维护遗留应用切换TLSv1.2邮件服务器遇503加密过弱错误求助
问题解决:SMTP加密过弱错误(503 5.7.0 encryption too weak 0 less than 128)
核心原因
你的报错源于JavaMail 1.5.0版本对TLSv1.2的加密套件支持不完善,加上目标服务器要求至少128位加密强度,导致协商的加密套件未达到服务器标准。
解决方案
1. 升级JavaMail依赖版本
1.5.0是2014年的旧版本,对TLSv1.2的支持存在局限性。建议升级到1.6.2版本(兼容javax命名空间,适配遗留应用):
<dependency> <groupId>com.sun.mail</groupId> <artifactId>javax.mail</artifactId> <version>1.6.2</version> </dependency>
2. 指定强加密套件
在配置中添加加密套件参数,强制使用符合128位及以上强度的套件:
props.put("mail.smtp.ssl.ciphersuites", "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256," + "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384," + "TLS_RSA_WITH_AES_128_GCM_SHA256," + "TLS_RSA_WITH_AES_256_GCM_SHA384");
3. 确保JDK版本符合要求
- 若使用JDK 7,需升级到1.7u131及以上版本(该版本才默认支持TLSv1.2)
- 优先推荐使用JDK 8及以上版本,对TLSv1.2的支持更完善
4. 强化TLS强制配置(可选)
添加starttls.required参数,确保连接必须使用TLS,避免降级到未加密或弱加密连接:
props.put("mail.smtp.starttls.required", "true");
验证调整后的完整配置
props.put("mail.smtp.host", smtpHost); props.put("mail.smtp.auth", "false"); props.put("mail.smtp.starttls.enable", "true"); props.put("mail.smtp.starttls.required", "true"); props.put("mail.smtp.ssl.protocols", "TLSv1.2"); props.put("mail.smtp.ssl.ciphersuites", "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256," + "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384," + "TLS_RSA_WITH_AES_128_GCM_SHA256," + "TLS_RSA_WITH_AES_256_GCM_SHA384"); props.put("mail.smtp.port", "25"); props.put("mail.debug", "true"); Session session = Session.getInstance(props, null); session.setDebug(true); // ... 设置发件人、收件人等逻辑 Transport.send(message);
内容的提问来源于stack exchange,提问作者Dawn White
相关产品推荐
相关产品推荐

