WSO2 4.0.0自注册遇Unexpected Error,日志报SSL证书不匹配
WSO2 Identity Server 4.0.0自注册「Unexpected Error」问题解决
在WSO2 Identity Server 4.0.0版本中,点击「继续自注册」按钮时触发「Unexpected Error」,无法完成注册流程。相关错误日志如下:
TID: [-1234] [accountrecoveryendpoint] [2023-02-10 10:11:38,270] ERROR {org.wso2.carbon.identity.mgt.endpoint.util.IdentityManagementEndpointUtil} - Exception while retrieving error details from original exception. Original exception: org.wso2.carbon.identity.mgt.endpoint.util.client.SelfRegistrationMgtClientException: Error while check username validity for user : john Caused by: javax.net.ssl.SSLPeerUnverifiedException: Certificate for
doesn't match any of the subject alternative names: []
错误根源
日志明确指向SSL证书验证异常:localhost对应的SSL证书未配置任何主题备用名称(SAN),导致证书验证失败,进而中断自注册流程。
解决步骤
- 生成包含localhost作为SAN的SSL证书
使用keytool工具生成符合要求的证书,示例命令:keytool -genkeypair -alias wso2carbon -keyalg RSA -keysize 2048 -storetype JKS -keystore wso2carbon.jks -dname "CN=localhost, OU=WSO2, O=WSO2, L=Colombo, ST=Western, C=LK" -ext SAN=DNS:localhost -validity 3650 - 替换WSO2服务中的证书
将生成的wso2carbon.jks替换到<IS_HOME>/repository/resources/security/目录,覆盖原有文件。 - 更新证书配置参数
检查<IS_HOME>/repository/conf/deployment.toml中的SSL配置,确保引用的证书文件和密码正确,示例配置:[transport.https.properties] sslEnabled = true keyStoreFile = "${carbon.home}/repository/resources/security/wso2carbon.jks" keyStorePassword = "wso2carbon" trustStoreFile = "${carbon.home}/repository/resources/security/client-truststore.jks" trustStorePassword = "wso2carbon" - 重启WSO2 Identity Server服务
完成配置后重启服务,使新证书生效。
内容的提问来源于stack exchange,提问作者Chinnu
相关产品推荐
相关产品推荐

