You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Grizzly+Glassfish Tyrus的WebSocket服务器配置SSL证书

解决Grizzly + Tyrus配置WSS(安全WebSocket)服务器的问题

要为你的Tyrus WebSocket服务器配置WSS,不能直接使用org.glassfish.tyrus.server.Server的简单构造函数,需要手动配置Grizzly的HttpServer并启用SSL,再将Tyrus端点部署到该服务器上。以下是具体实现步骤:

核心修改思路

  • 使用Grizzly的NetworkListener配置SSL上下文,替代Tyrus默认的无SSL监听
  • 手动创建HttpServer实例并绑定SSL监听
  • 通过GrizzlyServerContainer将WebSocket端点部署到配置好的HttpServer上

修改后的代码实现

调整startServer方法

替换原来的startServer逻辑,改为以下实现:

public static void startServer(String keystorePath, String keystorePassword) {
    try {
        if (typeServer) {
            conip = "localhost";
        } else {
            conip = "45.8.133.57";
        }

        // 创建Grizzly SSL上下文配置器
        SSLContextConfigurator sslConfig = createGrizzlySSLContext(keystorePath, keystorePassword);

        // 创建HttpServer并配置SSL监听
        HttpServer httpServer = new HttpServer();
        NetworkListener listener = new NetworkListener("grizzly", conip, 8082);
        listener.setSecure(true);
        listener.setSSLEngineConfig(sslConfig.createSSLEngineConfig());
        
        httpServer.addListener(listener);

        // 部署WebSocket端点
        ServerContainer serverContainer = GrizzlyServerContainer.getServerContainer(httpServer);
        ServerEndpointConfig config = ServerEndpointConfig.Builder.create(WSS.class, endpoint).build();
        serverContainer.addEndpoint(config);

        // 启动服务器
        httpServer.start();
        
        System.out.println("Websocket ip: wss://" + conip + ":8082" + endpoint);
        System.out.println("WebSocket Server started on IP " + conip + ". Press Ctrl+C to stop.");
        
        Thread.currentThread().join(); // 保持线程存活

    } catch (Exception e) {
        e.printStackTrace();
    }
}

替换SSL上下文创建方法

使用Grizzly原生的SSLContextConfigurator来创建SSL上下文,避免客户端/服务端API混用:

private static SSLContextConfigurator createGrizzlySSLContext(String keystorePath, String keystorePassword) throws KeyStoreException, IOException, NoSuchAlgorithmException, CertificateException, UnrecoverableKeyException, KeyManagementException {
    SSLContextConfigurator sslConfig = new SSLContextConfigurator();
    
    // 配置密钥库
    sslConfig.setKeyStoreFile(keystorePath);
    sslConfig.setKeyStorePass(keystorePassword);
    sslConfig.setKeyPass(keystorePassword);
    
    // 配置信任库(如果需要双向认证可以调整)
    sslConfig.setTrustStoreFile(keystorePath);
    sslConfig.setTrustStorePass(keystorePassword);
    
    return sslConfig;
}

关键说明

  • 移除了原代码中Tyrus客户端的SslContextConfigurator和SslEngineConfigurator,改用Grizzly服务端的SSL配置API,避免类冲突
  • 通过NetworkListener.setSecure(true)启用SSL监听,确保所有WebSocket连接使用WSS协议
  • 不再依赖Tyrus的Server类,而是直接操作底层Grizzly服务器,获得更灵活的配置权限

验证注意事项

  1. 确保keystorePath指向正确的JKS文件路径(建议使用绝对路径避免路径问题)
  2. 客户端连接时必须使用wss://协议,而非ws://
  3. 如果使用自签名证书,客户端需要信任该证书或关闭证书验证(仅测试环境可用)

内容的提问来源于stack exchange,提问作者AttestedAtom675

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 23:37:02