You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为ActiveMQ Artemis配置Let's Encrypt SSL证书?

为ActiveMQ Artemis配置Let's Encrypt证书解决SSL握手失败问题

我有一台独立的ActiveMQ Artemis服务器,此前使用自签名证书可正常运行,现在尝试配置Let's Encrypt颁发的有效证书。将证书添加到信任库后,Artemis能启动,但管理控制台返回SSL_PROTOCOL_ERROR,无法完成SSL握手。

请问如何为ActiveMQ Artemis配置经过验证的正式证书?我的bootstrap.xml配置如下:

<web path="web"  rootRedirectLocation="console">
    <binding name="artemis" 
             uri="https://haproxy.dedicatedtoservers.com:8161" 
             keyStorePath="/var/lib/mybroker/etc/broker_ks.p12" 
             keyStorePassword="********" 
    >
        <app name="branding" url="activemq-branding" war="activemq-branding.war"/>
        <app name="plugin" url="artemis-plugin" war="artemis-plugin.war"/>
        <app name="console" url="console" war="console.war"/>
    </binding>
</web>

启动控制台日志如下:

2024-12-13 09:37:57,769 INFO  [org.apache.activemq.artemis] AMQ241003: Starting embedded web server 
2024-12-13 09:37:58,054 INFO  [org.apache.activemq.hawtio.branding.PluginContextListener] Initialized activemq-branding plugin 
2024-12-13 09:37:58,110 INFO  [org.apache.activemq.hawtio.plugin.PluginContextListener] Initialized artemis-plugin plugin 
2024-12-13 09:37:58,158 INFO  [io.hawt.HawtioContextListener] Initialising hawtio services
2024-12-13 09:37:58,178 INFO  [io.hawt.system.ConfigManager] Configuration will be discovered via system properties 
2024-12-13 09:37:58,181 INFO  [io.hawt.jmx.JmxTreeWatcher] Welcome to Hawtio2.17.7 2024-12-13 09:37:58,192 INFO  [io.hawt.web.auth.AuthenticationConfiguration] Starting hawtio authentication filter, JAAS realm: "activemq" authorized role(s): "amq" role principal classes: "org.apache.activemq.artemis.spi.core.security.jaas.RolePrincipal"
2024-12-13 09:37:58,205 INFO  [io.hawt.web.auth.LoginRedirectFilter] Hawtio loginRedirectFilter is using 1800 sec. HttpSession timeout
2024-12-13 09:37:58,455 INFO  [org.apache.activemq.artemis] AMQ241001: HTTP Server started at https://haproxy.dedicatedtoservers.com:8161 2024-12-13 09:37:58,457 INFO  [org.apache.activemq.artemis] AMQ241002: Artemis Jolokia REST API available at https://haproxy.dedicatedtoservers.com:8161/console/jolokia
2024-12-13 09:37:58,457 INFO  [org.apache.activemq.artemis] AMQ241004: Artemis Console available at https://haproxy.dedicatedtoservers.com:8161/console

解决步骤

1. 确认证书格式与密钥库正确性

  • Let's Encrypt证书为PEM格式,需确保导入到PKCS12密钥库时包含完整证书链(服务器证书+Let's Encrypt中间证书),仅导入服务器证书会导致客户端验证失败。
  • 用以下命令查看密钥库内容,确认证书链和别名:
    keytool -list -v -keystore /var/lib/mybroker/etc/broker_ks.p12 -storetype PKCS12
    

2. 补充SSL配置参数

当前bootstrap.xml的<binding>节点缺少关键SSL配置,添加以下参数:

<web path="web"  rootRedirectLocation="console">
    <binding name="artemis" 
             uri="https://haproxy.dedicatedtoservers.com:8161" 
             keyStorePath="/var/lib/mybroker/etc/broker_ks.p12" 
             keyStorePassword="********"
             trustStorePath="/var/lib/mybroker/etc/broker_ts.p12"
             trustStorePassword="********"
             sslEnabled="true"
             protocol="TLSv1.2,TLSv1.3"
             cipherSuites="TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
    >
        <app name="branding" url="activemq-branding" war="activemq-branding.war"/>
        <app name="plugin" url="artemis-plugin" war="artemis-plugin.war"/>
        <app name="console" url="console" war="console.war"/>
    </binding>
</web>
  • sslEnabled="true":显式启用SSL
  • trustStorePath/trustStorePassword:指定包含Let's Encrypt根证书的信任库
  • protocol:指定兼容的TLS版本,避免过时协议触发握手失败
  • cipherSuites:配置安全加密套件,匹配主流客户端支持范围

3. 验证证书链完整性

使用OpenSSL检查证书链是否完整:

openssl s_client -connect haproxy.dedicatedtoservers.com:8161 -showcerts
  • 返回verify return:1表示验证通过;若返回verify return:2,需将Let's Encrypt的R3中间证书导入密钥库:
    keytool -importcert -alias letsencrypt-r3 -file /path/to/r3.pem -keystore /var/lib/mybroker/etc/broker_ks.p12 -storetype PKCS12
    

4. 检查JVM SSL信任配置

  • Let's Encrypt根证书通常已包含在JRE默认cacerts中,若使用自定义JRE,需手动导入:
    keytool -importcert -alias letsencrypt-root -file /path/to/root.pem -keystore $JAVA_HOME/jre/lib/security/cacerts -storepass changeit
    

5. 重启调试

修改配置后重启Artemis,再次访问控制台。若问题仍存在,开启SSL调试日志定位原因:
在logging.properties中添加:

org.apache.activemq.artemis.core.remoting.impl.netty.level=FINEST
io.netty.handler.ssl.level=FINEST

内容的提问来源于stack exchange,提问作者user3183111

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 14:54:52