-keystore.jks"
                         type="RSA"
                         certificateKeystorePassword="your-keystore-pass"
                         certificateKeyPassword="your-key-pass"/>
        </SSLHostConfig>
    </Connector>
    
  • Validate your keystore with this command to confirm the CA root is included in the chain:
    keytool -list -v -keystore your-keystore.jks
    

3. Adjust iOS ATS Settings (Test Only)

For iOS 13+, App Transport Security (ATS) enforces strict SSL rules. Add a temporary exception for your local server in Info.plist (remove this before production):

<key>NSAppTransportSecurity</key>
<dict>
    <key>NSAllowsArbitraryLoads</key>
    <false/>
    <key>NSExceptionDomains</key>
    <dict>
        <key>your-local-server-ip-or-domain</key>
        <dict>
            <key>NSIncludesSubdomains</key>
            <true/>
            <key>NSTemporaryExceptionMinimumTLSVersion</key>
            <string>TLSv1.2</string>
            <key>NSTemporaryExceptionRequiresForwardSecrecy</key>
            <false/>
        </dict>
    </dict>
</dict>

4. Test the SSL Connection

  • Use Safari on your iPhone to visit https://your-local-server-ip:8443. If Safari prompts you to trust the certificate, your Tomcat certificate chain is incomplete. If it loads without issues, double-check your iOS certificate trust settings.
  • Run this command on your Mac to debug the SSL handshake:
    openssl s_client -connect your-local-server-ip:8443
    
    Look for errors related to certificate chain validation or untrusted roots.

内容的提问来源于stack exchange,提问作者user9211159

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:48:48