JDK 11及更高版本TLS 1.3并发握手失败问题排查
TLS 1.3 Concurrent Connection Handshake Failure in OpenJDK 11/15
Let’s break down this issue clearly:
- Core Problem: Even though TLS 1.3 is theoretically supported in JDK 11, when multiple concurrent threads try to establish connections, all initial handshakes fail.
- Reported Fixed Versions: Oracle JDK 11.0.2 and OpenJDK 11.0.3 were claimed to resolve this handshake failure issue.
- Issue Persists in Newer Builds: Unfortunately, when running test code in OpenJDK 11.0.9.11-hotspot and OpenJDK 15.0.1.9-hotspot, we still see the error:
javax.net.ssl.SSLHandshakeException: Received fatal alert: handshake_failure - Temporary (But Not Ideal) Workaround: You can disable TLS 1.3 using JVM arguments to avoid the error. For example:
or-Djdk.tls.client.protocols="TLSv1.2"
Keep in mind this is only a short-term fix—disabling TLS 1.3 means missing out on its improved security and performance features, so it’s not a viable long-term solution.-Dhttps.protocols="TLSv1.2"
SSL Debug Log Snippet
javax.net.ssl|DEBUG|03|Thread-2|2024-05-20 09:15:00.789 UTC|ClientHello.java:654|Sending ClientHello message javax.net.ssl|ERROR|03|Thread-2|2024-05-20 09:15:00.901 UTC|Alert.java:232|Received alert message (Alert Severity: FATAL, Alert Description: handshake_failure)
内容的提问来源于stack exchange,提问作者Carsten
相关产品推荐
相关产品推荐

