配置Spring Integration ws:outbound-gateway拦截器遇SSL握手失败求助
Hey there, let's figure out why you're hitting that SSLHandshakeException: Received fatal alert: handshake_failure once you add the signature verification interceptor to your Spring Integration ws:outbound-gateway.
The Core Issue
When you rely solely on VM arguments like -Djavax.net.ssl.keyStore and -Djavax.net.ssl.keyStorePassword, the JVM's default SSL context picks up these settings automatically. However, once you configure a Spring WS security interceptor (like the one for signature verification), it creates its own isolated security context that doesn't inherit the JVM's default SSL configuration. That's why your setup works without the interceptor but breaks once you add it.
Fixes to Implement
Here are the key steps to align your interceptor's security config with the SSL setup you already have:
Explicitly Configure Keystore for Both the Interceptor and Message Sender
You need to make sure both the signature verification interceptor and the outbound gateway's message sender use the same keystore. This ensures consistency between the signature validation logic and the SSL handshake process.Here's a sample XML configuration that ties everything together:
<!-- Load your keystore --> <bean id="serviceKeyStore" class="org.springframework.ws.soap.security.support.KeyStoreFactoryBean"> <property name="location" value="file:C:/keystore.jks"/> <property name="password" value="123456"/> </bean> <!-- Configure KeyManagerFactory for SSL context --> <bean id="keyManagerFactory" class="org.springframework.ws.soap.security.support.KeyManagerFactoryBean"> <property name="keyStore" ref="serviceKeyStore"/> <property name="password" value="123456"/> </bean> <!-- Create an HTTPS message sender with your SSL config --> <bean id="httpsMessageSender" class="org.springframework.ws.transport.http.HttpsUrlConnectionMessageSender"> <property name="keyManager" ref="keyManagerFactory"/> </bean> <!-- Configure the WSS4J interceptor for signature verification --> <bean id="signatureValidationInterceptor" class="org.springframework.ws.soap.security.wss4j.Wss4jSecurityInterceptor"> <!-- Enable signature validation --> <property name="validationActions" value="Signature"/> <!-- Assign the keystore for verifying signatures --> <property name="validationKeyStore" ref="serviceKeyStore"/> <property name="validationPassword" value="123456"/> <!-- Add any other required config (like signature crypto properties) --> </bean> <!-- Wire everything into your outbound gateway --> <int-ws:outbound-gateway id="wsOutboundGateway" request-channel="requestChannel" uri="https://your-target-service-url" message-sender="httpsMessageSender" interceptor="signatureValidationInterceptor"/>Verify Keystore Integrity
Double-check that your keystore:- Contains the full certificate chain (including any intermediate CA certificates) required by the target service.
- Uses the correct keystore type (e.g.,
JKSorPKCS12). If it's PKCS12, add<property name="type" value="PKCS12"/>to theKeyStoreFactoryBean. - Has the correct alias for the private key/certificate pair you're using.
Enable SSL Debug Logging for Deep Dive
If you still hit issues, enable SSL handshake debugging with the VM argument:-Djavax.net.debug=ssl:handshakeThis will log detailed steps of the SSL handshake, helping you pinpoint exactly where it fails (e.g., missing certificate, unsupported cipher suite, etc.).
Why This Works
By explicitly passing your keystore to both the WSS4J interceptor (for signature validation) and the HTTPS message sender (for the SSL handshake), you ensure both components use the same security credentials. This eliminates the mismatch that was causing the handshake failure when the interceptor was added.
内容的提问来源于stack exchange,提问作者Chandrasekar Subramanian

