You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JMeter SSE脚本遇TrustStore相关SSL错误,求解决方案

Solution Paths for JMeter SSE SSL Issues with Java 21

1. Fix Default Trust Store Import (Root Cause of Initial SSL Handshake Failure)

Java 21 uses PKCS12 as the default trust store format (file: cacerts.p12), replacing the legacy JKS cacerts file. Your initial certificate import to the JKS store had no effect because Java 21 wasn't using it. To resolve:

  • Locate your Azul Zulu JDK 21's trust store path (typically <zulu-jdk-21>/lib/security/cacerts.p12)
  • Import the target certificate into this PKCS12 store using keytool:
    keytool -importcert -file /path/to/your/certificate.crt -keystore <zulu-jdk-21>/lib/security/cacerts.p12 -storetype PKCS12 -alias "sse-server-cert"
    
    • Default password for cacerts.p12 is changeit
  • Restart JMeter after the import.

2. Resolve Custom Trust Store Access Error

The no such algorithm: jks for provider SunJSSE error occurs because Java 21's SunJSSE provider no longer supports JKS. Use PKCS12 for custom trust stores instead:

Step 1: Create a PKCS12 Trust Store

If you need a custom trust store (instead of modifying the default), generate one with PKCS12:

keytool -importcert -file /path/to/certificate.crt -keystore /path/to/custom-truststore.p12 -storetype PKCS12 -alias "sse-server-cert"

Step 2: Configure JMeter to Use the Custom PKCS12 Store

Choose one of these methods:

Option A: Via JMeter Configuration Files

Add these lines to system.properties:

javax.net.ssl.trustStore=/path/to/custom-truststore.p12
javax.net.ssl.trustStorePassword=your-store-password
javax.net.ssl.trustStoreType=PKCS12

Option B: Directly in JSR223 Script (Before EventSource Setup)

System.setProperty("javax.net.ssl.trustStore", "/path/to/custom-truststore.p12")
System.setProperty("javax.net.ssl.trustStorePassword", "your-store-password")
System.setProperty("javax.net.ssl.trustStoreType", "PKCS12")

3. Custom SSL Context for OkHttp EventSource (Alternative Reliable Approach)

If system-wide trust store changes don't work, configure a custom SSL context directly in your script to ensure OkHttp uses your trust store:

import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody
import com.launchdarkly.eventsource.EventSource
import com.launchdarkly.eventsource.EventHandler
import java.security.KeyStore
import javax.net.ssl.SSLContext
import javax.net.ssl.TrustManagerFactory
import java.io.FileInputStream

// Load custom PKCS12 trust store
def trustStorePath = "/path/to/custom-truststore.p12"
def trustStorePassword = "your-store-password".toCharArray()

KeyStore trustStore = KeyStore.getInstance("PKCS12")
trustStore.load(new FileInputStream(trustStorePath), trustStorePassword)

// Initialize TrustManagerFactory
TrustManagerFactory tmf = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm())
tmf.init(trustStore)

// Create SSL Context
SSLContext sslContext = SSLContext.getInstance("TLS")
sslContext.init(null, tmf.getTrustManagers(), null)

// Build OkHttpClient with custom SSL context
OkHttpClient client = new OkHttpClient.Builder()
    .sslSocketFactory(sslContext.getSocketFactory(), (X509TrustManager)tmf.getTrustManagers()[0])
    .build()

// Build POST request for SSE
Request request = new Request.Builder()
    .url("https://your-sse-endpoint.com")
    .post(RequestBody.create("your-post-payload".getBytes()))
    .build()

// Implement EventHandler logic
EventHandler eventHandler = new EventHandler() {
    void onOpen() { /* Handle connection open */ }
    void onMessage(String event, String data) { /* Process SSE messages */ }
    void onError(Throwable t) { /* Handle errors */ }
    void onClosed() { /* Handle connection close */ }
}

// Initialize and start EventSource
EventSource eventSource = new EventSource.Builder(eventHandler, request)
    .client(client)
    .build()

eventSource.start()

4. Verification Steps

  • Confirm trust store path and password are correct (no typos, JMeter has read permissions for the file)
  • Check jmeter.log for remaining SSL-related errors
  • Use JMeter's SSL Manager (Options > SSL Manager) to select your PKCS12 store (GUI-only for testing)

内容的提问来源于stack exchange,提问作者Sameer Rajimwale

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 03:18:10