Spring Boot 1.5.12集成Undertow启用HTTP/2无效问题求助
解决Spring Boot 1.5.x + Undertow HTTP/2不生效的问题
让我来帮你排查下这个问题,Spring Boot 1.5.x搭配Undertow开启HTTP/2确实有几个容易踩的坑,结合你的配置和环境,主要有以下几个需要修正的点:
1. 修正配置文件中的错误
你的application.properties里存在三处关键问题:
- 重复的SSL配置节点:你写了两个
server.ssl块,这会导致配置冲突,需要合并成一个完整的SSL配置。 - HTTP/2配置项错误:Spring Boot 1.5.x中,Undertow的HTTP/2启用开关是
server.undertow.http2.enabled=true,而不是server.http2.enabled=true(后者是Spring Boot 2.x的配置)。 - 证书路径的空格问题:
key-store: classpath: keystore.p12里classpath:后面多了一个空格,这会导致Spring无法正确加载证书文件。
修正后的完整配置如下:
security: require-ssl: true server: port: 8085 ssl: enabled: true key-store: classpath:keystore.p12 key-store-type: PKCS12 key-alias: devel key-store-password: pass key-password: pass undertow: http2: enabled: true eureka: client: serviceUrl: defaultZone: https://localhost:8761/eureka instance: preferIpAddress: false securePortEnabled: true securePort: ${server.port}
2. 添加ALPN支持依赖
HTTP/2 over TLS需要依赖**ALPN(应用层协议协商)**扩展来在TLS握手阶段协商使用HTTP/2协议,但JDK 8默认的JSSE并不支持ALPN。Undertow基于Netty实现,所以需要添加Netty的native SSL库来提供ALPN支持。
如果是Maven项目,在pom.xml中添加以下依赖和插件:
<!-- 提供ALPN支持的native SSL库 --> <dependency> <groupId>io.netty</groupId> <artifactId>netty-tcnative-boringssl-static</artifactId> <version>2.0.25.Final</version> <classifier>${os.detected.classifier}</classifier> </dependency> <!-- 自动检测操作系统,匹配对应的native库 --> <build> <plugins> <plugin> <groupId>kr.motd.maven</groupId> <artifactId>os-maven-plugin</artifactId> <version>1.6.2</version> <executions> <execution> <phase>initialize</phase> <goals> <goal>detect</goal> </goals> </execution> </executions> </plugin> </plugins> </build>
如果是Gradle项目,配置如下:
plugins { id "com.google.osdetector" version "1.6.2" } dependencies { compile "io.netty:netty-tcnative-boringssl-static:2.0.25.Final:$osdetect.classifier" }
3. 浏览器端验证
完成上述配置后,重启应用,然后:
- 在浏览器中访问
https://localhost:8085,因为是自签名证书,需要手动添加信任例外。 - 打开浏览器开发者工具(F12),切换到Network标签,查看请求的
Protocol列,正常情况下应该显示h2(表示HTTP/2协议)。
额外注意点
- 确保Angular应用的所有资源请求都是通过HTTPS发起的,避免混合内容问题影响协议协商。
- 查看应用启动日志,确认Undertow正常启动并启用了HTTP/2,日志中会包含类似
Undertow started on port(s) 8085 (https) with context path ''的信息。
内容的提问来源于stack exchange,提问作者Bad_Pan
相关产品推荐
相关产品推荐

