2012-07-18 13:24
浏览 359

Secure WebSocket(wss://)在Firefox上不起作用

I have a working WebSocket non secure application. But my website uses https and I need a Secure WebSocket connection to avoid Firefox to complain about the fact that the connection is insecure.

I am using php-websocket-server for my WebSocket server with PhP 5.2.9, so when i use WebSocket secure i can't decrypt packets with the openssl_decrypt function.

That's why i used stunnel in order to decrypt packets sent by the client using wss, to do that i binded client WebSocket to 12345 port an server WebSocket to 54321 port, then i added a stunnel in server mode :

accept  = 12345
connect =

With this configuration my application works fine on Chrome through https + wss. But on Firefox there's a problem during the handshake, it seems that Sec-WebSocket-Version and Sec-WebSocket-Key are missing in the header. I don't understand because it works on Firefox through http + ws.

Thanks in advance for your help.

Edit : i added an exception for the certificate on the port 12345, now the handshake is going well because i think Firefox now have the Sec-WebSocket-Key.

Here the working header request with Firefox (bigger than Chrome request):

GET / HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:14.0) Gecko/20100101 Firefox/14.0.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/;q=0.8
Accept-Language: fr,fr-fr;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
DNT: 1
Connection: keep-alive, Upgrade
Sec-WebSocket-Version: 13
Sec-WebSocket-Protocol: HyBi-00
Sec-WebSocket-Key: 65nHN33M6drIPjQHcGK8pA==
Pragma: no-cache
Cache-Control: no-cache
Upgrade: websocket

图片转代码服务由CSDN问答提供 功能建议

我有一个有效的WebSocket非安全应用程序。 但我的网站使用https,我需要一个安全的WebSocket连接,以避免Firefox抱怨连接不安全的事实。

我正在使用 php-websocket-server ,所以当我使用WebSocket安全时,我无法使用openssl_decrypt函数解密数据包 。

这就是我使用 stunnel 来解密客户端使用wss发送的数据包的原因, 这样做我把客户端WebSocket绑定到12345端口服务器WebSocket到54321端口,然后我在服务器模式下添加了一个stunnel:

accept = 12345 
connect = 192.168  .1.227:54321 

使用此配置,我的应用程序可以通过https + wss在Chrome上正常运行。 但是在Firefox上,握手期间出现问题,似乎标题中缺少 Sec-WebSocket-Version Sec-WebSocket-Key 。 我不明白,因为它可以通过http + ws在Firefox上运行。


编辑:我添加了一个例外 对于端口12345上的证书,现在握手进展顺利,因为我认为Firefox现在有 Sec-WebSocket-Key

这里是工作头请求 使用Firefox(大于Chrome请求):

  GET / HTTP / 1.1 
User-Agent:Mozilla / 5.0(Windows NT 6.1; WOW64  ; rv:14.0)Gecko / 20100101 Firefox / 14.0.1 
接受:text / html,application / xhtml + xml,application / xml; q = 0.9,* /; q = 0.8 
Accept-语言:fr,fr-fr  ; q = 0.8,en-us; q = 0.5,en; q = 0.3 
Origin:https  :// 
Sec-WebSocket-Key:65nHN33M6drIPjQHcGK8pA == 
  • 点赞
  • 写回答
  • 关注问题
  • 收藏
  • 邀请回答

1条回答 默认 最新

  • douren1891 2012-07-19 05:58

    If you work in local with auto-signed certificate, you have to approve it on both servers https:// running on port 443 and wss:// running on port 12345 here with Firefox.

    I think your browser does not allow the secure websocket connection and that why some headers are missing.

    点赞 2 打赏 评论

相关推荐 更多相似问题