iOS应用本地HTTPS连接测试失败问题求助
Fixing SSL Trust Error Between iOS App and Local Tomcat Server
Hey there, let's work through this SSL error you're stuck on. That NSURLErrorDomain code: 18446744073709550416 is actually the unsigned representation of -1200, which directly links to the _kCFStreamErrorCodeKey: -9800 — this means your iOS device doesn't trust the SSL certificate from your local Tomcat server. Here's how to fix this step by step:
1. Ensure Your Self-Signed CA Root Certificate is Trusted on iPhone
This is the most common missed step:
- Send your self-signed CA root certificate to your iPhone via AirDrop, email, or a local file share, then install it when prompted.
- Critical: After installation, go to
Settings > General > About > Certificate Trust Settings, find your CA certificate, and toggle on "Full Trust for Root Certificate". iOS won't automatically trust self-signed CAs even after installation.
2. Verify Tomcat's SSL Configuration
Double-check your Tomcat server.xml to make sure the SSL connector is set up correctly:
- Ensure you're using the identity certificate signed by your self-signed CA, and the certificate chain is complete. Example configuration:
<Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" maxThreads="150" SSLEnabled="true"> <SSLHostConfig> <Certificate certificateKeystoreFile="conf/your-keystore.jks" type="RSA" certificateKeystorePassword="your-keystore-pass" certificateKeyPassword="your-key-pass"/> </SSLHostConfig> </Connector> - Validate your keystore with this command to confirm the CA root is included in the chain:
keytool -list -v -keystore your-keystore.jks
3. Adjust iOS ATS Settings (Test Only)
For iOS 13+, App Transport Security (ATS) enforces strict SSL rules. Add a temporary exception for your local server in Info.plist (remove this before production):
<key>NSAppTransportSecurity</key> <dict> <key>NSAllowsArbitraryLoads</key> <false/> <key>NSExceptionDomains</key> <dict> <key>your-local-server-ip-or-domain</key> <dict> <key>NSIncludesSubdomains</key> <true/> <key>NSTemporaryExceptionMinimumTLSVersion</key> <string>TLSv1.2</string> <key>NSTemporaryExceptionRequiresForwardSecrecy</key> <false/> </dict> </dict> </dict>
4. Test the SSL Connection
- Use Safari on your iPhone to visit
https://your-local-server-ip:8443. If Safari prompts you to trust the certificate, your Tomcat certificate chain is incomplete. If it loads without issues, double-check your iOS certificate trust settings. - Run this command on your Mac to debug the SSL handshake:
Look for errors related to certificate chain validation or untrusted roots.openssl s_client -connect your-local-server-ip:8443
内容的提问来源于stack exchange,提问作者user9211159
相关产品推荐
相关产品推荐

