这可以通过在 conf/server.xml 中设置单独的“服务”元素来实现。
例如你有
<Service name="Catalina">
<Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" />
<Engine name="Catalina" defaultHost="insecure.example.com">
<Host name="insecure.example.com" appBase="insecure" unpackWARs="true" autoDeploy="true">
</Host>
</Engine>
</Service>
现在添加额外的服务部分
<Service name="SecureApps">
<Connector port="8443" protocol="HTTP/1.1" SSLEnabled="true"
maxThreads="150" scheme="https" secure="true"
keystoreFile="/usr/local/tomcat/keys/keystore.p12" keystorePass="mySecret" keystoreType="pkcs12"
clientAuth="false" sslProtocol="TLS" />
<Engine name="SecureEngine" defaultHost="secure.example.com">
<Host name="secure.example.com" appBase="secure" unpackWARs="true" autoDeploy="true">
</Host>
</Engine>
</Service>
因此,安全应用程序将无法通过不安全的连接获得,因为 HTTP 端口由另一个服务提供服务。
关于 HTTP(8080)->HTTPS(8443) 重定向,在这种配置中可能有更好的方法,但可以在“Catalina”服务中设置第二个“Host”部分,名称为“secure.example.com” ,并部署一些包含简单 servlet 的 Web 应用程序,将任何请求重定向到指定的安全 url。
例如
web.xml
<web-app xmlns="http://java.sun.com/xml/ns/j2ee"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://java.sun.com/xml/ns/j2ee http://java.sun.com/xml/ns/j2ee/web-app_2_4.xsd"
version="2.4">
<display-name>Redirect to secure port</display-name>
<description>
This is a simple web application which redirects you to secure port
</description>
<servlet>
<servlet-name>RedirectServlet</servlet-name>
<servlet-class>com.mycompany.RedirectServlet</servlet-class>
</servlet>
<servlet-mapping>
<servlet-name>RedirectServlet</servlet-name>
<url-pattern>/*</url-pattern>
</servlet-mapping>
</web-app>
重定向Servlet.java
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
public class RedirectServlet extends HttpServlet
{
@Override
protected void doPost(HttpServletRequest request, HttpServletResponse response)
throws IOException
{
String url = "https://secure.example.com:8443/";
response.sendRedirect(url);
}
protected void doGet(HttpServletRequest request, HttpServletResponse response)
throws IOException
{
String url = "https://secure.example.com:8443/";
response.sendRedirect(url);
}
}