【问题标题】:camel:sslContextParameters is not being used in an http4 connection骆驼:sslContextParameters 未在 http4 连接中使用
【发布时间】:2017-06-14 12:01:22
【问题描述】:

我在尝试创建安全 URL 的端点时遇到问题(它要求提供个人证书),我的目标是创建具有相同输入参数的内部服务,并通过获取有效证书调用外部服务响应并将其重定向到调用者,从而避免调用者拥有有效的证书。

这是我的路线:

<blueprint xmlns="http://www.osgi.org/xmlns/blueprint/v1.0.0"
xmlns:camel="http://camel.apache.org/schema/blueprint"
xmlns:cxf="http://camel.apache.org/schema/blueprint/cxf"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="   
http://www.osgi.org/xmlns/blueprint/v1.0.0 
http://www.osgi.org/xmlns/blueprint/v1.0.0/blueprint.xsd    
http://camel.apache.org/schema/blueprint/cxf 
http://camel.apache.org/schema/blueprint/cxf/camel-cxf.xsd    
http://camel.apache.org/schema/blueprint 
http://camel.apache.org/schema/blueprint/camel-blueprint.xsd">
    <cxf:cxfEndpoint address="/validate_nif/" id="validateNifEndpoint" serviceClass="validationservice.nif.ValidateNifEndpoint"/>
    <camel:sslContextParameters id="mySslContextParameters">
        <camel:keyManagers keyPassword="">
            <camel:keyStore password="XXXXX" resource="etc/certs/truststore.jks"/>
        </camel:keyManagers>
        <camel:clientParameters>
            <camel:secureSocketProtocols>
            <camel:secureSocketProtocol>SSLv3</camel:secureSocketProtocol>
            </camel:secureSocketProtocols>
        </camel:clientParameters>
    </camel:sslContextParameters>
<bean class="org.apache.camel.component.http4.HttpComponent" id="my-http4">
    <property name="sslContextParameters" ref="mySslContextParameters"/>
</bean>
<camelContext id="camelContext-83032cb1-6f93-4d6f-b22f-2cef908fcc8b" xmlns="http://camel.apache.org/schema/blueprint">
    <contextScan/>
    <route id="_route1" trace="true">
        <!-- route starts from the cxf webservice -->
        <from id="_from1" uri="cxf:bean:validateNifEndpoint"/>
        <!-- log input received -->
        <log id="_log1" message="Input: ${body}"/>
        <removeHeaders id="_removeHeaders1" pattern="CamelHttp*"/>
        <!-- call external service -->
        <to id="_to2" uri="my-http4://www1.agenciatributaria.gob.es/wlpl/BURT-JDIT/ws/VNifV1SOAP?sslContextParametersRef=mySslContextParameters&amp;proxyAuthHost=myproxy&amp;proxyAuthPort=8080&amp;proxyAuthScheme=http4"/>
        <!-- log answer from real web service -->
        <log id="_log2" message="Output: ${body}"/>
        <transform id="_transform1">
            <constant>OK</constant>
        </transform>
    </route>
</camelContext>
</blueprint>

http4 组件正确解析代理设置,但似乎没有解析 ssl 设置:

