You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在SoapUI中启用TLS时遭遇连接重置错误的求助

Fixing "Connection reset by peer" TLS Error for Oracle JDBC in SoapUI

Hey there, let's tackle this frustrating connection reset error you're hitting when using SoapUI's JDBC test step to connect to Oracle. The key thing to spot here is that your current fixes (adding soapui.https.protocols etc.) are for SoapUI's HTTP/WS requests—they don't apply to JDBC connections to Oracle. That's why none of those changes have helped!

Let's walk through targeted fixes based on your error logs:

1. Stop using SoapUI-specific HTTPS parameters for JDBC

The parameters you added like -Dsoapui.https.protocols only affect web service calls in SoapUI. For Oracle JDBC connections, we need to use Oracle-specific JVM properties and JDBC URL settings instead.

2. Ensure your JDBC driver matches Oracle DB and JDK versions

Old Oracle JDBC drivers (like ojdbc6) don't support modern TLS protocols like TLSv1.2. If your Oracle DB is 12c or newer, use ojdbc8 for JDK 8+, or ojdbc11 for newer JDKs. Replace the existing ojdbc.jar in SoapUI's bin/ext folder with the correct version.

3. Configure JDBC URL with TLS settings

Update your SoapUI JDBC connection URL to explicitly use TCPS (TLS for Oracle) and specify compatible TLS versions/cipher suites. Here's an example:

jdbc:oracle:thin:@(DESCRIPTION=(ADDRESS=(PROTOCOL=TCPS)(HOST=your-db-host)(PORT=2483))(CONNECT_DATA=(SERVICE_NAME=your-db-service))(SECURITY=(SSL_SERVER_CERT_DN="CN=your-db-certificate-dn")))?oracle.net.ssl_version=TLSv1.2&oracle.net.ssl_cipher_suites=(AES256-SHA256)
  • Replace your-db-host, your-db-service, and your-db-certificate-dn with your actual values.
  • The SSL_SERVER_CERT_DN ensures you're connecting to the correct server (prevents MITM attacks).

4. Add Oracle-specific JVM parameters to SoapUI's vmoptions

Edit your SoapUI .vmoptions file (or test-runner.sh) and add these properties instead of the ones you tried before:

-Doracle.net.ssl_version=TLSv1.2
-Doracle.net.ssl_cipher_suites=(AES256-SHA256)
-Djavax.net.ssl.trustStore=/path/to/your/truststore.jks
-Djavax.net.ssl.trustStorePassword=your-truststore-password
  • The truststore must contain the Oracle server's SSL certificate (ask your DBA for this, or export it using keytool).
  • If you don't need strict certificate validation (not recommended for production), you can add -Doracle.net.ssl_server_dn_match=false temporarily to test.

5. Verify Oracle Server's TLS Configuration

Check with your DBA that the Oracle server's SQLNET.ORA file has matching TLS settings:

SQLNET.AUTHENTICATION_SERVICES=(TCPS)
SSL_VERSION=TLSv1.2
SSL_CIPHER_SUITES=(AES256-SHA256)
SSL_CLIENT_AUTHENTICATION=FALSE

If the server is using a different cipher suite or TLS version, your client settings won't match, leading to a connection reset.

6. Rule out Network Issues

  • Confirm that the TCPS port (default 2483) is open in your firewall between SoapUI and the Oracle server.
  • Check if any proxy or security tool is intercepting and blocking TLS traffic to the DB.

Why Your Previous Fixes Didn't Work

Looking at your stack trace:

Caused by: java.io.IOException: An existing connection was forcibly closed by the remote host
at oracle.jdbc.driver.T4CConnection.logon(T4CConnection.java:874)

This error happens during the Oracle JDBC handshake, not during an HTTP request. SoapUI's soapui.https.* parameters don't influence this process at all—they're only for web service calls. That's why changing cipher suites there had no effect.


内容的提问来源于stack exchange,提问作者Utsav vats

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 09:17:37