SpringBoot调用CRM系统HTTPS服务时SSL证书匹配异常求助
解决SpringBoot调用HTTPS服务时的SSL证书SAN不匹配问题
你遇到的错误核心是SSL证书的**主题备用名称(SAN)**与请求的主机名不匹配:
org.springframework.web.client.ResourceAccessException: I/O error on POST request for "https://host.company.corp.ae:8243/ISCP.Integration/api/CRMDocument/CreateCustomerRejectionFeedback": Certificate for <host.company.corp.ae> doesn't match any of the subject alternative names: [host]; nested exception is javax.net.ssl.SSLPeerUnverifiedException: Certificate for <host.company.corp.ae> doesn't match any of the subject alternative names: [host]
下面是具体的解决方案:
- 修正请求地址:CRM服务的SSL证书仅把
host配置为合法主机名,直接将请求地址改为https://host:8243/ISCP.Integration/api/CRMDocument/CreateCustomerRejectionFeedback,保证请求主机名和证书SAN完全一致。 - 更新CRM服务证书:联系CRM运维团队,将
host.company.corp.ae添加到证书的SAN列表中,这是合规的长期解决方案,从根源上避免证书验证问题。 - 测试环境临时绕过验证:仅限测试场景使用,生产环境绝对不能这么做(会引入严重安全风险)。可以通过自定义RestTemplate忽略SSL校验:
@Bean public RestTemplate restTemplate() throws KeyStoreException, NoSuchAlgorithmException, KeyManagementException { // 信任所有证书(仅测试用) TrustStrategy acceptingTrustStrategy = (X509Certificate[] chain, String authType) -> true; SSLContext sslContext = org.apache.http.ssl.SSLContexts.custom() .loadTrustMaterial(null, acceptingTrustStrategy) .build(); SSLConnectionSocketFactory csf = new SSLConnectionSocketFactory(sslContext); CloseableHttpClient httpClient = HttpClients.custom() .setSSLSocketFactory(csf) .build(); HttpComponentsClientHttpRequestFactory requestFactory = new HttpComponentsClientHttpRequestFactory(); requestFactory.setHttpClient(httpClient); return new RestTemplate(requestFactory); }
- 本地hosts映射临时处理:如果必须用
host.company.corp.ae地址,可在本地/服务器的hosts文件添加映射:[CRM服务实际IP] host,让域名解析到证书认可的主机名对应的IP,这只是临时本地 workaround,不适合全局部署。
内容的提问来源于stack exchange,提问作者SrikanthM
相关产品推荐
相关产品推荐