2017-06-14 13:48:40,237 | DEBUG | cxf/validate_nif | SendProcessor                    | 323 - org.apache.camel.camel-core - 2.17.0.redhat-630187 | >>>> Endpoint[my-http4://www1.agenciatributaria.gob.es/wlpl/BURT-JDIT/ws/VNifV1SOAP?proxyAuthScheme=http4&proxyAuthPort=8080&sslContextParametersRef=mySslContextParameters&proxyAuthHost=myproxy] Exchange[ID-010668-57070-1497438180654-4-6]
2017-06-14 13:48:40,242 | DEBUG | cxf/validate_nif | HttpProducer                     | 391 - org.apache.camel.camel-http4 - 2.17.0.redhat-630187 | Executing http GET method: http://www1.agenciatributaria.gob.es/wlpl/BURT-JDIT/ws/VNifV1SOAP?sslContextParametersRef=mySslContextParameters
2017-06-14 13:48:40,242 | DEBUG | cxf/validate_nif | RequestAddCookies                | 392 - org.apache.httpcomponents.httpclient - 4.5.2 | CookieSpec selected: default
2017-06-14 13:48:40,242 | DEBUG | cxf/validate_nif | RequestAuthCache                 | 392 - org.apache.httpcomponents.httpclient - 4.5.2 | Auth cache not set in the context
2017-06-14 13:48:40,242 | DEBUG | cxf/validate_nif | olingHttpClientConnectionManager | 392 - org.apache.httpcomponents.httpclient - 4.5.2 | Connection request: [route: {}->http4://myproxy:8080->http://www1.agenciatributaria.gob.es:80][total kept alive: 3; route allocated: 1 of 20; total allocated: 3 of 200]
2017-06-14 13:48:40,247 | DEBUG | cxf/validate_nif | olingHttpClientConnectionManager | 392 - org.apache.httpcomponents.httpclient - 4.5.2 | Connection leased: [id: 10][route: {}->http4://myproxy:8080->http://www1.agenciatributaria.gob.es:80][total kept alive: 2; route allocated: 1 of 20; total allocated: 3 of 200]
2017-06-14 13:48:40,247 | DEBUG | cxf/validate_nif | MainClientExec                   | 392 - org.apache.httpcomponents.httpclient - 4.5.2 | Executing request GET http://www1.agenciatributaria.gob.es/wlpl/BURT-JDIT/ws/VNifV1SOAP?sslContextParametersRef=mySslContextParameters HTTP/1.1
2017-06-14 13:48:40,247 | DEBUG | cxf/validate_nif | MainClientExec                   | 392 - org.apache.httpcomponents.httpclient - 4.5.2 | Target auth state: UNCHALLENGED
2017-06-14 13:48:40,247 | DEBUG | cxf/validate_nif | MainClientExec                   | 392 - org.apache.httpcomponents.httpclient - 4.5.2 | Proxy auth state: UNCHALLENGED
2017-06-14 13:48:40,247 | DEBUG | cxf/validate_nif | headers                          | 392 - org.apache.httpcomponents.httpclient - 4.5.2 | http-outgoing-10 >> GET http://www1.agenciatributaria.gob.es/wlpl/BURT-JDIT/ws/VNifV1SOAP?sslContextParametersRef=mySslContextParameters HTTP/1.1

关于如何使它工作的任何想法?

【问题讨论】:

  • 你使用什么版本的骆驼。还要注意你已经配置了 sslContext 两次 - 在组件和端点上。
  • 我使用的是版本:camel 2.17.0.redhat-630187,你说得对,它配置了两次,我已经删除了端点中的配置并更改了 SSL 参数,我可以看到它正在使用上下文配置,谢谢!

标签: java ssl https apache-camel


【解决方案1】:

https://camel.apache.org/manual/latest/camel-configuration-utilities.html 注意:“secureSocketProtocol(attribute)” 所以,也许这会起作用:

<camel:sslContextParameters id="mySslContextParameters" secureSocketProtocol="SSLv3">
    <camel:keyManagers keyPassword="">
        <camel:keyStore password="XXXXX" resource="etc/certs/truststore.jks"/>
    </camel:keyManagers>
</camel:sslContextParameters>

很长一段时间以来,我都试图克服通过 https4 发送的错误。建议在任何地方使用:

<camel:clientParameters>
    <camel:secureSocketProtocols>
        <camel:secureSocketProtocol>TLSv1.2</camel:secureSocketProtocol>
    </camel:secureSocketProtocols>
</camel:clientParameters>

一位同事建议使用属性secureSocketProtocol="TLSv1.2",它奏效了。

【讨论】:

    【解决方案2】:

    我知道这已经是 4 年前的事了。但是今天我发现 sslContextParametersRef 不起作用。它应该是:

    注意 id-reference 中的哈希 ('#')。

    【讨论】:

      猜你喜欢
      • 2014-05-13
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2020-12-22
      • 2015-04-29
      • 1970-01-01
      相关资源
      最近更新 更多