使用JAX-WS通过SSL调用WebService时遇连接超时问题
First, let's restate your error for clarity (since the stack trace got cut off):
com.sun.xml.internal.ws.client.ClientTransportException: HTTP transport error: java.net.ConnectException: Connection timed out: connect at com.sun.xml.internal.ws.transport.http.client.HttpClientTransport.getOutput(Unknown Source) at com.sun...
Alright, since you’ve already successfully created the service instance and port, the timeout isn’t coming from the initial service metadata fetch—it’s happening when your client tries to send the actual request over HTTPS. Let’s break down the most likely fixes step by step:
1. Double-Check the Endpoint URL and Network Reachability
- First things first: confirm the HTTPS endpoint URL you’re using is 100% correct. Typos in the domain, port, or path are super easy to miss (e.g., accidentally using
http://instead ofhttps://, or a wrong custom port like8443instead of443). - Test if the endpoint is reachable from your machine directly using a tool like
curlor Postman. Run this in your terminal:
If this times out too, the issue is network-level—either your firewall is blocking traffic, the service is down on the server side, or there’s an unconfigured proxy in play.curl -v https://your-service-endpoint-url
2. Configure Proxy Settings (If You’re Behind a Corporate Firewall)
Most corporate networks use proxies for external HTTPS traffic, and JAX-WS doesn’t always pick up system proxy settings automatically. Here’s how to set them explicitly:
- Option 1: Set system properties before initializing your service:
// Replace with your actual proxy details System.setProperty("https.proxyHost", "your-proxy-server.com"); System.setProperty("https.proxyPort", "8080"); // Add these lines if your proxy requires authentication System.setProperty("https.proxyUser", "your-username"); System.setProperty("https.proxyPassword", "your-password"); - Option 2: Configure the proxy directly in the JAX-WS port’s
BindingProvider:YourServicePortType port = yourService.getYourServicePort(); BindingProvider bindingProvider = (BindingProvider) port; bindingProvider.getRequestContext().put(BindingProvider.PROXY_HOST_PROPERTY, "your-proxy-server.com"); bindingProvider.getRequestContext().put(BindingProvider.PROXY_PORT_PROPERTY, "8080");
3. Verify SSL Certificate Trust
While timeouts usually aren’t SSL-related, certificate issues can sometimes cause unexpected connection failures. Here’s how to rule this out:
- If the service uses a self-signed certificate or one from an internal CA, you’ll need to import it into your JVM’s truststore. Run this command (default truststore password is
changeit):keytool -import -alias service-cert -file /path/to/service-cert.crt -keystore $JAVA_HOME/jre/lib/security/cacerts - For testing purposes only (never do this in production!), you can temporarily disable certificate validation to see if that’s the root cause:
// Create a trust manager that accepts all certificates TrustManager[] trustAllCerts = new TrustManager[]{ new X509TrustManager() { public X509Certificate[] getAcceptedIssuers() { return null; } public void checkClientTrusted(X509Certificate[] certs, String authType) {} public void checkServerTrusted(X509Certificate[] certs, String authType) {} } }; // Install the all-trusting trust manager SSLContext sc = SSLContext.getInstance("SSL"); sc.init(null, trustAllCerts, new SecureRandom()); HttpsURLConnection.setDefaultSSLSocketFactory(sc.getSocketFactory()); // Create a hostname verifier that accepts all hosts HostnameVerifier allHostsValid = (hostname, session) -> true; HttpsURLConnection.setDefaultHostnameVerifier(allHostsValid);
4. Increase Connection/Request Timeouts
The default JAX-WS timeout might be too short for a slow service. Adjust these values to give the connection more time:
YourServicePortType port = yourService.getYourServicePort(); BindingProvider bindingProvider = (BindingProvider) port; // Set connection timeout (time to establish the connection) to 30 seconds bindingProvider.getRequestContext().put("com.sun.xml.ws.connect.timeout", 30000); // Set request timeout (time to wait for a response) to 60 seconds bindingProvider.getRequestContext().put("com.sun.xml.ws.request.timeout", 60000);
Note: These property names are for the JAX-WS Reference Implementation (RI). If you’re using a different implementation (like Apache CXF), check their documentation for the correct property keys.
5. Check Firewall and Network Restrictions
- Ensure your local firewall isn’t blocking outgoing traffic to the service’s HTTPS port (usually 443, but could be a custom port).
- On the server side, confirm that the service’s firewall allows incoming traffic from your IP address.
If none of these fixes work, enable debug logging to get more granular details about the connection attempt:
// Enable JAX-WS transport logging System.setProperty("com.sun.xml.ws.transport.http.client.HttpTransportPipe.dump", "true"); // Enable SSL handshake logging System.setProperty("javax.net.debug", "ssl,handshake");
This will print detailed logs about the HTTPS handshake and connection process, which should help you pinpoint the exact issue.
内容的提问来源于stack exchange,提问作者Ahmed Abdelmonem

