You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Keycloak+Spring环境下同时支持HTTP与HTTPS?

How to Make Keycloak Support Both HTTP and HTTPS for Your Angular + Spring Boot App

It sounds like you're hitting protocol mismatch issues once you enable HTTPS alongside HTTP for your app. Let's walk through the key fixes to get everything working smoothly:

1. Update Keycloak Client Valid Redirect URIs

First, ensure your Keycloak clients (both Angular frontend and Spring Boot backend) allow redirects over both protocols. Here's how:

  • Log into your Keycloak admin console and navigate to each client.
  • In the Valid Redirect URIs field, add both HTTP and HTTPS versions of your app's URLs. For example:
    • Angular: http://your-frontend-domain/* and https://your-frontend-domain/*
    • Spring Boot backend (if using authorization code flow): http://your-backend-domain/* and https://your-backend-domain/*
  • Don't forget the Web Origins field—add * (for testing) or specific HTTP/HTTPS URLs to avoid CORS issues across both protocols.

2. Ensure Keycloak Listens on Both HTTP and HTTPS

By default, Keycloak runs on 8080 (HTTP) and 8443 (HTTPS) in development, but production setups might disable HTTP. To confirm/enable both:

  • Open Keycloak's configuration file (usually standalone.xml or standalone-ha.xml in the conf folder).
  • Look for the <socket-binding-group> section—verify both http (port 8080) and https (port 8443) bindings exist.
  • Check the <http-listener> elements in the <server> block: there should be one for HTTP (with socket-binding="http") and one for HTTPS (with socket-binding="https" and a valid keystore configured).

3. Adjust Spring Boot Backend Configuration

Your backend's Keycloak adapter needs to handle both protocols correctly:

  • Keep keycloak.auth-server-url=http://my-keycloak/auth if you want the backend to communicate with Keycloak over HTTP. The adapter should automatically detect the correct protocol for redirect URIs, but if not, explicitly set the redirect URI for your backend client in Keycloak to include both HTTP/HTTPS.
  • If you prefer the backend to use HTTPS to talk to Keycloak, update the auth-server-url to https://my-keycloak/auth. For this, you'll need to add Keycloak's SSL certificate to your backend's truststore (especially if using a self-signed cert for testing).
  • Double-check your Spring Boot SSL config to make sure both HTTP and HTTPS ports are properly set:
    server.port=8080 # HTTP port
    server.ssl.enabled=true
    server.ssl.port=8443 # HTTPS port
    server.ssl.key-store-type=PKCS12
    server.ssl.key-store=classpath:your-keystore.p12
    server.ssl.key-store-password=your-password
    server.ssl.key-alias=your-alias
    

4. Fix Frontend Mixed Content Issues

If your Angular app is accessed over HTTPS, browsers will block requests to Keycloak over HTTP (mixed content). To resolve this:

  • Update your Angular Keycloak config to use https://my-keycloak/auth as the auth server URL.
  • For testing only, you can temporarily allow mixed content in your browser (Chrome: Settings > Privacy and security > Site Settings > Insecure content > Allow for your frontend domain).

5. Debug the Exact Error

If you're still seeing backend errors, check the logs for specific messages:

  • Invalid redirect URI: The callback URL from Keycloak isn't in your client's valid redirect URIs—double-check step 1.
  • SSLHandshakeException: Your backend doesn't trust Keycloak's HTTPS certificate—add the cert to your backend's truststore.
  • Mixed content blocked: Frontend is trying to access Keycloak over HTTP while on HTTPS—fix with step 4.

Content of the question originates from stack exchange, question author Mihai

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:27:18