如何为ActiveMQ Artemis配置Let's Encrypt SSL证书?
为ActiveMQ Artemis配置Let's Encrypt证书解决SSL握手失败问题
我有一台独立的ActiveMQ Artemis服务器,此前使用自签名证书可正常运行,现在尝试配置Let's Encrypt颁发的有效证书。将证书添加到信任库后,Artemis能启动,但管理控制台返回SSL_PROTOCOL_ERROR,无法完成SSL握手。
请问如何为ActiveMQ Artemis配置经过验证的正式证书?我的bootstrap.xml配置如下:
<web path="web" rootRedirectLocation="console"> <binding name="artemis" uri="https://haproxy.dedicatedtoservers.com:8161" keyStorePath="/var/lib/mybroker/etc/broker_ks.p12" keyStorePassword="********" > <app name="branding" url="activemq-branding" war="activemq-branding.war"/> <app name="plugin" url="artemis-plugin" war="artemis-plugin.war"/> <app name="console" url="console" war="console.war"/> </binding> </web>
启动控制台日志如下:
2024-12-13 09:37:57,769 INFO [org.apache.activemq.artemis] AMQ241003: Starting embedded web server 2024-12-13 09:37:58,054 INFO [org.apache.activemq.hawtio.branding.PluginContextListener] Initialized activemq-branding plugin 2024-12-13 09:37:58,110 INFO [org.apache.activemq.hawtio.plugin.PluginContextListener] Initialized artemis-plugin plugin 2024-12-13 09:37:58,158 INFO [io.hawt.HawtioContextListener] Initialising hawtio services 2024-12-13 09:37:58,178 INFO [io.hawt.system.ConfigManager] Configuration will be discovered via system properties 2024-12-13 09:37:58,181 INFO [io.hawt.jmx.JmxTreeWatcher] Welcome to Hawtio2.17.7 2024-12-13 09:37:58,192 INFO [io.hawt.web.auth.AuthenticationConfiguration] Starting hawtio authentication filter, JAAS realm: "activemq" authorized role(s): "amq" role principal classes: "org.apache.activemq.artemis.spi.core.security.jaas.RolePrincipal" 2024-12-13 09:37:58,205 INFO [io.hawt.web.auth.LoginRedirectFilter] Hawtio loginRedirectFilter is using 1800 sec. HttpSession timeout 2024-12-13 09:37:58,455 INFO [org.apache.activemq.artemis] AMQ241001: HTTP Server started at https://haproxy.dedicatedtoservers.com:8161 2024-12-13 09:37:58,457 INFO [org.apache.activemq.artemis] AMQ241002: Artemis Jolokia REST API available at https://haproxy.dedicatedtoservers.com:8161/console/jolokia 2024-12-13 09:37:58,457 INFO [org.apache.activemq.artemis] AMQ241004: Artemis Console available at https://haproxy.dedicatedtoservers.com:8161/console
解决步骤
1. 确认证书格式与密钥库正确性
- Let's Encrypt证书为PEM格式,需确保导入到PKCS12密钥库时包含完整证书链(服务器证书+Let's Encrypt中间证书),仅导入服务器证书会导致客户端验证失败。
- 用以下命令查看密钥库内容,确认证书链和别名:
keytool -list -v -keystore /var/lib/mybroker/etc/broker_ks.p12 -storetype PKCS12
2. 补充SSL配置参数
当前bootstrap.xml的<binding>节点缺少关键SSL配置,添加以下参数:
<web path="web" rootRedirectLocation="console"> <binding name="artemis" uri="https://haproxy.dedicatedtoservers.com:8161" keyStorePath="/var/lib/mybroker/etc/broker_ks.p12" keyStorePassword="********" trustStorePath="/var/lib/mybroker/etc/broker_ts.p12" trustStorePassword="********" sslEnabled="true" protocol="TLSv1.2,TLSv1.3" cipherSuites="TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256" > <app name="branding" url="activemq-branding" war="activemq-branding.war"/> <app name="plugin" url="artemis-plugin" war="artemis-plugin.war"/> <app name="console" url="console" war="console.war"/> </binding> </web>
sslEnabled="true":显式启用SSLtrustStorePath/trustStorePassword:指定包含Let's Encrypt根证书的信任库protocol:指定兼容的TLS版本,避免过时协议触发握手失败cipherSuites:配置安全加密套件,匹配主流客户端支持范围
3. 验证证书链完整性
使用OpenSSL检查证书链是否完整:
openssl s_client -connect haproxy.dedicatedtoservers.com:8161 -showcerts
- 返回
verify return:1表示验证通过;若返回verify return:2,需将Let's Encrypt的R3中间证书导入密钥库:keytool -importcert -alias letsencrypt-r3 -file /path/to/r3.pem -keystore /var/lib/mybroker/etc/broker_ks.p12 -storetype PKCS12
4. 检查JVM SSL信任配置
- Let's Encrypt根证书通常已包含在JRE默认
cacerts中,若使用自定义JRE,需手动导入:keytool -importcert -alias letsencrypt-root -file /path/to/root.pem -keystore $JAVA_HOME/jre/lib/security/cacerts -storepass changeit
5. 重启调试
修改配置后重启Artemis,再次访问控制台。若问题仍存在,开启SSL调试日志定位原因:
在logging.properties中添加:
org.apache.activemq.artemis.core.remoting.impl.netty.level=FINEST io.netty.handler.ssl.level=FINEST
内容的提问来源于stack exchange,提问作者user3183111
相关产品推荐
相关产品推荐

