天天看點

PKIX path building failed:

1.最近發現java發送https請求時,會報一個證書異常現象(個人的是在本地windows系統上可以正常通路https路徑,但在linux系統上不能通路,後來發現是因為本地%JAVA_HOME%/jre/lib/security和linux上的cacerts證書版本不一緻,linux上的是2015-4-16的,比較落後了) -->報錯全部資訊如下 異常堆棧資訊:javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target sun.security.ssl.Alerts.getSSLException(Alerts.java:192) sun.security.ssl.SSLSocketImpl.fatal(SSLSocketImpl.java:1937) sun.security.ssl.Handshaker.fatalSE(Handshaker.java:302) sun.security.ssl.Handshaker.fatalSE(Handshaker.java:296) sun.security.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:1478) sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:212) sun.security.ssl.Handshaker.processLoop(Handshaker.java:979) sun.security.ssl.Handshaker.process_record(Handshaker.java:914) sun.security.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:1050) sun.security.ssl.SSLSocketImpl.performInitialHandshake(SSLSocketImpl.java:1363) sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1391) sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1375) org.apache.http.conn.ssl.SSLConnectionSocketFactory.createLayeredSocket(SSLConnectionSocketFactory.java:395) org.apache.http.conn.ssl.SSLConnectionSocketFactory.connectSocket(SSLConnectionSocketFactory.java:354) org.apache.http.impl.conn.DefaultHttpClientConnectionOperator.connect(DefaultHttpClientConnectionOperator.java:134) org.apache.http.impl.conn.PoolingHttpClientConnectionManager.connect(PoolingHttpClientConnectionManager.java:353) org.apache.http.impl.execchain.MainClientExec.establishRoute(MainClientExec.java:380) org.apache.http.impl.execchain.MainClientExec.execute(MainClientExec.java:236) org.apache.http.impl.execchain.ProtocolExec.execute(ProtocolExec.java:184) org.apache.http.impl.execchain.RetryExec.execute(RetryExec.java:88) org.apache.http.impl.execchain.RedirectExec.execute(RedirectExec.java:110) org.apache.http.impl.client.InternalHttpClient.doExecute(InternalHttpClient.java:184) org.apache.http.impl.client.CloseableHttpClient.execute(CloseableHttpClient.java:82) org.apache.http.impl.client.CloseableHttpClient.execute(CloseableHttpClient.java:107) org.apache.http.impl.client.CloseableHttpClient.execute(CloseableHttpClient.java:55)

2.根本原因: Java在請求某些不受信任的https網站時會報:PKIX path building failed

3.解決辦法: 1)、導入證書到本地證書庫

2)、信任所有SSL證書

4.網上推薦使用 3.2,個人嘗試了一下不行,這裡講解個人的解決方式

PKIX path building failed:

将最新的cacerts檔案,替換到linux伺服器上\jre\lib\security\目錄下,替換老版本的證書

版權聲明:本文為CSDN部落客「weixin_33869377」的原創文章,遵循CC 4.0 BY-SA版權協定,轉載請附上原文出處連結及本聲明。

原文連結:https://blog.csdn.net/weixin_33869377/article/details/92335787