在SoapUI中启用TLS时遭遇连接重置错误的求助
Hey there, let's tackle this frustrating connection reset error you're hitting when using SoapUI's JDBC test step to connect to Oracle. The key thing to spot here is that your current fixes (adding soapui.https.protocols etc.) are for SoapUI's HTTP/WS requests—they don't apply to JDBC connections to Oracle. That's why none of those changes have helped!
Let's walk through targeted fixes based on your error logs:
1. Stop using SoapUI-specific HTTPS parameters for JDBC
The parameters you added like -Dsoapui.https.protocols only affect web service calls in SoapUI. For Oracle JDBC connections, we need to use Oracle-specific JVM properties and JDBC URL settings instead.
2. Ensure your JDBC driver matches Oracle DB and JDK versions
Old Oracle JDBC drivers (like ojdbc6) don't support modern TLS protocols like TLSv1.2. If your Oracle DB is 12c or newer, use ojdbc8 for JDK 8+, or ojdbc11 for newer JDKs. Replace the existing ojdbc.jar in SoapUI's bin/ext folder with the correct version.
3. Configure JDBC URL with TLS settings
Update your SoapUI JDBC connection URL to explicitly use TCPS (TLS for Oracle) and specify compatible TLS versions/cipher suites. Here's an example:
jdbc:oracle:thin:@(DESCRIPTION=(ADDRESS=(PROTOCOL=TCPS)(HOST=your-db-host)(PORT=2483))(CONNECT_DATA=(SERVICE_NAME=your-db-service))(SECURITY=(SSL_SERVER_CERT_DN="CN=your-db-certificate-dn")))?oracle.net.ssl_version=TLSv1.2&oracle.net.ssl_cipher_suites=(AES256-SHA256)
- Replace
your-db-host,your-db-service, andyour-db-certificate-dnwith your actual values. - The
SSL_SERVER_CERT_DNensures you're connecting to the correct server (prevents MITM attacks).
4. Add Oracle-specific JVM parameters to SoapUI's vmoptions
Edit your SoapUI .vmoptions file (or test-runner.sh) and add these properties instead of the ones you tried before:
-Doracle.net.ssl_version=TLSv1.2 -Doracle.net.ssl_cipher_suites=(AES256-SHA256) -Djavax.net.ssl.trustStore=/path/to/your/truststore.jks -Djavax.net.ssl.trustStorePassword=your-truststore-password
- The truststore must contain the Oracle server's SSL certificate (ask your DBA for this, or export it using
keytool). - If you don't need strict certificate validation (not recommended for production), you can add
-Doracle.net.ssl_server_dn_match=falsetemporarily to test.
5. Verify Oracle Server's TLS Configuration
Check with your DBA that the Oracle server's SQLNET.ORA file has matching TLS settings:
SQLNET.AUTHENTICATION_SERVICES=(TCPS) SSL_VERSION=TLSv1.2 SSL_CIPHER_SUITES=(AES256-SHA256) SSL_CLIENT_AUTHENTICATION=FALSE
If the server is using a different cipher suite or TLS version, your client settings won't match, leading to a connection reset.
6. Rule out Network Issues
- Confirm that the TCPS port (default 2483) is open in your firewall between SoapUI and the Oracle server.
- Check if any proxy or security tool is intercepting and blocking TLS traffic to the DB.
Why Your Previous Fixes Didn't Work
Looking at your stack trace:
Caused by: java.io.IOException: An existing connection was forcibly closed by the remote host
at oracle.jdbc.driver.T4CConnection.logon(T4CConnection.java:874)
This error happens during the Oracle JDBC handshake, not during an HTTP request. SoapUI's soapui.https.* parameters don't influence this process at all—they're only for web service calls. That's why changing cipher suites there had no effect.
内容的提问来源于stack exchange,提问作者Utsav vats

