Spring Boot中配置CXF HttpConduit设置disableCNCheck为true的方法
How to Set
disableCNCheck=true for HttpConduit in Camel CXF Spring Boot Application Got it, let's sort this out for you. To configure the HttpConduit's disableCNCheck property on your Camel CXF endpoint, you can use the ClientConfigurer interface from Camel's CXF component. This lets you directly tweak the underlying CXF client configuration when the endpoint initializes.
Here's your modified CxfEndpoint bean with the necessary setup:
import org.apache.camel.component.cxf.CxfEndpoint; import org.apache.camel.spi.DataFormat; import org.apache.cxf.configuration.jsse.TLSClientParameters; import org.apache.cxf.transport.http.HTTPConduit; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; @Configuration public class YourCxfConfigClass { // Replace with your actual config class name @Bean public CxfEndpoint cxfEndpoint() { CxfEndpoint cxfEndpoint = new CxfEndpoint(); cxfEndpoint.setAddress(address); cxfEndpoint.setWsdlURL(wsdlLocal); cxfEndpoint.setDataFormat(DataFormat.PAYLOAD); cxfEndpoint.setUsername(username); cxfEndpoint.setPassword(password); // Configure HttpConduit to disable CN check cxfEndpoint.setClientConfigurer((client, endpoint) -> { // Fetch the HTTPConduit from the CXF client HTTPConduit conduit = (HTTPConduit) client.getConduit(); TLSClientParameters tlsParams = conduit.getTlsClientParameters(); // Create new TLS parameters if none exist yet if (tlsParams == null) { tlsParams = new TLSClientParameters(); conduit.setTlsClientParameters(tlsParams); } // Disable Common Name (CN) validation for SSL certificates tlsParams.setDisableCNCheck(true); }); return cxfEndpoint; } }
Key Notes:
- ClientConfigurer: This callback triggers when the CXF client is being initialized, giving you direct access to modify its conduit settings.
- HTTPConduit: Make sure you import the CXF-specific implementation (
org.apache.cxf.transport.http.HTTPConduit) to avoid type mismatches. - TLSClientParameters: We check for existing TLS parameters first (in case they're pre-configured elsewhere) before enabling the CN check disable.
This change only affects this specific CxfEndpoint, so it won't interfere with any other CXF endpoints in your application.
内容的提问来源于stack exchange,提问作者Tvori
相关产品推荐
相关产品推荐

