JMeter SSE脚本遇TrustStore相关SSL错误,求解决方案
1. Fix Default Trust Store Import (Root Cause of Initial SSL Handshake Failure)
Java 21 uses PKCS12 as the default trust store format (file: cacerts.p12), replacing the legacy JKS cacerts file. Your initial certificate import to the JKS store had no effect because Java 21 wasn't using it. To resolve:
- Locate your Azul Zulu JDK 21's trust store path (typically
<zulu-jdk-21>/lib/security/cacerts.p12) - Import the target certificate into this PKCS12 store using keytool:
keytool -importcert -file /path/to/your/certificate.crt -keystore <zulu-jdk-21>/lib/security/cacerts.p12 -storetype PKCS12 -alias "sse-server-cert"- Default password for
cacerts.p12ischangeit
- Default password for
- Restart JMeter after the import.
2. Resolve Custom Trust Store Access Error
The no such algorithm: jks for provider SunJSSE error occurs because Java 21's SunJSSE provider no longer supports JKS. Use PKCS12 for custom trust stores instead:
Step 1: Create a PKCS12 Trust Store
If you need a custom trust store (instead of modifying the default), generate one with PKCS12:
keytool -importcert -file /path/to/certificate.crt -keystore /path/to/custom-truststore.p12 -storetype PKCS12 -alias "sse-server-cert"
Step 2: Configure JMeter to Use the Custom PKCS12 Store
Choose one of these methods:
Option A: Via JMeter Configuration Files
Add these lines to system.properties:
javax.net.ssl.trustStore=/path/to/custom-truststore.p12 javax.net.ssl.trustStorePassword=your-store-password javax.net.ssl.trustStoreType=PKCS12
Option B: Directly in JSR223 Script (Before EventSource Setup)
System.setProperty("javax.net.ssl.trustStore", "/path/to/custom-truststore.p12") System.setProperty("javax.net.ssl.trustStorePassword", "your-store-password") System.setProperty("javax.net.ssl.trustStoreType", "PKCS12")
3. Custom SSL Context for OkHttp EventSource (Alternative Reliable Approach)
If system-wide trust store changes don't work, configure a custom SSL context directly in your script to ensure OkHttp uses your trust store:
import okhttp3.OkHttpClient import okhttp3.Request import okhttp3.RequestBody import com.launchdarkly.eventsource.EventSource import com.launchdarkly.eventsource.EventHandler import java.security.KeyStore import javax.net.ssl.SSLContext import javax.net.ssl.TrustManagerFactory import java.io.FileInputStream // Load custom PKCS12 trust store def trustStorePath = "/path/to/custom-truststore.p12" def trustStorePassword = "your-store-password".toCharArray() KeyStore trustStore = KeyStore.getInstance("PKCS12") trustStore.load(new FileInputStream(trustStorePath), trustStorePassword) // Initialize TrustManagerFactory TrustManagerFactory tmf = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm()) tmf.init(trustStore) // Create SSL Context SSLContext sslContext = SSLContext.getInstance("TLS") sslContext.init(null, tmf.getTrustManagers(), null) // Build OkHttpClient with custom SSL context OkHttpClient client = new OkHttpClient.Builder() .sslSocketFactory(sslContext.getSocketFactory(), (X509TrustManager)tmf.getTrustManagers()[0]) .build() // Build POST request for SSE Request request = new Request.Builder() .url("https://your-sse-endpoint.com") .post(RequestBody.create("your-post-payload".getBytes())) .build() // Implement EventHandler logic EventHandler eventHandler = new EventHandler() { void onOpen() { /* Handle connection open */ } void onMessage(String event, String data) { /* Process SSE messages */ } void onError(Throwable t) { /* Handle errors */ } void onClosed() { /* Handle connection close */ } } // Initialize and start EventSource EventSource eventSource = new EventSource.Builder(eventHandler, request) .client(client) .build() eventSource.start()
4. Verification Steps
- Confirm trust store path and password are correct (no typos, JMeter has read permissions for the file)
- Check
jmeter.logfor remaining SSL-related errors - Use JMeter's SSL Manager (Options > SSL Manager) to select your PKCS12 store (GUI-only for testing)
内容的提问来源于stack exchange,提问作者Sameer Rajimwale

