这两天在twitter服务器上忽然遇到这样的异常:

e: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

经过检查确认,完整的异常信息应该如下:

Java类已经无法下载了。。。。历经N次的google,终于找到该文件了,不敢独享,记录于此。

问题的根本是:

缺少安全证书时出现的异常。

解决问题方法:

将你要访问的webservice/url....的安全认证证书导入到客户端即可。

以下是获取安全证书的一种方法,通过以下程序获取安全证书:

  1. /*
  2. * Copyright 2006 Sun Microsystems, Inc.  All Rights Reserved.
  3. *
  4. * Redistribution and use in source and binary forms, with or without
  5. * modification, are permitted provided that the following conditions
  6. * are met:
  7. *
  8. *   - Redistributions of source code must retain the above copyright
  9. *     notice, this list of conditions and the following disclaimer.
  10. *
  11. *   - Redistributions in binary form must reproduce the above copyright
  12. *     notice, this list of conditions and the following disclaimer in the
  13. *     documentation and/or other materials provided with the distribution.
  14. *
  15. *   - Neither the name of Sun Microsystems nor the names of its
  16. *     contributors may be used to endorse or promote products derived
  17. *     from this software without specific prior written permission.
  18. *
  19. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS
  20. * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
  21. * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
  22. * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE COPYRIGHT OWNER OR
  23. * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
  24. * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
  25. * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
  26. * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
  27. * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
  28. * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
  29. * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  30. */
  31. import java.io.BufferedReader;
  32. import java.io.File;
  33. import java.io.FileInputStream;
  34. import java.io.FileOutputStream;
  35. import java.io.InputStream;
  36. import java.io.InputStreamReader;
  37. import java.io.OutputStream;
  38. import java.security.KeyStore;
  39. import java.security.MessageDigest;
  40. import java.security.cert.CertificateException;
  41. import java.security.cert.X509Certificate;
  42. import javax.net.ssl.SSLContext;
  43. import javax.net.ssl.SSLException;
  44. import javax.net.ssl.SSLSocket;
  45. import javax.net.ssl.SSLSocketFactory;
  46. import javax.net.ssl.TrustManager;
  47. import javax.net.ssl.TrustManagerFactory;
  48. import javax.net.ssl.X509TrustManager;
  49. public class InstallCert {
  50. public static void main(String[] args) throws Exception {
  51. String host;
  52. int port;
  53. char[] passphrase;
  54. if ((args.length == 1) || (args.length == 2)) {
  55. String[] c = args[0].split(":");
  56. host = c[0];
  57. port = (c.length == 1) ? 443 : Integer.parseInt(c[1]);
  58. String p = (args.length == 1) ? "changeit" : args[1];
  59. passphrase = p.toCharArray();
  60. } else {
  61. System.out
  62. .println("Usage: java InstallCert <host>[:port] [passphrase]");
  63. return;
  64. }
  65. File file = new File("jssecacerts");
  66. if (file.isFile() == false) {
  67. char SEP = File.separatorChar;
  68. File dir = new File(System.getProperty("java.home") + SEP + "lib"
  69. + SEP + "security");
  70. file = new File(dir, "jssecacerts");
  71. if (file.isFile() == false) {
  72. file = new File(dir, "cacerts");
  73. }
  74. }
  75. System.out.println("Loading KeyStore " + file + "...");
  76. InputStream in = new FileInputStream(file);
  77. KeyStore ks = KeyStore.getInstance(KeyStore.getDefaultType());
  78. ks.load(in, passphrase);
  79. in.close();
  80. SSLContext context = SSLContext.getInstance("TLS");
  81. TrustManagerFactory tmf = TrustManagerFactory
  82. .getInstance(TrustManagerFactory.getDefaultAlgorithm());
  83. tmf.init(ks);
