You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Java 8迁移至Java 11后,IIOP Corba通信报CORBA NO_PERMISSION错误

Java 11客户端IIOP调用Payara 5 EJB的NO_PERMISSION问题解决建议

不可变更限制条件

  • 客户端(Portlet)需从Java 8迁移至Java 11
  • 服务器端为Java 11环境下的Payara 5,会话Bean基于Java 1.8编译
  • 通信方式固定为IIOP/CORBA

Java 8 正常运行代码

Context ctx = new InitialContext();
String jndiName = "corbaname:iiop:127.0.0.1:3700#java:global/Portal/Portalejb/PortalService!se.services.portal.PortalServiceHome";
PortalServiceHome home = (PortalServiceHome)ctx.lookup(jndiName);
PortalService ps = home.create();

Java 11 测试失败代码

Properties props = new Properties();
props.setProperty("java.naming.factory.initial", "com.sun.enterprise.naming.SerialInitContextFactory");
props.setProperty("java.naming.factory.url.pkgs", "com.sun.enterprise.naming");
props.setProperty("java.naming.factory.state", "com.sun.corba.ee.impl.presentation.rmi.JNDIStateFactoryImpl");
props.setProperty("org.omg.CORBA.ORBInitialHost", "localhost");
props.setProperty("org.omg.CORBA.ORBInitialPort", "3700");
props.setProperty("org.omg.CORBA.ORBClass", "com.sun.corba.ee.impl.orb.ORBImpl");
Context ctx = new InitialContext(props);
String jndiName = "java:global/Portal/Portalejb/PortalService!se.services.portal.PortalServiceHome";
PortalServiceHome home = (PortalServiceHome)ctx.lookup(jndiName);
PortalService ps = home.create();

报错信息

java.rmi.AccessException: CORBA NO_PERMISSION 0 No; nested exception is:
org.omg.CORBA.NO_PERMISSION: ----------BEGIN server-side stack trace----------
org.omg.CORBA.NO_PERMISSION: vmcid: 0x0 minor code: 0 completed: No
at com.sun.enterprise.iiop.security.SecServerRequestInterceptor.handle_null_service_context(SecServerRequestInterceptor.java:441)
at com.sun.enterprise.iiop.security.SecServerRequestInterceptor.receive_request(SecServerRequestInterceptor.java:460)

说明:两种测试场景使用相同的会话Bean和Payara 5服务,Java 11客户端已引入依赖:glassfish-corba-omgapi、javaee-api、gf-client

解决建议

  1. 沿用Java 8的JNDI命名格式
    Java 11客户端可尝试复用Java 8中corbaname格式的JNDI名称,而非直接使用java:global前缀。修改后的代码如下:
Properties props = new Properties();
props.setProperty("java.naming.factory.initial", "com.sun.enterprise.naming.SerialInitContextFactory");
props.setProperty("java.naming.factory.url.pkgs", "com.sun.enterprise.naming");
props.setProperty("java.naming.factory.state", "com.sun.corba.ee.impl.presentation.rmi.JNDIStateFactoryImpl");
props.setProperty("org.omg.CORBA.ORBInitialHost", "localhost");
props.setProperty("org.omg.CORBA.ORBInitialPort", "3700");
props.setProperty("org.omg.CORBA.ORBClass", "com.sun.corba.ee.impl.orb.ORBImpl");
Context ctx = new InitialContext(props);
// 使用corbaname格式的完整JNDI路径
String jndiName = "corbaname:iiop:127.0.0.1:3700#java:global/Portal/Portalejb/PortalService!se.services.portal.PortalServiceHome";
PortalServiceHome home = (PortalServiceHome)ctx.lookup(jndiName);
PortalService ps = home.create();
  1. 补充安全上下文配置
    报错根源是服务端安全拦截器检测到空服务上下文,需确保客户端调用时传递正确的安全凭据。可在InitialContext属性中添加安全相关配置:
// 添加安全认证属性(替换为实际凭据)
props.setProperty("java.naming.security.principal", "your-username");
props.setProperty("java.naming.security.credentials", "your-password");
// 启用企业级认证
props.setProperty("com.sun.enterprise.security.enterpriseauth", "true");

若服务端允许匿名访问,可跳过凭据配置,但需确认Payara的EJB安全策略是否开启匿名调用权限。

  1. 对齐依赖版本兼容性
    确保引入的glassfish-corba-omgapi、gf-client版本与Payara 5服务器端版本完全一致。建议使用Payara官方提供的payara-client依赖替代零散组件,避免版本不匹配导致的通信问题。

  2. 启用CORBA调试日志排查
    在客户端启动参数中添加以下日志配置,查看安全上下文传递的细节:

-Djavax.rmi.CORBA.UtilClass=com.sun.corba.ee.impl.util.Utility
-Dcom.sun.corba.ee.transport.ORBDebug=true
-Dcom.sun.corba.ee.ORBDebug.security=true

通过日志可确认服务上下文是否正确生成,是否存在安全属性缺失或格式错误的情况。

内容的提问来源于stack exchange,提问作者SGoldwin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 12:24:58