WebTransport无法连接本地服务器的排查与求助
问题:WebTransport QUIC连接无法建立,请求未到达服务器
当尝试通过new WebTransport('https://localhost')建立QUIC连接时,请求从未到达服务器:
- Chrome中连接立即终止,控制台报错:
Failed to establish a connection to https://localhost/: net::ERR_CONNECTION_RESET.和Uncaught (in promise) WebTransportError: Opening handshake failed. - Firefox中连接不会立即终止,约10秒后控制台抛出
WebTransportError,提示WebTransport connection rejected,同样无请求到达服务器的迹象。
服务器代码排查(Deno + --unstable-net)
推测问题可能出在SSL证书或服务器代码,先排查服务器代码:使用带--unstable-net标志的Deno,简化代码如下:
const key = Deno.readTextFileSync('./SSL/Self-signed.key'), cert = Deno.readTextFileSync('./SSL/Self-signed.crt') Deno.serve({ port: 443, key, cert }, ()=>new Response('Hello World!')) const endpoint = new Deno.QuicEndpoint, listener = endpoint.listen({ alpnProtocols: ['h2', 'h3', 'idc'], key, cert }), conn = await listener.incoming() console.log('New connection: ', conn)
该代码可正常提供HTTPS服务(访问https://localhost能看到“Hello World!”),但最后一行从未执行,说明无法处理QUIC连接。
自签名证书排查(Windows环境)
在Windows环境下通过手写批处理生成自签名证书,批处理已简化并添加注释:
@echo off set OPENSSL_HOME=%~dp0openssl-3 set OPENSSL_CONF=%OPENSSL_HOME%/ssl/openssl.cnf PATH=%PATH%;"%OPENSSL_HOME%/x64/bin" ::Generate signatory ECDSA key openssl ecparam -genkey -out "%~dp0rootKey.key" -name prime256v1 ::Generate authority from key openssl req -x509 -new -nodes -key "%~dp0rootKey.key" -days 13 -out "%~dp0rootCA.pem" -subj "/C=UA/ST=UA/O=UA" ::Adding authority to the Windows trust store so that browsers can obey certutil -addstore -f -enterprise -user root "%~dp0rootCA.pem" ::Generate new sign request and public key openssl req -new -nodes -out "%~dp0signRequest.csr" -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -keyout "%~dp0/../Self-signed.key" -subj "/C=UA/ST=UA/O=UA" ::Generate new self-signed ECDSA certificate openssl x509 -req -in "%~dp0signRequest.csr" -CA "%~dp0rootCA.pem" -CAkey "%~dp0rootKey.key" -out "%~dp0/../Self-signed.crt" -days 13 -extfile "%~dp0extfile" ::Content of the "extfile": ::authorityKeyIdentifier=keyid,issuer ::basicConstraints=CA:FALSE ::keyUsage=digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment ::subjectAltName=IP:127.0.0.1,DNS:localhost,DNS:*.localhost ::Saving certificates HASH openssl x509 -noout -fingerprint -sha256 -noout -in "%~dp0/../Self-signed.crt">"%~dp0HASH" set /p fp="<%~dp0HASH" echo %fp:~19%>"%~dp0HASH" pause
该证书可正常提供HTTPS服务(无需浏览器特殊标志),但无法用于QUIC连接。根据MDN的WebTransport证书要求,证书符合条件(X.509v3、有效期13天、ECDSA密钥),但浏览器仍拒绝建立QUIC连接。
尝试serverCertificateHashes选项
结合证书哈希编写代码并在浏览器控制台执行:
function base64ToArrayBuffer(base64) { var binaryString = atob(base64); var bytes = new Uint8Array(binaryString.length); for (var i = 0; i < binaryString.length; i++) { bytes[i] = binaryString.charCodeAt(i); } return bytes.buffer; } new WebTransport('https://localhost', { serverCertificateHashes: [ { algorithm: 'sha-256', value: base64ToArrayBuffer(btoa(`92:49:72:24:FB:2D:84:D2:0B:5B:A0:1A:F3:0A:6D:60:B5:E2:12:25:7D:2B:60:47:FF:DD:BF:32:33:57:60:53`)) } ] });
但结果仍相同,请问下一步该如何排查?
内容的提问来源于stack exchange,提问作者Товарищ Понечка
相关产品推荐
相关产品推荐