  84. X509TrustManager defaultTrustManager = (X509TrustManager) tmf
  85. .getTrustManagers()[0];
  86. SavingTrustManager tm = new SavingTrustManager(defaultTrustManager);
  87. context.init(null, new TrustManager[] { tm }, null);
  88. SSLSocketFactory factory = context.getSocketFactory();
  89. System.out
  90. .println("Opening connection to " + host + ":" + port + "...");
  91. SSLSocket socket = (SSLSocket) factory.createSocket(host, port);
  92. socket.setSoTimeout(10000);
  93. try {
  94. System.out.println("Starting SSL handshake...");
  95. socket.startHandshake();
  96. socket.close();
  97. System.out.println();
  98. System.out.println("No errors, certificate is already trusted");
  99. } catch (SSLException e) {
  100. System.out.println();
  101. e.printStackTrace(System.out);
  102. }
  103. X509Certificate[] chain = tm.chain;
  104. if (chain == null) {
  105. System.out.println("Could not obtain server certificate chain");
  106. return;
  107. }
  108. BufferedReader reader = new BufferedReader(new InputStreamReader(
  109. System.in));
  110. System.out.println();
  111. System.out.println("Server sent " + chain.length + " certificate(s):");
  112. System.out.println();
  113. MessageDigest sha1 = MessageDigest.getInstance("SHA1");
  114. MessageDigest md5 = MessageDigest.getInstance("MD5");
  115. for (int i = 0; i < chain.length; i++) {
  116. X509Certificate cert = chain[i];
  117. System.out.println(" " + (i + 1) + " Subject "
  118. + cert.getSubjectDN());
  119. System.out.println("   Issuer  " + cert.getIssuerDN());
  120. sha1.update(cert.getEncoded());
  121. System.out.println("   sha1    " + toHexString(sha1.digest()));
  122. md5.update(cert.getEncoded());
  123. System.out.println("   md5     " + toHexString(md5.digest()));
  124. System.out.println();
  125. }
  126. System.out
  127. .println("Enter certificate to add to trusted keystore or 'q' to quit: [1]");
  128. String line = reader.readLine().trim();
  129. int k;
  130. try {
  131. k = (line.length() == 0) ? 0 : Integer.parseInt(line) - 1;
  132. } catch (NumberFormatException e) {
  133. System.out.println("KeyStore not changed");
  134. return;
  135. }
  136. X509Certificate cert = chain[k];
  137. String alias = host + "-" + (k + 1);
  138. ks.setCertificateEntry(alias, cert);
  139. OutputStream out = new FileOutputStream("jssecacerts");
  140. ks.store(out, passphrase);
  141. out.close();
  142. System.out.println();
  143. System.out.println(cert);
  144. System.out.println();
  145. System.out
  146. .println("Added certificate to keystore 'jssecacerts' using alias '"
  147. + alias + "'");
  148. }
  149. private static final char[] HEXDIGITS = "0123456789abcdef".toCharArray();
  150. private static String toHexString(byte[] bytes) {
  151. StringBuilder sb = new StringBuilder(bytes.length * 3);
  152. for (int b : bytes) {
  153. b &= 0xff;
  154. sb.append(HEXDIGITS[b >> 4]);
  155. sb.append(HEXDIGITS[b & 15]);
  156. sb.append(' ');
  157. }
  158. return sb.toString();
  159. }
  160. private static class SavingTrustManager implements X509TrustManager {
  161. private final X509TrustManager tm;
  162. private X509Certificate[] chain;
  163. SavingTrustManager(X509TrustManager tm) {
  164. this.tm = tm;
  165. }
  166. public X509Certificate[] getAcceptedIssuers() {
  167. throw new UnsupportedOperationException();
  168. }
  169. public void checkClientTrusted(X509Certificate[] chain, String authType)
  170. throws CertificateException {
  171. throw new UnsupportedOperationException();
  172. }
  173. public void checkServerTrusted(X509Certificate[] chain, String authType)
  174. throws CertificateException {
  175. this.chain = chain;
  176. tm.checkServerTrusted(chain, authType);
  177. }
  178. }
  179. }

编译InstallCert.java,然后执行:java InstallCert hostname,比如:
java InstallCert www.twitter.com
会看到如下信息:

