Spring Boot应用启用HTTP Strict Transport Security(HSTS)失败排查
问题:Spring Boot配置HSTS头后响应中未出现Strict-Transport-Security
我按照Spring Security 4.0.2的文档配置了HSTS头,但响应里始终没有出现Strict-Transport-Security字段,相关配置和当前响应信息如下:
pom.xml依赖配置
<dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-actuator</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-thymeleaf</artifactId> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-web</artifactId> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-config</artifactId> </dependency> </dependencies>
WebSecurityConfig配置类
import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @EnableWebSecurity @Configuration public class WebSecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .headers() .httpStrictTransportSecurity() .includeSubDomains(true) .maxAgeInSeconds(31536000); } }
当前响应头列表
cache-control → no-cache, no-store, max-age=0, must-revalidate content-language → en-GB content-type → text/html;charset=UTF-8 date → Thu, 24 May 2018 14:10:29 GMT expires → pragma → no-cache transfer-encoding → chunked x-application-context → application:9000 x-content-type-options → nosniff x-frame-options → SAMEORIGIN x-xss-protection → 1; mode=block
解决方案:HSTS仅在HTTPS请求下生效
你遇到的问题核心原因是HSTS头只会在HTTPS协议的请求中返回,HTTP请求下Spring Security不会添加这个头。下面是具体的排查和解决步骤:
1. 确认应用是否运行在HTTPS环境
如果你的应用当前是通过HTTP访问(比如本地开发默认的8080端口),那肯定看不到Strict-Transport-Security头。你需要配置Spring Boot启用HTTPS:
步骤1:生成自签名证书(本地测试用)
用keytool命令生成一个PKCS12格式的证书:
keytool -genkeypair -alias tomcat -keyalg RSA -keysize 2048 -storetype PKCS12 -keystore keystore.p12 -validity 3650
执行后按照提示输入密码和相关信息,生成的keystore.p12文件放到项目的src/main/resources目录下。
步骤2:配置application.properties
添加HTTPS相关配置:
server.port=8443 server.ssl.key-store=classpath:keystore.p12 server.ssl.key-store-password=你设置的密码 server.ssl.keyStoreType=PKCS12 server.ssl.keyAlias=tomcat
2. 验证配置正确性
你的Spring Security配置本身是没问题的,但可以确保没有其他配置覆盖HSTS的设置。比如如果有自定义的Filter修改响应头,需要检查是否会移除HSTS字段。
3. 测试HTTPS请求
启动应用后,用浏览器访问https://localhost:8443,或者用curl命令查看响应头:
curl -v https://localhost:8443 --insecure
此时你应该能看到Strict-Transport-Security头出现在响应中。
额外说明
如果你的应用是部署在反向代理(如Nginx)后面,需要确保反向代理将HTTPS的请求信息传递给Spring Boot,或者直接在反向代理层面配置HSTS头。比如Nginx的配置可以添加:
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
内容的提问来源于stack exchange,提问作者kk.
相关产品推荐
相关产品推荐

