You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Micro Integrator 4.2.0连接SQL Server 2012生产环境(K8s)TLS兼容错误

解决Micro Integrator 4.2.0在K8s中连接SQL Server 2012的TLS版本兼容问题

问题场景

本地环境中,使用Micro Integrator 4.2.0配置数据服务连接SQL Server 2012时,以下配置可正常运行:

<config id="mscrm">    
<property name="driverClassName">com.microsoft.sqlserver.jdbc.SQLServerDriver</property>    
<property name="url">jdbc:sqlserver://********:1433;databaseName=********;integratedSecurity=false;encrypt=false</property>    
<property name="username">*******</property>    
<property name="password">********</property>  
</config>

但部署到Kubernetes集群的生产实例时,出现如下错误:

com.microsoft.sqlserver.jdbc.SQLServerException: The driver could not establish a secure connection to SQL Server by using Secure Sockets Layer (SSL) encryption. Error: "The server selected protocol version TLS10 is not accepted by client preferences [TLS13, TLS12]". ClientConnectionId:17a956f9-6d42-484f-9cff-62af192ad2f7

        at org.wso2.micro.integrator.dataservices.core.description.config.RDBMSConfig.<init>(RDBMSConfig.java:39)
        at org.wso2.micro.integrator.dataservices.core.description.config.ConfigFactory.getRDBMSConfig(ConfigFactory.java:91)
        at org.wso2.micro.integrator.dataservices.core.description.config.ConfigFactory.createConfig(ConfigFactory.java:59)
        at org.wso2.micro.integrator.dataservices.core.DataServiceFactory.createDataService(DataServiceFactory.java:168)
        at org.wso2.micro.integrator.dataservices.core.DBDeployer.createDBService(DBDeployer.java:819)
        at org.wso2.micro.integrator.dataservices.core.DBDeployer.processService(DBDeployer.java:1182)

错误根源

SQL Server 2012默认启用TLS 1.0,而Kubernetes环境中Micro Integrator运行的JVM默认禁用了TLS 1.0,仅支持TLS 1.2和1.3,导致握手协议版本不匹配。


解决方案

方案1:升级SQL Server的TLS版本(推荐,符合安全规范)

SQL Server 2012支持升级到TLS 1.2,操作步骤:

  • 安装SQL Server 2012最新服务包(至少SP4)及补丁KB3135244,确保服务器具备TLS 1.2支持能力。
  • 修改Windows注册表配置:
    1. 打开注册表编辑器,定位到HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols
    2. 若不存在TLS 1.0\Server和TLS 1.2\Server项,手动创建
    3. 在TLS 1.0\Server下新建DWORD值Enabled,设置为0(禁用TLS1.0)
    4. 在TLS 1.2\Server下新建DWORD值Enabled,设置为1(启用TLS1.2)
  • 重启SQL Server服务使配置生效。

方案2:调整Micro Integrator的JVM参数,允许TLS 1.0(临时 workaround)

若暂时无法升级SQL Server的TLS版本,可修改K8s中MI的JVM启动参数,允许客户端使用TLS 1.0:

  • 在MI的K8s部署配置(Deployment.yaml)中添加环境变量:
    env:
      - name: JAVA_OPTS
        value: "-Djdk.tls.client.protocols=TLSv1,TLSv1.1,TLSv1.2,TLSv1.3"
    
  • 或调整JVM的java.security文件,找到jdk.tls.disabledAlgorithms配置项,移除其中的TLSv1,再重新部署MI。

方案3:验证JDBC驱动版本

确保使用的SQL Server JDBC驱动版本支持TLS 1.2,推荐使用Microsoft JDBC Driver 6.0及以上版本(适配SQL Server 2012)。若K8s环境中驱动版本与本地不一致,需同步为相同版本。

内容的提问来源于stack exchange,提问作者Oussama Nairi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 17:02:51