  1. java InstallCert www.twitter.com
  2. Loading KeyStore /usr/java/jdk1.6.0_16/jre/lib/security/cacerts...
  3. Opening connection to www.twitter.com:443...
  4. Starting SSL handshake...
  5. javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
  6. at com.sun.net.ssl.internal.ssl.Alerts.getSSLException(Alerts.java:150)
  7. at com.sun.net.ssl.internal.ssl.SSLSocketImpl.fatal(SSLSocketImpl.java:1476)
  8. at com.sun.net.ssl.internal.ssl.Handshaker.fatalSE(Handshaker.java:174)
  9. at com.sun.net.ssl.internal.ssl.Handshaker.fatalSE(Handshaker.java:168)
  10. at com.sun.net.ssl.internal.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:846)
  11. at com.sun.net.ssl.internal.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:106)
  12. at com.sun.net.ssl.internal.ssl.Handshaker.processLoop(Handshaker.java:495)
  13. at com.sun.net.ssl.internal.ssl.Handshaker.process_record(Handshaker.java:433)
  14. at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:815)
  15. at com.sun.net.ssl.internal.ssl.SSLSocketImpl.performInitialHandshake(SSLSocketImpl.java:1025)
  16. at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1038)
  17. at InstallCert.main(InstallCert.java:63)
  18. Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
  19. at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:221)
  20. at sun.security.validator.PKIXValidator.engineValidate(PKIXValidator.java:145)
  21. at sun.security.validator.Validator.validate(Validator.java:203)
  22. at com.sun.net.ssl.internal.ssl.X509TrustManagerImpl.checkServerTrusted(X509TrustManagerImpl.java:172)
  23. at InstallCert$SavingTrustManager.checkServerTrusted(InstallCert.java:158)
  24. at com.sun.net.ssl.internal.ssl.JsseX509TrustManager.checkServerTrusted(SSLContextImpl.java:320)
  25. at com.sun.net.ssl.internal.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:839)
  26. ... 7 more
  27. Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
  28. at sun.security.provider.certpath.SunCertPathBuilder.engineBuild(SunCertPathBuilder.java:236)
  29. at java.security.cert.CertPathBuilder.build(CertPathBuilder.java:194)
  30. at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:216)
  31. ... 13 more
  32. Server sent 2 certificate(s):
  33. 1 Subject CN=www.twitter.com, O=example.com, C=US
  34. Issuer  CN=Certificate Shack, O=example.com, C=US
  35. sha1    2e 7f 76 9b 52 91 09 2e 5d 8f 6b 61 39 2d 5e 06 e4 d8 e9 c7
  36. md5     dd d1 a8 03 d7 6c 4b 11 a7 3d 74 28 89 d0 67 54
  37. 2 Subject CN=Certificate Shack, O=example.com, C=US
  38. Issuer  CN=Certificate Shack, O=example.com, C=US
  39. sha1    fb 58 a7 03 c4 4e 3b 0e e3 2c 40 2f 87 64 13 4d df e1 a1 a6
  40. md5     72 a0 95 43 7e 41 88 18 ae 2f 6d 98 01 2c 89 68
  41. Enter certificate to add to trusted keystore or 'q' to quit: [1]

输入1,回车,然后会在当前的目录下产生一个名为“ssecacerts”的证书。

将证书拷贝到$JAVA_HOME/jre/lib/security目录下,或者通过以下方式:
System.setProperty("javax.net.ssl.trustStore", "你的jssecacerts证书路径");

注意:因为是静态加载,所以要重新启动你的Web Server,证书才能生效。

解决PKIX:unable to find valid certification path to requested target 的问题的更多相关文章

  1. PKIX: unable to find valid certification path to requested target

    // Create a trust manager that does not validate certificate chains TrustManager[] trustAllCerts = n ...

  2. 解决 java 使用ssl过程中出现"PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"

    今天,封装HttpClient使用ssl时报一下错误: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorExc ...

