You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OAuth请求中证书主机名不匹配问题求助

Fixing SSL Hostname Mismatch Error (hostname in certificate didn't match)

What's Causing This?

Looking at your error message:

16:30:21,046 ERROR [org.keycloak.adapters.OAuthRequestAuthenticator] (http-/0.0.0.0:8080-1) failed to turn code into token: javax.net.ssl.SSLException: hostname in certificate didn't match: <135.209.100.150> !=

The core issue is that the certificate you generated only has nginxsvc as its Common Name (CN), but you're accessing the service directly via the IP 135.209.100.150. Modern SSL clients (like the one Keycloak uses) validate that the accessed hostname/IP matches either the CN or an entry in the certificate's Subject Alternative Name (SAN) extension. Since your certificate has neither the IP in its SAN nor the IP as the CN, the validation fails.


This is the proper long-term fix, as it aligns with modern SSL standards. Here's how to do it:

  1. Create a temporary OpenSSL config file (name it openssl-custom.cnf) with the following content:
[req]
default_bits = 2048
prompt = no
default_md = sha256
distinguished_name = dn
req_extensions = req_ext

[dn]
CN = nginxsvc
O = nginxsvc

[req_ext]
subjectAltName = @alt_names

[alt_names]
IP.1 = 135.209.100.150
# Add DNS entries here if you need to support domain names too, e.g.:
# DNS.1 = nginxsvc.yourdomain.com
  1. Use this config to generate a new certificate and key:
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout tls.key -out tls.crt -config openssl-custom.cnf
  1. Update the Java cacerts keystore with the new certificate:
    • First, check if the old certificate exists (and delete it if so):
      keytool -list -keystore "C:\Program Files\Java\jdk1.8.0_152\jre\lib\security\cacerts" -storepass changeit | findstr nginxsvc
      keytool -delete -alias nginxsvc -keystore "C:\Program Files\Java\jdk1.8.0_152\jre\lib\security\cacerts" -storepass changeit
      
    • Then import the new certificate:
      keytool -import -file C:\Code_Base\Certificates\NGINX_150\tls.crt -storepass changeit -keystore "C:\Program Files\Java\jdk1.8.0_152\jre\lib\security\cacerts" -alias nginxsvc
      

Solution 2: Map the CN to the IP via Hosts File (Quick Workaround)

If you need a temporary fix without regenerating the certificate, you can map the certificate's CN (nginxsvc) to your target IP in your local hosts file:

  1. Open C:\Windows\System32\drivers\etc\hosts with administrator privileges.
  2. Add this line at the bottom:
    135.209.100.150 nginxsvc
    
  3. Save the file, then access your service using nginxsvc as the hostname (instead of the IP). This will make the SSL validation match the certificate's CN.

Why Your Original Command Failed

Your initial OpenSSL command only set the CN to nginxsvc using -subj "/CN=nginxsvc/O=nginxsvc", but it didn't include the IP address in the SAN extension. While older SSL implementations allowed CN matching for IPs, modern clients strictly require the IP to be listed in the SAN (or the CN to be the exact IP) to pass validation. That's why you saw the mismatch error when accessing via IP.

内容的提问来源于stack exchange,提问作者Subodh Joshi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:58:05