You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WebTransport无法连接本地服务器的排查与求助

问题:WebTransport QUIC连接无法建立,请求未到达服务器

当尝试通过new WebTransport('https://localhost')建立QUIC连接时,请求从未到达服务器:

  • Chrome中连接立即终止,控制台报错:Failed to establish a connection to https://localhost/: net::ERR_CONNECTION_RESET. 和 Uncaught (in promise) WebTransportError: Opening handshake failed.
  • Firefox中连接不会立即终止,约10秒后控制台抛出WebTransportError,提示WebTransport connection rejected,同样无请求到达服务器的迹象。

服务器代码排查(Deno + --unstable-net)

推测问题可能出在SSL证书或服务器代码,先排查服务器代码:使用带--unstable-net标志的Deno,简化代码如下:

const key = Deno.readTextFileSync('./SSL/Self-signed.key'),
cert = Deno.readTextFileSync('./SSL/Self-signed.crt')

Deno.serve({ port: 443, key, cert }, ()=>new Response('Hello World!'))

const endpoint = new Deno.QuicEndpoint,
listener = endpoint.listen({ alpnProtocols: ['h2', 'h3', 'idc'], key, cert }),
conn = await listener.incoming()
console.log('New connection: ', conn)

该代码可正常提供HTTPS服务(访问https://localhost能看到“Hello World!”),但最后一行从未执行,说明无法处理QUIC连接。


自签名证书排查(Windows环境)

在Windows环境下通过手写批处理生成自签名证书,批处理已简化并添加注释:

@echo off
set OPENSSL_HOME=%~dp0openssl-3
set OPENSSL_CONF=%OPENSSL_HOME%/ssl/openssl.cnf
PATH=%PATH%;"%OPENSSL_HOME%/x64/bin"

::Generate signatory ECDSA key
openssl ecparam -genkey -out "%~dp0rootKey.key" -name prime256v1

::Generate authority from key
openssl req -x509 -new -nodes -key "%~dp0rootKey.key" -days 13 -out "%~dp0rootCA.pem" -subj "/C=UA/ST=UA/O=UA"

::Adding authority to the Windows trust store so that browsers can obey
certutil -addstore -f -enterprise -user root "%~dp0rootCA.pem"

::Generate new sign request and public key
openssl req -new -nodes -out "%~dp0signRequest.csr" -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -keyout "%~dp0/../Self-signed.key" -subj "/C=UA/ST=UA/O=UA"

::Generate new self-signed ECDSA certificate
openssl x509 -req -in "%~dp0signRequest.csr" -CA "%~dp0rootCA.pem" -CAkey "%~dp0rootKey.key" -out "%~dp0/../Self-signed.crt" -days 13 -extfile "%~dp0extfile"

::Content of the "extfile":
::authorityKeyIdentifier=keyid,issuer
::basicConstraints=CA:FALSE
::keyUsage=digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment
::subjectAltName=IP:127.0.0.1,DNS:localhost,DNS:*.localhost

::Saving certificates HASH
openssl x509 -noout -fingerprint -sha256 -noout -in "%~dp0/../Self-signed.crt">"%~dp0HASH"
set /p fp="<%~dp0HASH"
echo %fp:~19%>"%~dp0HASH"

pause

该证书可正常提供HTTPS服务(无需浏览器特殊标志),但无法用于QUIC连接。根据MDN的WebTransport证书要求,证书符合条件(X.509v3、有效期13天、ECDSA密钥),但浏览器仍拒绝建立QUIC连接。


尝试serverCertificateHashes选项

结合证书哈希编写代码并在浏览器控制台执行:

function base64ToArrayBuffer(base64) {
  var binaryString = atob(base64);
  var bytes = new Uint8Array(binaryString.length);
  for (var i = 0; i < binaryString.length; i++) {
    bytes[i] = binaryString.charCodeAt(i);
  }
  return bytes.buffer;
}
new WebTransport('https://localhost', {
  serverCertificateHashes: [
    {
      algorithm: 'sha-256',
      value: base64ToArrayBuffer(btoa(`92:49:72:24:FB:2D:84:D2:0B:5B:A0:1A:F3:0A:6D:60:B5:E2:12:25:7D:2B:60:47:FF:DD:BF:32:33:57:60:53`))
    }
  ]
});

但结果仍相同,请问下一步该如何排查?


内容的提问来源于stack exchange,提问作者Товарищ Понечка

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 16:45:21