如何通过jboss-cli.sh正确配置WildFly MySQL数据源的useSSL=false?
It sounds like you're hitting a common gotcha with WildFly and MySQL driver configurations—let's break down what's likely going wrong and how to fix it properly.
Common Causes & Solutions
1. Your CLI Command Might Be Failing Due to Shell Escaping Issues
When you run jboss-cli.sh directly from the shell, special characters like & in your connection URL get interpreted by the shell instead of being passed to WildFly. That means your useSSL=false parameter might not actually be making it into the connection URL.
Fix: Wrap the connection URL in single quotes to prevent shell parsing, or use the interactive CLI mode.
Option A: Non-interactive Mode with Single Quotes
./jboss-cli.sh --connect command="/subsystem=datasources/data-source=MySqlDS:write-attribute(name=connection-url, value='jdbc:mysql://localhost:3306/your_db?useSSL=false&serverTimezone=UTC')"
Option B: Interactive Mode (Avoids Escaping Hassles)
- Launch the CLI and connect:
./jboss-cli.sh --connect - Run the attribute update command:
[standalone@localhost:9990 /] /subsystem=datasources/data-source=MySqlDS:write-attribute(name=connection-url, value="jdbc:mysql://localhost:3306/your_db?useSSL=false&serverTimezone=UTC")
2. You Might Be Modifying the Wrong Datasource or Configuration File
If you have a -ds.xml file deployed in WildFly's deployments directory, any changes you make via CLI to standalone.xml/domain.xml will be ignored—WildFly prioritizes the deployed datasource descriptor.
Fix:
- Check if there's a file like
mysql-ds.xmlindeployments/. If so, edit that file directly to adduseSSL=falseto the<connection-url>tag. - Or, remove the deployed
-ds.xmlfile and rely on the CLI-configured datasource instandalone.xml.
3. Add Explicit Connection Property for useSSL (For Newer MySQL Drivers)
Newer MySQL JDBC drivers (8.0+) have stricter SSL defaults. Even if you add useSSL=false to the URL, some versions might still require you to set it as a separate connection property.
Fix: Add the useSSL property via CLI:
/subsystem=datasources/data-source=MySqlDS/connection-properties=useSSL:add(value=false, type=BOOLEAN)
4. Reload the Server to Apply Changes
After making any CLI changes, you need to reload WildFly for the configuration to take effect. Skip this step, and you'll still see the old configuration on startup.
Command to Reload:
:reload
5. Verify Your Configuration
To confirm the changes stuck, run this CLI command to check the datasource details:
/subsystem=datasources/data-source=MySqlDS:read-resource(recursive=true)
Look for the connection-url field and ensure useSSL=false is present, and check if the connection-properties include useSSL=false if you added it.
Why Re-running the CLI Command Throws an Error
If you run the same write-attribute command again, WildFly will throw an error because the attribute is already set to that value. To avoid this, you can use the write-attribute command with the allow-resource-service-restart=true parameter, or check if the value exists before updating. Alternatively, use the replace operation if you need to overwrite the URL completely.
内容的提问来源于stack exchange,提问作者Pako

