You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Open Liberty集成Azure Service Bus(Smallrye AMQP)时SSL握手失败求助

解决Open Liberty + Smallrye AMQP连接Azure Service Bus的SSL握手异常

你遇到的javax.net.ssl.SSLHandshakeException问题,主要是配置里的几个关键参数设置错误导致的,我帮你梳理并修正:

核心配置问题修正

1. 端口设置错误

Azure Service Bus的AMQP over SSL端口是5671,而非5672(5672是未加密的AMQP端口,Azure Service Bus默认不对外开放)。你当前用的5672端口无法建立SSL连接,这是导致握手失败的主要原因之一。

2. 重复的SSL配置

你同时设置了use-ssl=true和amqp-use-ssl=true,Smallrye AMQP连接器的正确控制参数是amqp-use-ssl,保留这个即可,删掉use-ssl避免参数冲突。

3. 主机名验证配置不当

hostname-verification-algorithm=''这个空值配置会破坏SSL证书的验证流程,要么直接移除这个参数(使用默认的验证逻辑),要么明确设置为符合Azure证书的算法(比如HTTPS),绝对不能设为空字符串。

修正后的完整配置

mp.messaging.outgoing.servicebus.address=xxxxxxx
mp.messaging.outgoing.servicebus.connector=smallrye-amqp
mp.messaging.outgoing.servicebus.host=xxxxx.servicebus.windows.net
mp.messaging.outgoing.servicebus.port=5671
mp.messaging.outgoing.servicebus.username=my_saspolicyname
mp.messaging.outgoing.servicebus.password=the_saskey
mp.messaging.outgoing.servicebus.amqp-use-ssl=true
mp.messaging.outgoing.servicebus.containerId=mycontainer

额外排查建议

  • 确认你的SAS政策拥有Send权限:如果政策权限不足,有时候也会伪装成连接异常,务必检查政策的权限配置。
  • 检查Open Liberty信任库:默认情况下Open Liberty的信任库已经包含公共CA证书,但如果你的环境用了自定义信任库,需要确保Azure Service Bus的根CA证书已被导入。
  • 版本兼容性验证:确认Smallrye AMQP 1.0.8和你使用的Open Liberty版本的mpReactiveMessaging-1.0特性兼容,比如Open Liberty 20.0.0.12及以上版本对mpReactiveMessaging-1.0的支持更完善,适配Smallrye 1.0.8应该没问题,但最好做下确认。

调整完配置后,应该就能正常建立SSL连接并向Azure Service Bus队列发送消息了。

内容的提问来源于stack exchange,提问作者Daniel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:34:33