Java 8迁移至Java 11后,IIOP Corba通信报CORBA NO_PERMISSION错误
不可变更限制条件
- 客户端(Portlet)需从Java 8迁移至Java 11
- 服务器端为Java 11环境下的Payara 5,会话Bean基于Java 1.8编译
- 通信方式固定为IIOP/CORBA
Java 8 正常运行代码
Context ctx = new InitialContext(); String jndiName = "corbaname:iiop:127.0.0.1:3700#java:global/Portal/Portalejb/PortalService!se.services.portal.PortalServiceHome"; PortalServiceHome home = (PortalServiceHome)ctx.lookup(jndiName); PortalService ps = home.create();
Java 11 测试失败代码
Properties props = new Properties(); props.setProperty("java.naming.factory.initial", "com.sun.enterprise.naming.SerialInitContextFactory"); props.setProperty("java.naming.factory.url.pkgs", "com.sun.enterprise.naming"); props.setProperty("java.naming.factory.state", "com.sun.corba.ee.impl.presentation.rmi.JNDIStateFactoryImpl"); props.setProperty("org.omg.CORBA.ORBInitialHost", "localhost"); props.setProperty("org.omg.CORBA.ORBInitialPort", "3700"); props.setProperty("org.omg.CORBA.ORBClass", "com.sun.corba.ee.impl.orb.ORBImpl"); Context ctx = new InitialContext(props); String jndiName = "java:global/Portal/Portalejb/PortalService!se.services.portal.PortalServiceHome"; PortalServiceHome home = (PortalServiceHome)ctx.lookup(jndiName); PortalService ps = home.create();
报错信息
java.rmi.AccessException: CORBA NO_PERMISSION 0 No; nested exception is:
org.omg.CORBA.NO_PERMISSION: ----------BEGIN server-side stack trace----------
org.omg.CORBA.NO_PERMISSION: vmcid: 0x0 minor code: 0 completed: No
at com.sun.enterprise.iiop.security.SecServerRequestInterceptor.handle_null_service_context(SecServerRequestInterceptor.java:441)
at com.sun.enterprise.iiop.security.SecServerRequestInterceptor.receive_request(SecServerRequestInterceptor.java:460)
说明:两种测试场景使用相同的会话Bean和Payara 5服务,Java 11客户端已引入依赖:glassfish-corba-omgapi、javaee-api、gf-client
解决建议
- 沿用Java 8的JNDI命名格式
Java 11客户端可尝试复用Java 8中corbaname格式的JNDI名称,而非直接使用java:global前缀。修改后的代码如下:
Properties props = new Properties(); props.setProperty("java.naming.factory.initial", "com.sun.enterprise.naming.SerialInitContextFactory"); props.setProperty("java.naming.factory.url.pkgs", "com.sun.enterprise.naming"); props.setProperty("java.naming.factory.state", "com.sun.corba.ee.impl.presentation.rmi.JNDIStateFactoryImpl"); props.setProperty("org.omg.CORBA.ORBInitialHost", "localhost"); props.setProperty("org.omg.CORBA.ORBInitialPort", "3700"); props.setProperty("org.omg.CORBA.ORBClass", "com.sun.corba.ee.impl.orb.ORBImpl"); Context ctx = new InitialContext(props); // 使用corbaname格式的完整JNDI路径 String jndiName = "corbaname:iiop:127.0.0.1:3700#java:global/Portal/Portalejb/PortalService!se.services.portal.PortalServiceHome"; PortalServiceHome home = (PortalServiceHome)ctx.lookup(jndiName); PortalService ps = home.create();
- 补充安全上下文配置
报错根源是服务端安全拦截器检测到空服务上下文,需确保客户端调用时传递正确的安全凭据。可在InitialContext属性中添加安全相关配置:
// 添加安全认证属性(替换为实际凭据) props.setProperty("java.naming.security.principal", "your-username"); props.setProperty("java.naming.security.credentials", "your-password"); // 启用企业级认证 props.setProperty("com.sun.enterprise.security.enterpriseauth", "true");
若服务端允许匿名访问,可跳过凭据配置,但需确认Payara的EJB安全策略是否开启匿名调用权限。
对齐依赖版本兼容性
确保引入的glassfish-corba-omgapi、gf-client版本与Payara 5服务器端版本完全一致。建议使用Payara官方提供的payara-client依赖替代零散组件,避免版本不匹配导致的通信问题。启用CORBA调试日志排查
在客户端启动参数中添加以下日志配置,查看安全上下文传递的细节:
-Djavax.rmi.CORBA.UtilClass=com.sun.corba.ee.impl.util.Utility -Dcom.sun.corba.ee.transport.ORBDebug=true -Dcom.sun.corba.ee.ORBDebug.security=true
通过日志可确认服务上下文是否正确生成,是否存在安全属性缺失或格式错误的情况。
内容的提问来源于stack exchange,提问作者SGoldwin

