Quarkus项目SSL配置未识别导致无法启动,求助排查问题
问题排查:Quarkus SSL配置项未被识别导致启动失败
错误日志
Unrecognized configuration key "quarkus.http.ssl.certificate.key-store-type" was provided; it will be ignored; verify that the dependency extension for this configuration is set or that you did not make a typo Unrecognized configuration key "quarkus.http.ssl.port" was provided; it will be ignored; verify that the dependency extension for this configuration is set or that you did not make a typo Unrecognized configuration key "quarkus.http.ssl.certificate.key-password" was provided; it will be ignored; verify that the dependency extension for this configuration is set or that you did not make a typo Unrecognized configuration key "quarkus.http.ssl" was provided; it will be ignored; verify that the dependency extension for this configuration is set or that you did not make a typo
当前配置
application.properties
quarkus.http.ssl=true quarkus.http.ssl.port=3000 quarkus.http.ssl.certificate.key-store-file=/etc/letsencrypt/live/verseny.iranyazur.hu/keystore.p12 quarkus.http.ssl.certificate.key-password=password quarkus.http.ssl.certificate.key-store-type=PKCS12
pom.xml依赖片段
<dependency> <groupId>io.quarkus</groupId> <artifactId>quarkus-ssl</artifactId> </dependency> <dependency> <groupId>io.quarkus</groupId> <artifactId>quarkus-undertow</artifactId> </dependency>
密钥库验证结果
Keystore type: PKCS12 Keystore provider: SUN Your keystore contains 1 entry 1, 13 Sept 2023, PrivateKeyEntry, Certificate fingerprint (SHA-256): 73:21:26:CE:DA:D2:C9:06:B3:8B:09:8E:37:0F:A9:0B:BF:C2:6A:42:A3:2A:78:94:0C:8C:13:EA:28:95:A1:81
解决方案
1. 修正配置项名称(核心问题)
Quarkus 2.x及以上版本对SSL配置项做了调整:
quarkus.http.ssl=true需改为quarkus.http.ssl.enabled=truequarkus.http.ssl.port=3000需改为quarkus.http.ssl-port=3000(使用连字符而非点分隔)
修正后的application.properties:
quarkus.http.ssl.enabled=true quarkus.http.ssl-port=3000 quarkus.http.ssl.certificate.key-store-file=/etc/letsencrypt/live/verseny.iranyazur.hu/keystore.p12 quarkus.http.ssl.certificate.key-password=password quarkus.http.ssl.certificate.key-store-type=PKCS12
2. 验证依赖与版本兼容性
- 若使用Quarkus 3.x,
quarkus-undertow已被quarkus-undertow-web替代,需更新依赖:<dependency> <groupId>io.quarkus</groupId> <artifactId>quarkus-undertow-web</artifactId> </dependency> - 确保所有Quarkus依赖版本一致,避免因版本差异导致配置不兼容。
3. 检查配置加载干扰
- 排查是否存在其他配置文件(如
application-dev.properties)、环境变量或系统属性覆盖了当前SSL配置。 - 启动时添加
-Dquarkus.log.level=DEBUG,查看配置加载日志,确认目标配置项是否被正确读取。
4. 二次确认密钥库访问
- 建议将密钥库权限从
777调整为更安全的600,并确保运行Quarkus进程的用户拥有文件所有权。 - 若运行在容器中,需确认密钥库文件已正确挂载到容器内指定路径。
内容的提问来源于stack exchange,提问作者Gergő Szabó
相关产品推荐
相关产品推荐

