如何配置WildFly的messaging-activemq子系统使JMS连接用主机名
问题:WildFly 26.1.3 JMS连接使用IP地址导致SSL证书验证失败
我有一个运行在WildFly 26.1.3上的应用,已配置为仅使用HTTPS。几乎所有配置都已完成,但messaging-activemq子系统生成的JMS连接存在问题:该子系统创建的远程JMS连接对象使用服务器IP地址而非主机名或完全限定域名(FQDN)作为连接URL,这导致SSL证书验证失败。
客户端问题代码示例
// 使用JNDI从WildFly服务器获取TopicConnectionFactory Hashtable<String, String> p = new Hashtable<String, String>(); p.put(Context.INITIAL_CONTEXT_FACTORY, "org.wildfly.naming.client.WildFlyInitialContextFactory"); p.put(Context.PROVIDER_URL, "https://<serverFQDN>:9090"); Context jndiContext; jndiContext = new InitialContext(p); myTopicConnFac = (TopicConnectionFactory)jndiContext.lookup(topicConnFacName); // JNDI查找成功 myTopicConnection = myTopicConnFac.createTopicConnection(); // 因使用IP地址抛出SSL连接错误
是否存在配置选项可以让TopicConnectionFactory使用主机名而非IP地址?
现有standalone.xml相关配置片段
... <subsystem xmlns="urn:jboss:domain:messaging-activemq:13.1"> <server name="default"> <statistics enabled="${wildfly.messaging-activemq.statistics-enabled:${wildfly.statistics-enabled:false}}"/> <security enabled="false"/> <address-setting name="#" dead-letter-address="jms.queue.DLQ" expiry-address="jms.queue.ExpiryQueue" max-size-bytes="10485760" page-size-bytes="2097152" message-counter-history-day-limit="10"/> <http-connector name="https-connector" socket-binding="https" endpoint="https-acceptor"> <param name="ssl-enabled" value="true"/> </http-connector> <http-connector name="https-connector-throughput" socket-binding="https" endpoint="https-acceptor-throughput"> <param name="batch-delay" value="50"/> </http-connector> <http-acceptor name="https-acceptor" http-listener="default"/> <http-acceptor name="https-acceptor-throughput" http-listener="default"> <param name="batch-delay" value="50"/> <param name="direct-deliver" value="false"/> </http-acceptor> ... <connection-factory name="RemoteConnectionFactory" retry-interval="1000" reconnect-attempts="1000" entries="java:jboss/exported/jms/RemoteConnectionFactory java:jboss/exported/com.rsc.mmpl.TopicConnectionFactory java:jboss/exported/com.rsc.mmpl.Log4jTopicConnectionFactory" connectors="http-connector"/> </server> <subsystem/> ... <interfaces> ... <!-- jboss.bind.address已设置为服务器的FQDN,而非IP地址 --> <interface name="public"> <inet-address value="${jboss.bind.address:127.0.0.1}"/> </interface> </interfaces> <socket-binding-group name="standard-sockets" default-interface="public" port-offset="${jboss.socket.binding.port-offset:0}"> ... <socket-binding name="https" port="${jboss.https.port:9090}"/> ... </socket-binding-group>
我曾尝试在http-connector部分添加多个参数(local-address、host、hostname),但均无效。
解决方案
要让messaging-activemq子系统返回的连接工厂使用主机名而非IP地址,需在http-connector中添加publish-host参数,指定服务器的FQDN。修改后的http-connector配置如下:
<http-connector name="https-connector" socket-binding="https" endpoint="https-acceptor"> <param name="ssl-enabled" value="true"/> <param name="publish-host" value="your-server-fqdn"/> </http-connector> <http-connector name="https-connector-throughput" socket-binding="https" endpoint="https-acceptor-throughput"> <param name="batch-delay" value="50"/> <param name="publish-host" value="your-server-fqdn"/> </http-connector>
关键说明
publish-host参数会强制连接器对外发布指定的主机名,覆盖系统自动解析的IP地址,确保客户端获取的连接URL使用正确的FQDN。- 替换
your-server-fqdn为实际的服务器域名,必须与SSL证书中包含的主机名完全一致,避免验证失败。 - 修改配置后需重启WildFly服务,使配置生效。
额外检查项
确认Undertow子系统的http-listener配置,避免因监听IP导致的地址异常:
<subsystem xmlns="urn:jboss:domain:undertow:12.0"> <server name="default-server"> <http-listener name="default" socket-binding="https" ssl-context="applicationSSLSecure" enable-http2="true"/> ... </server> ... </subsystem>
如果http-listener绑定的是IP,建议改为绑定FQDN或0.0.0.0(仍需配合publish-host指定正确域名)。
内容的提问来源于stack exchange,提问作者Psirax
相关产品推荐
相关产品推荐

