You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2 APIM内部调用超时:配置明文HTTP或替换SSL证书

WSO2 APIM 4.2 后端API调用超时问题解决

问题背景

从WSO2 APIM 2.6升级到4.2版本,采用Ansible管理部署。本地虚拟机环境运行正常,但生产服务器上UI、API注册功能正常,后端API调用却失败。抓包发现WSO2内部向自身8243端口的请求超时,未触发对后端服务器的调用(服务器可手动访问后端)。手动调用8243端口时出现自签名证书错误,架构为单节点APIM部署在Apache HTTPD反向代理之后。

需求:

  • 优先配置代理到WSO2的请求及WSO2内部请求使用明文HTTP
  • 若上述方案不可行,配置有效SSL证书

相关日志:

TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.passthru.SourceHandler} - http-incoming-36: Timeout
TID: [] [] [2023-05-16 10:42:38,078]  INFO {org.apache.synapse.transport.passthru.SourceHandler} - Writer null when calling informWriterError
TID: [] [] [2023-05-16 10:42:38,078]  WARN {org.apache.synapse.transport.passthru.SourceHandler} - STATE_DESCRIPTION = Socket Timeout occurred after accepting the request headers and the request body, INTERNAL_STATE = REQUEST_DONE, DIRECTION = REQUEST, CAUSE_OF_ERROR = Connection between the client and the EI timeouts, HTTP_URL = /integrations/scim/carcwso2/v1/integrations/scim/v2/Users/apiuser, HTTP_METHOD = GET, SOCKET_TIMEOUT = 180000, CLIENT_ADDRESS = /10.0.100.60:33982, CONNECTION http-incoming-36 Correlation ID : 1b58ec31-3bbd-4e5e-a197-d18f67424aef
TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.passthru.connections.SourceConnections} - Shutting down connection forcefully http-incoming-36
TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.http.conn.LoggingNHttpServerConnection} - http-incoming-36: Shutdown connection
TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.http.nio.reactor.ssl.SSLIOSession} - I/O session http-incoming-36-36 10.0.100.60:8243<->10.0.100.60:33982[ACTIVE][:r][ACTIVE][][NOT_HANDSHAKING][0][0][0]: Shutdown
TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.passthru.SourceHandler} - http-incoming-36: Closed
TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.passthru.SourceHandler} - http-incoming-36: Keep-Alive connection was closed:  Remote Address : null
TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.passthru.connections.SourceConnections} - Shutting down connection forcefully http-incoming-36
TID: [] [] [2023-05-16 10:42:38,078] DEBUG {org.apache.synapse.transport.http.conn.LoggingNHttpServerConnection} - http-incoming-36: Shutdown connection
TID: [] [] [2023-05-16 10:42:38,079] DEBUG {org.apache.http.nio.reactor.ssl.SSLIOSession} - I/O session http-incoming-36-36 [CLOSED][][CLOSED][][NOT_HANDSHAKING][0][0][0]: Shutdown
TID: [] [] [2023-05-16 10:42:38,200] DEBUG {org.wso2.andes.kernel.disruptor.inbound.InboundEventManager} - [ Sequence: 3337 ] SAFE_ZONE_DECLARE_EVENT' published to Disruptor

解决方案一:切换为明文HTTP通信

1. 修改WSO2 APIM传输配置

编辑<APIM_HOME>/repository/conf/deployment.toml:

  • 启用HTTP传输,禁用HTTPS:
[transport.http]
listener.enabled = true
listener.port = 8280
sender.enabled = true

[transport.https]
listener.enabled = false
listener.port = 8243
sender.enabled = false
  • 配置网关内部服务地址为HTTP:
[apim.gateway.environment]
service_url = "http://localhost:8280/services/"
type = "hybrid"
display_name = "Production and Sandbox"
description = "Hybrid gateway handling production and sandbox token traffic."

2. 调整Apache反向代理配置

更新虚拟主机配置,将请求转发到WSO2的8280端口:

ProxyPass / http://localhost:8280/
ProxyPassReverse / http://localhost:8280/

确保已启用proxy、proxy_http模块。

3. 检查API端点配置

在API Publisher中确认所有API的后端端点使用HTTP协议,网关路由指向正确的HTTP端口。


解决方案二:配置有效SSL证书

1. 准备可信CA证书

获取由公共CA(如Let’s Encrypt)签发的证书包,包含:

  • 服务器证书(.crt)
  • 私钥文件(.key)
  • 中间证书(若有)

2. 导入证书到WSO2密钥库

使用keytool将证书导入默认密钥库:

keytool -importcert -file /path/to/server.crt -alias apim-prod-cert -keystore <APIM_HOME>/repository/resources/security/wso2carbon.jks -storepass wso2carbon

若使用自定义密钥库,在deployment.toml中添加:

[keystore.tls]
file_name = "prod-keystore.jks"
password = "your-keystore-pass"
alias = "apim-prod-cert"
key_password = "your-key-pass"

3. 配置HTTPS传输

更新deployment.toml的HTTPS设置:

[transport.https]
listener.enabled = true
listener.port = 8243
sender.enabled = true
listener.ssl.hostname_verifier = "DefaultAndLocalhost"
listener.ssl.certificate.password = "your-keystore-pass"

4. 信任后端证书(若后端用HTTPS)

将后端API的证书导入WSO2信任库:

keytool -importcert -file /path/to/backend.crt -alias backend-prod-cert -keystore <APIM_HOME>/repository/resources/security/client-truststore.jks -storepass wso2carbon

5. 内部服务URL配置

确保所有内部服务(如发布者、商店、网关)的通信URL使用HTTPS且匹配证书域名,例如:

[apim.publisher]
url = "https://your-apim-domain:9443/publisher"

验证步骤

  1. 重启WSO2 APIM和Apache HTTPD服务
  2. 发起API调用,检查是否成功触发后端请求
  3. 查看WSO2日志,确认无SSL握手错误或超时信息

内容的提问来源于stack exchange,提问作者Adam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 20:17:00