WSO2 APIM内部调用超时:配置明文HTTP或替换SSL证书
WSO2 APIM 4.2 后端API调用超时问题解决
问题背景
从WSO2 APIM 2.6升级到4.2版本,采用Ansible管理部署。本地虚拟机环境运行正常,但生产服务器上UI、API注册功能正常,后端API调用却失败。抓包发现WSO2内部向自身8243端口的请求超时,未触发对后端服务器的调用(服务器可手动访问后端)。手动调用8243端口时出现自签名证书错误,架构为单节点APIM部署在Apache HTTPD反向代理之后。
需求:
- 优先配置代理到WSO2的请求及WSO2内部请求使用明文HTTP
- 若上述方案不可行,配置有效SSL证书
相关日志:
TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.passthru.SourceHandler} - http-incoming-36: Timeout TID: [] [] [2023-05-16 10:42:38,078] INFO {org.apache.synapse.transport.passthru.SourceHandler} - Writer null when calling informWriterError TID: [] [] [2023-05-16 10:42:38,078] WARN {org.apache.synapse.transport.passthru.SourceHandler} - STATE_DESCRIPTION = Socket Timeout occurred after accepting the request headers and the request body, INTERNAL_STATE = REQUEST_DONE, DIRECTION = REQUEST, CAUSE_OF_ERROR = Connection between the client and the EI timeouts, HTTP_URL = /integrations/scim/carcwso2/v1/integrations/scim/v2/Users/apiuser, HTTP_METHOD = GET, SOCKET_TIMEOUT = 180000, CLIENT_ADDRESS = /10.0.100.60:33982, CONNECTION http-incoming-36 Correlation ID : 1b58ec31-3bbd-4e5e-a197-d18f67424aef TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.passthru.connections.SourceConnections} - Shutting down connection forcefully http-incoming-36 TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.http.conn.LoggingNHttpServerConnection} - http-incoming-36: Shutdown connection TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.http.nio.reactor.ssl.SSLIOSession} - I/O session http-incoming-36-36 10.0.100.60:8243<->10.0.100.60:33982[ACTIVE][:r][ACTIVE][][NOT_HANDSHAKING][0][0][0]: Shutdown TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.passthru.SourceHandler} - http-incoming-36: Closed TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.passthru.SourceHandler} - http-incoming-36: Keep-Alive connection was closed: Remote Address : null TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.passthru.connections.SourceConnections} - Shutting down connection forcefully http-incoming-36 TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.http.conn.LoggingNHttpServerConnection} - http-incoming-36: Shutdown connection TID: [] [] [2023-05-16 10:42:38,079] DEBUG {org.apache.http.nio.reactor.ssl.SSLIOSession} - I/O session http-incoming-36-36 [CLOSED][][CLOSED][][NOT_HANDSHAKING][0][0][0]: Shutdown TID: [] [] [2023-05-16 10:42:38,200] DEBUG {org.wso2.andes.kernel.disruptor.inbound.InboundEventManager} - [ Sequence: 3337 ] SAFE_ZONE_DECLARE_EVENT' published to Disruptor
解决方案一:切换为明文HTTP通信
1. 修改WSO2 APIM传输配置
编辑<APIM_HOME>/repository/conf/deployment.toml:
- 启用HTTP传输,禁用HTTPS:
[transport.http] listener.enabled = true listener.port = 8280 sender.enabled = true [transport.https] listener.enabled = false listener.port = 8243 sender.enabled = false
- 配置网关内部服务地址为HTTP:
[apim.gateway.environment] service_url = "http://localhost:8280/services/" type = "hybrid" display_name = "Production and Sandbox" description = "Hybrid gateway handling production and sandbox token traffic."
2. 调整Apache反向代理配置
更新虚拟主机配置,将请求转发到WSO2的8280端口:
ProxyPass / http://localhost:8280/ ProxyPassReverse / http://localhost:8280/
确保已启用proxy、proxy_http模块。
3. 检查API端点配置
在API Publisher中确认所有API的后端端点使用HTTP协议,网关路由指向正确的HTTP端口。
解决方案二:配置有效SSL证书
1. 准备可信CA证书
获取由公共CA(如Let’s Encrypt)签发的证书包,包含:
- 服务器证书(
.crt) - 私钥文件(
.key) - 中间证书(若有)
2. 导入证书到WSO2密钥库
使用keytool将证书导入默认密钥库:
keytool -importcert -file /path/to/server.crt -alias apim-prod-cert -keystore <APIM_HOME>/repository/resources/security/wso2carbon.jks -storepass wso2carbon
若使用自定义密钥库,在deployment.toml中添加:
[keystore.tls] file_name = "prod-keystore.jks" password = "your-keystore-pass" alias = "apim-prod-cert" key_password = "your-key-pass"
3. 配置HTTPS传输
更新deployment.toml的HTTPS设置:
[transport.https] listener.enabled = true listener.port = 8243 sender.enabled = true listener.ssl.hostname_verifier = "DefaultAndLocalhost" listener.ssl.certificate.password = "your-keystore-pass"
4. 信任后端证书(若后端用HTTPS)
将后端API的证书导入WSO2信任库:
keytool -importcert -file /path/to/backend.crt -alias backend-prod-cert -keystore <APIM_HOME>/repository/resources/security/client-truststore.jks -storepass wso2carbon
5. 内部服务URL配置
确保所有内部服务(如发布者、商店、网关)的通信URL使用HTTPS且匹配证书域名,例如:
[apim.publisher] url = "https://your-apim-domain:9443/publisher"
验证步骤
- 重启WSO2 APIM和Apache HTTPD服务
- 发起API调用,检查是否成功触发后端请求
- 查看WSO2日志,确认无SSL握手错误或超时信息
内容的提问来源于stack exchange,提问作者Adam
相关产品推荐
相关产品推荐

