.NET Kestrel服务器在Firefox中无法建立HTTP/3连接,回落至HTTP/2
问题:Ubuntu 24.04上.NET 9 Kestrel+MsQuic搭建的HTTP/3服务器仅能通过HTTP/2连接
在Ubuntu 24.04系统上,使用.NET 9、Kestrel和MsQuic搭建支持HTTP/3的Web服务器,服务器配置看似正确,已监听TCP(HTTP/2)和UDP(HTTP/3)端口5001,但Firefox仅能通过HTTP/2连接。
服务器基于.NET 9、Kestrel、Microsoft.AspNetCore.Server.Kestrel及libmsquic搭建,使用mkcert和openssl生成了localhost.pfx证书,相关配置如下:
appsettings.json配置
{ "ServerOptions": { "Port": 5001, "Certificate": { "Path": "certs/localhost.pfx", "Password": REDACTED } } }
Kestrel绑定代码(绑定IPAddress.IPv6Any以同时处理IPv4和IPv6)
using System.Net; using System.Security.Cryptography.X509Certificates; using Microsoft.AspNetCore.Server.Kestrel.Core; public static class KestrelSetup { public static void SetupKestrel(this KestrelServerOptions options, ServerOptions serverOptions) { var cert = new X509Certificate2(serverOptions.Certificate.Path, serverOptions.Certificate.Password); options.ConfigureHttpsDefaults(httpsOptions => { httpsOptions.ServerCertificate = cert; }); // 单个监听器同时绑定[::]:5001的TCP和UDP协议 options.Listen(IPAddress.IPv6Any, serverOptions.Port, listenOptions => { listenOptions.Protocols = HttpProtocols.Http1AndHttp2AndHttp3; listenOptions.UseHttps(); }); } }
问题详情
服务器启动无报错,netstat输出显示TCP6和UDP6均已监听5001端口:
- TCP监听:执行
sudo netstat -ltpn | grep 5001返回tcp6 0 0 :::5001 :::* LISTEN 27292/QUICServer - UDP监听:执行
sudo netstat -lupn | grep 5001返回udp6 0 0 :::5001 :::* 27292/Server
访问127.0.0.1:5001或[::1]:5001时页面可加载,但Firefox网络面板显示使用HTTP/2(h2)协议;响应头包含正确的alt-svc: h3=":5001"; ma=86400,但在about:networking#http3中,该origin显示为“inactive”。这表明Firefox识别到HTTP/3通知,但QUIC握手失败,因此回落至可用的HTTP/2连接,且Kestrel日志仅记录HTTP/2请求,无QUIC或HTTP/3相关日志。
已尝试的无效解决措施
- 防火墙:执行
sudo ufw allow 5001/udp开放UDP端口 - 安装libmsquic原生依赖
- 运行
mkcert -install将证书安装到系统存储,手动导入rootCA.pem到Firefox信任列表并勾选“信任此CA以识别网站” - Firefox
about:config设置:security.enterprise_roots.enabled=true、network.http.http3.enabled=true - 清除HTTP/3缓存、多次重启Firefox、新建配置文件测试
疑问
在服务器已监听TCP和UDP端口、证书信任配置正确的情况下,QUIC握手失败的原因是什么?
内容的提问来源于stack exchange,提问作者SHIFD
相关产品推荐
相关产品推荐