  3. 解决PKIX(PKIX path building failed) 问题 unable to find valid certification path to requested target

    最近在写java的一个服务,需要给远程服务器发送post请求,认证方式为Basic Authentication,在请求过程中出现了 PKIX path building failed: sun.se ...

  4. Pop3_解决PKIX:unable to find valid certification path to requested target 的问题

    最近有公司pop3协议接收pp邮箱出现异常,连不上服务器,错误内容: e: sun.security.validator.ValidatorException: PKIX path building ...

  5. https编程遇到PKIX:unable to find valid certification path to requested target 的问题

    https编程遇到PKIX:unable to find valid certification path to requested target 的问题 2016-12-01 解决方案见:解决PKI ...

  6. 解决flutter:unable to find valid certification path to requested target 的问题

    1.问题 周末在家想搞搞flutter,家里电脑是windows的,按照官网教程一步步安装好以后,创建flutter工程,点击运行,一片红色弹出来,WTF? PKIX path building fa ...

  7. Maven:sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

    还是记录使用 maven 时遇到的问题. 一.maven报错 maven package 进行打包时出现了以下报错: Non-resolvable parent POM for com.wpbxin: ...

  8. Flutter配置环境报错“PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target”

    背景:最近看了很多Flutter漂亮的项目,想要尝试一下.所有环境都搭建好之后,按照文档一步一步配置(抄袭),但始终报如下图错误. PKIX path building failed: sun.sec ...

  9. PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

    注:网上搜来的快照,暂未验证 在java代码中请求https链接的时候,可能会报下面这个错误javax.net.ssl.SSLHandshakeException: sun.security.vali ...

随机推荐

  1. iOS开发之集成iOS9中的Core Spotlight Framework搜索App的内容

    Spotlight在iOS9上做了一些新的改进, 也就是开放了一些新的API, 通过Core Spotlight Framework你可以在你的app中集成Spotlight.集成Spotlight的 ...

  2. php+phpStorm+xdebug配置方法

    1.下载xdebug文件 http://xdebug.org/wizard.php 将phpinfo()的源代码复制到文本框中,xdebug会提示如何配置和下载哪个版本的xdebug. 全部下载地址: ...

  3. ZOJ Problem Set - 1048 Financial Management

    我承认这是一道水的不能再水的题,今天一下就做到了,还是无耻的帖上来吧 #include <stdio.h> int main() { double sum=0; for(int i=1;i ...

  4. Hive启动报错: Found class jline.Terminal, but interface was expected

    报错: [ERROR] Terminal initialization failed; falling back to unsupported java.lang.IncompatibleClassC ...

  5. SQL之收集SQL Server线程等待信息

    要知道线程等待时间是制约SQL Server效率的重要原因,这一个随笔中将学习怎样收集SQL Server中的线程等待时间,类型等信息,这些信息是进行数据库优化的依据. sys.dm_os_wait_ ...

  6. 20 个看起来很棒的 Web UI 工具包

    程序员们比设计师更需要这些 UI 方面的内容: 1. Mini Reminders Mini Reminders 2. Transluscent UI elements Transluscent UI ...

  7. iframe在iphone6 plus的safari下子页面的宽度不受父页面控制的bug

    这是想要的效果: 样式设置是iframe外面的宽度为100%,iframe的宽度为父元素的90%,高度为宽度 除以1.6,固定比例, 正常显示就是上面的样子,但是,问题出现在iphone特定手机特定版 ...

  8. SQL转换全角/半角函数

    /****** SQL转换全角/半角函数 开始******/ CREATE FUNCTION ConvertWordAngle ( ), --要转换的字符串 @flag bit --转换标志,0转换成 ...

  9. 组合模式 - Composite

    Composite Pattern,将对象组合成树形结构以表示’部分-整体’的层次关系,用户对单对象和组合部件的使用具有一致性. 实现方式: 透明方式:接口统一: 安全方式:不统一: 参考:

  10. java移位运算符

    http://www.iteye.com/topic/766461 这篇博客讲的很清楚