You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Spring Integration ws:outbound-gateway拦截器遇SSL握手失败求助

Troubleshooting SSL Handshake Failure with Spring Integration WS Outbound Gateway + Signature Validation Interceptor

Hey there, let's figure out why you're hitting that SSLHandshakeException: Received fatal alert: handshake_failure once you add the signature verification interceptor to your Spring Integration ws:outbound-gateway.

The Core Issue

When you rely solely on VM arguments like -Djavax.net.ssl.keyStore and -Djavax.net.ssl.keyStorePassword, the JVM's default SSL context picks up these settings automatically. However, once you configure a Spring WS security interceptor (like the one for signature verification), it creates its own isolated security context that doesn't inherit the JVM's default SSL configuration. That's why your setup works without the interceptor but breaks once you add it.

Fixes to Implement

Here are the key steps to align your interceptor's security config with the SSL setup you already have:

  1. Explicitly Configure Keystore for Both the Interceptor and Message Sender
    You need to make sure both the signature verification interceptor and the outbound gateway's message sender use the same keystore. This ensures consistency between the signature validation logic and the SSL handshake process.

    Here's a sample XML configuration that ties everything together:

    <!-- Load your keystore -->
    <bean id="serviceKeyStore" class="org.springframework.ws.soap.security.support.KeyStoreFactoryBean">
        <property name="location" value="file:C:/keystore.jks"/>
        <property name="password" value="123456"/>
    </bean>
    
    <!-- Configure KeyManagerFactory for SSL context -->
    <bean id="keyManagerFactory" class="org.springframework.ws.soap.security.support.KeyManagerFactoryBean">
        <property name="keyStore" ref="serviceKeyStore"/>
        <property name="password" value="123456"/>
    </bean>
    
    <!-- Create an HTTPS message sender with your SSL config -->
    <bean id="httpsMessageSender" class="org.springframework.ws.transport.http.HttpsUrlConnectionMessageSender">
        <property name="keyManager" ref="keyManagerFactory"/>
    </bean>
    
    <!-- Configure the WSS4J interceptor for signature verification -->
    <bean id="signatureValidationInterceptor" class="org.springframework.ws.soap.security.wss4j.Wss4jSecurityInterceptor">
        <!-- Enable signature validation -->
        <property name="validationActions" value="Signature"/>
        <!-- Assign the keystore for verifying signatures -->
        <property name="validationKeyStore" ref="serviceKeyStore"/>
        <property name="validationPassword" value="123456"/>
        <!-- Add any other required config (like signature crypto properties) -->
    </bean>
    
    <!-- Wire everything into your outbound gateway -->
    <int-ws:outbound-gateway id="wsOutboundGateway"
                             request-channel="requestChannel"
                             uri="https://your-target-service-url"
                             message-sender="httpsMessageSender"
                             interceptor="signatureValidationInterceptor"/>
    
  2. Verify Keystore Integrity
    Double-check that your keystore:

    • Contains the full certificate chain (including any intermediate CA certificates) required by the target service.
    • Uses the correct keystore type (e.g., JKS or PKCS12). If it's PKCS12, add <property name="type" value="PKCS12"/> to the KeyStoreFactoryBean.
    • Has the correct alias for the private key/certificate pair you're using.
  3. Enable SSL Debug Logging for Deep Dive
    If you still hit issues, enable SSL handshake debugging with the VM argument:

    -Djavax.net.debug=ssl:handshake
    

    This will log detailed steps of the SSL handshake, helping you pinpoint exactly where it fails (e.g., missing certificate, unsupported cipher suite, etc.).

Why This Works

By explicitly passing your keystore to both the WSS4J interceptor (for signature validation) and the HTTPS message sender (for the SSL handshake), you ensure both components use the same security credentials. This eliminates the mismatch that was causing the handshake failure when the interceptor was added.

内容的提问来源于stack exchange,提问作者Chandrasekar Subramanian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:18:29