Spring Boot应用YAML中SSL配置值被忽略的原因排查
问题分析:Spring OAuth2客户端无法读取自定义信任库连接Keycloak
问题背景
我开发的Spring OAuth2客户端以Keycloak作为OAuth认证服务器,配置SSL后,应用无法连接OpenID配置端点,但在浏览器中能正常访问该URL。调试发现应用读取的是IDE默认的JDK信任库(C:\Users\me\.jdks\temurin-21.0.2\lib\security\cacerts),而非application.yaml中配置的信任库,需分析该问题的成因。
错误信息
Caused by: org.springframework.web.client.ResourceAccessException: I/O error on GET request for "https://localhost:8443/realms/MyRealm/.well-known/openid-configuration": PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target Caused by: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
当前application.yaml配置
server: port: 9443 ssl: key-store-type: PKCS12 key-store-password: ${self.signed.password} key-alias: tim-asus key-store: classpath:keystore/self_signed.p12 enabled: true
调试输出
javax.net.ssl|DEBUG|22|restartedMain|2024-05-28 17:18:28.070 CDT|TrustStoreManager.java:113|trustStore is: C:\Users\me\.jdks\temurin-21.0.2\lib\security\cacerts trustStore type is: pkcs12
问题成因分析
- 配置作用范围不匹配:你在
server.ssl节点下配置的是Spring Boot应用自身作为HTTPS服务端的证书信息,用于对外提供HTTPS接口时使用,完全不影响应用作为客户端向Keycloak发起HTTPS请求时的SSL信任逻辑。这是核心误解点。 - 客户端信任库未指定:Spring OAuth2客户端默认采用JDK自带的
cacerts信任库验证服务端证书。如果Keycloak使用的是自签名证书,且该证书未被导入到JDK默认信任库,就会触发PKIX路径构建失败的错误。 - 缺少客户端SSL上下文配置:要让应用在调用Keycloak接口时使用自定义信任库,需要单独为客户端请求组件(如
RestTemplate、WebClient)配置SSL上下文,或者通过Spring Security OAuth2的扩展配置指定信任库参数,而非仅配置服务端SSL。
内容的提问来源于stack exchange,提问作者Timothy Vogel
相关产品推荐
相关产品推荐

