You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2 4.0.0自注册遇Unexpected Error,日志报SSL证书不匹配

WSO2 Identity Server 4.0.0自注册「Unexpected Error」问题解决

在WSO2 Identity Server 4.0.0版本中,点击「继续自注册」按钮时触发「Unexpected Error」,无法完成注册流程。相关错误日志如下:

TID: [-1234] [accountrecoveryendpoint] [2023-02-10 10:11:38,270] ERROR {org.wso2.carbon.identity.mgt.endpoint.util.IdentityManagementEndpointUtil} - Exception while retrieving error details from original exception. Original exception: org.wso2.carbon.identity.mgt.endpoint.util.client.SelfRegistrationMgtClientException: Error while check username validity for user : john Caused by: javax.net.ssl.SSLPeerUnverifiedException: Certificate for doesn't match any of the subject alternative names: []

错误根源

日志明确指向SSL证书验证异常:localhost对应的SSL证书未配置任何主题备用名称(SAN),导致证书验证失败,进而中断自注册流程。

解决步骤

  • 生成包含localhost作为SAN的SSL证书
    使用keytool工具生成符合要求的证书,示例命令:
    keytool -genkeypair -alias wso2carbon -keyalg RSA -keysize 2048 -storetype JKS -keystore wso2carbon.jks -dname "CN=localhost, OU=WSO2, O=WSO2, L=Colombo, ST=Western, C=LK" -ext SAN=DNS:localhost -validity 3650
    
  • 替换WSO2服务中的证书
    将生成的wso2carbon.jks替换到<IS_HOME>/repository/resources/security/目录,覆盖原有文件。
  • 更新证书配置参数
    检查<IS_HOME>/repository/conf/deployment.toml中的SSL配置,确保引用的证书文件和密码正确,示例配置:
    [transport.https.properties]
    sslEnabled = true
    keyStoreFile = "${carbon.home}/repository/resources/security/wso2carbon.jks"
    keyStorePassword = "wso2carbon"
    trustStoreFile = "${carbon.home}/repository/resources/security/client-truststore.jks"
    trustStorePassword = "wso2carbon"
    
  • 重启WSO2 Identity Server服务
    完成配置后重启服务,使新证书生效。

内容的提问来源于stack exchange,提问作者Chinnu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 07:50:14