You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SonarQube安全邮件配置失败求助及SMTP用户名设置咨询

Troubleshooting SonarQube Secure SMTP Connection Issues & SMTP Username Clarification

First off, let’s clarify the SMTP username question: 9 times out of 10, you need to enter your full email address (e.g., jane.smith@company.com). Some legacy mail servers might accept just the local part (like jane.smith), but modern providers (Gmail, Outlook, most enterprise systems) require the full address to authenticate properly. If you’re using an on-prem mail server, confirm with your admin if a shortened username is allowed—but start with the full email first.

Now, let’s walk through fixing your secure SMTP connection problems with both SSL (port 465) and STARTTLS (port 587):

General Pre-Checks (Do These First!)

  • Verify network access: From the SonarQube server, run a telnet test to confirm the port is reachable:
    # For SSL (465)
    telnet your-smtp-server.com 465
    # For STARTTLS (587)
    telnet your-smtp-server.com 587
    
    If this fails, your firewall or network is blocking the connection—work with your ops team to open the port.
  • Double-check credentials: Ensure your password is correct (copy-paste to avoid typos) and that your account isn’t locked. If 2FA is enabled on your email account, you’ll need to use an app-specific password instead of your regular login password.
  • Check SonarQube logs: The logs (usually in $SONARQUBE_HOME/logs/sonar.log) will have detailed error messages (e.g., SSL handshake failures, authentication errors). These are your best clue to the root cause.

Fixes for SSL (Port 465)

Make sure your sonar.properties file has these exact settings:

sonar.email.smtp.host=your-smtp-server.com
sonar.email.smtp.port=465
sonar.email.smtp.ssl=true
sonar.email.smtp.auth=true
sonar.email.smtp.username=your-full-email@domain.com
sonar.email.smtp.password=your-password-or-app-specific-password
  • Trust the SMTP certificate: If your server uses a self-signed or internal CA certificate, SonarQube’s JVM won’t trust it by default. Import the certificate into the JVM’s truststore:
    keytool -import -alias smtp-cert -file /path/to/your/cert.crt -keystore $JAVA_HOME/lib/security/cacerts
    
    The default cacerts password is changeit. Restart SonarQube after this step.

Fixes for STARTTLS (Port 587)

Your sonar.properties should look like this (note the different TLS setting):

sonar.email.smtp.host=your-smtp-server.com
sonar.email.smtp.port=587
sonar.email.smtp.starttls.enable=true
sonar.email.smtp.auth=true
sonar.email.smtp.username=your-full-email@domain.com
sonar.email.smtp.password=your-password-or-app-specific-password
  • Relax TLS version restrictions: Some older SMTP servers use outdated TLS versions that SonarQube’s JVM rejects. Add this JVM argument to SonarQube’s startup script (e.g., sonar.sh or sonar.bat):
    -Dmail.smtp.ssl.protocols=TLSv1.2
    
    If that doesn’t work, you can try disabling strict STARTTLS checks (use cautiously):
    -Dmail.smtp.starttls.required=false
    
    Restart SonarQube after modifying the script.

Provider-Specific Tips

  • Gmail/Google Workspace: Use smtp.gmail.com with port 465 (SSL) or 587 (STARTTLS). Enable an app-specific password if 2FA is on (avoid "less secure app access" for security).
  • Microsoft 365/Outlook: Use smtp.office365.com on port 587 with STARTTLS. Your username is your full email, and password is your account or app-specific password.
  • On-prem enterprise servers: Confirm with your mail admin that SMTP auth is allowed from the SonarQube server’s IP, and that the server supports TLS 1.2+ (the modern standard).

内容的提问来源于stack exchange,提问作者Raq

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:57:40