本文介绍了Java 应用程序中的 PKIX 路径构建失败的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

在将我的应用程序从 Windows 2000 迁移到 Windows 2008 R2 Server 之后,我已经努力了将近一个星期才能让我的应用程序正常运行.

I have been struggling for almost one week to get my applications up running after moving my applications from Windows 2000 to Windows 2008 R2 Server.

程序:

  1. 已安装 Java JDK 1.7.0_25
  2. 设置系统环境变量JAVA_HOMEC:Progra~1Javajdk1.7.0_25
  3. 使用 keytool
  4. 将证书导入 cacerts
  5. 使用 -list 确保证书存在于 keytool 中.
  1. Installed Java JDK 1.7.0_25
  2. Set system environment variable JAVA_HOME to C:Progra~1Javajdk1.7.0_25
  3. Imported the certificate into cacerts with keytool
  4. Ensured that the certificate exists in keytool with -list.

我尝试使用 InstallCert 重复 步骤 3 以确保我没有搞砸任何事情.

I have tried to repeat step 3 with InstallCert to ensure that i havent messed anything up.

以上方法没有解决我的问题,所以我尝试以编程方式来做:

The above methods did not solve my problem, so i tried to do it programmatically:

System.setProperty("javax.net.ssl.trustStore",
"C:/Progra~1/Java/jdk1.7.0_25/jre/lib/security/cacerts");
System.setProperty("javax.net.ssl.trustStorePassword", "changeit");

仍然没有任何运气.我被卡住了,不太确定从这里往哪个方向.

Still without any luck. I am stuck and not quite sure which direction to go from here.

堆栈跟踪:

javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
    at sun.security.ssl.Alerts.getSSLException(Alerts.java:192)
    at sun.security.ssl.SSLSocketImpl.fatal(SSLSocketImpl.java:1886)
    at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:276)
    at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:270)
    at sun.security.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:1341)
    at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:153)
    at sun.security.ssl.Handshaker.processLoop(Handshaker.java:868)
    at sun.security.ssl.Handshaker.process_record(Handshaker.java:804)
    at sun.security.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:1016)
    at sun.security.ssl.SSLSocketImpl.performInitialHandshake(SSLSocketImpl.java:1312)
    at sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1339)
    at sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1323)
    at sun.net.www.protocol.https.HttpsClient.afterConnect(HttpsClient.java:515)
    at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:185)
    at sun.net.www.protocol.https.HttpsURLConnectionImpl.connect(HttpsURLConnectionImpl.java:153)
    at util.SMS.send(SMS.java:93)
    at domain.ActivationSMSSenderMain.sendActivationMessagesToCustomers(ActivationSMSSenderMain.java:80)
    at domain.ActivationSMSSenderMain.<init>(ActivationSMSSenderMain.java:44)
    at domain.ActivationSMSSenderMain.main(ActivationSMSSenderMain.java:341)
Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
    at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:385)
    at sun.security.validator.PKIXValidator.engineValidate(PKIXValidator.java:292)
    at sun.security.validator.Validator.validate(Validator.java:260)
    at sun.security.ssl.X509TrustManagerImpl.validate(X509TrustManagerImpl.java:326)
    at sun.security.ssl.X509TrustManagerImpl.checkTrusted(X509TrustManagerImpl.java:231)
    at sun.security.ssl.X509TrustManagerImpl.checkServerTrusted(X509TrustManagerImpl.java:126)
    at sun.security.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:1323)
    ... 14 more
Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
    at sun.security.provider.certpath.SunCertPathBuilder.engineBuild(SunCertPathBuilder.java:196)
    at java.security.cert.CertPathBuilder.build(CertPathBuilder.java:268)
    at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:380)
    ... 20 more

更新:

两者System.out.println(System.getProperty("javax.net.ssl.trustStore"));System.out.println(System.getProperty("javax.net.ssl.keyStore"));

返回null.

推荐答案

我遇到了类似的问题,其原因和解决方案都非常简单:

I ran into similar issues whose cause and solution turned out both to be rather simple:

主要原因:没有使用 keytool 导入正确的证书

Main Cause: Did not import the proper cert using keytool

注意:仅导入根 CA(或您自己的自签名)证书

注意:不要导入中间的、非证书链根证书

imap.gmail.com 的解决方案示例

  1. 确定根 CA 证书:

  1. Determine the root CA cert:

openssl s_client -showcerts -connect imap.gmail.com:993

在这种情况下,我们发现根 CA 是 Equifax Secure Certificate Authority

in this case we find the root CA is Equifax Secure Certificate Authority

javax.net.ssl.trustStore 导入证书:

keytool -import -alias gmail_imap -file Equifax_Secure_Certificate_Authority.pem

  • 运行你的java代码
  • 这篇关于Java 应用程序中的 PKIX 路径构建失败的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持!

    08-05 06:57