如何在Keycloak+Spring环境下同时支持HTTP与HTTPS?
It sounds like you're hitting protocol mismatch issues once you enable HTTPS alongside HTTP for your app. Let's walk through the key fixes to get everything working smoothly:
1. Update Keycloak Client Valid Redirect URIs
First, ensure your Keycloak clients (both Angular frontend and Spring Boot backend) allow redirects over both protocols. Here's how:
- Log into your Keycloak admin console and navigate to each client.
- In the Valid Redirect URIs field, add both HTTP and HTTPS versions of your app's URLs. For example:
- Angular:
http://your-frontend-domain/*andhttps://your-frontend-domain/* - Spring Boot backend (if using authorization code flow):
http://your-backend-domain/*andhttps://your-backend-domain/*
- Angular:
- Don't forget the Web Origins field—add
*(for testing) or specific HTTP/HTTPS URLs to avoid CORS issues across both protocols.
2. Ensure Keycloak Listens on Both HTTP and HTTPS
By default, Keycloak runs on 8080 (HTTP) and 8443 (HTTPS) in development, but production setups might disable HTTP. To confirm/enable both:
- Open Keycloak's configuration file (usually
standalone.xmlorstandalone-ha.xmlin theconffolder). - Look for the
<socket-binding-group>section—verify bothhttp(port 8080) andhttps(port 8443) bindings exist. - Check the
<http-listener>elements in the<server>block: there should be one for HTTP (withsocket-binding="http") and one for HTTPS (withsocket-binding="https"and a valid keystore configured).
3. Adjust Spring Boot Backend Configuration
Your backend's Keycloak adapter needs to handle both protocols correctly:
- Keep
keycloak.auth-server-url=http://my-keycloak/authif you want the backend to communicate with Keycloak over HTTP. The adapter should automatically detect the correct protocol for redirect URIs, but if not, explicitly set the redirect URI for your backend client in Keycloak to include both HTTP/HTTPS. - If you prefer the backend to use HTTPS to talk to Keycloak, update the auth-server-url to
https://my-keycloak/auth. For this, you'll need to add Keycloak's SSL certificate to your backend's truststore (especially if using a self-signed cert for testing). - Double-check your Spring Boot SSL config to make sure both HTTP and HTTPS ports are properly set:
server.port=8080 # HTTP port server.ssl.enabled=true server.ssl.port=8443 # HTTPS port server.ssl.key-store-type=PKCS12 server.ssl.key-store=classpath:your-keystore.p12 server.ssl.key-store-password=your-password server.ssl.key-alias=your-alias
4. Fix Frontend Mixed Content Issues
If your Angular app is accessed over HTTPS, browsers will block requests to Keycloak over HTTP (mixed content). To resolve this:
- Update your Angular Keycloak config to use
https://my-keycloak/authas the auth server URL. - For testing only, you can temporarily allow mixed content in your browser (Chrome: Settings > Privacy and security > Site Settings > Insecure content > Allow for your frontend domain).
5. Debug the Exact Error
If you're still seeing backend errors, check the logs for specific messages:
- Invalid redirect URI: The callback URL from Keycloak isn't in your client's valid redirect URIs—double-check step 1.
- SSLHandshakeException: Your backend doesn't trust Keycloak's HTTPS certificate—add the cert to your backend's truststore.
- Mixed content blocked: Frontend is trying to access Keycloak over HTTP while on HTTPS—fix with step 4.
Content of the question originates from stack exchange, question author Mihai

