You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Eclipse调用第三方API遇SSLHandshakeException认证路径问题求助

解决javax.net.ssl.SSLHandshakeException: PKIX路径构建失败问题

问题详情

环境信息

  • JAVA版本:1.8
  • IDE:Eclipse

触发异常

javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

前置条件

目标API属于第三方工具,需先通过ZScaler登录,再进行Basic Auth认证。

已尝试操作

  • 安装JDK 1.8并配置JAVA_HOME指向JDK 1.8
  • 在Eclipse项目运行配置中设置Java Build Path为JDK 1.8
  • 使用keytool将根证书添加到C:\Program Files\Java\jre8\lib\security\cacerts
  • 重启系统后重新运行

证书导入命令

keytool -importcert -file location_of_cert -alias cd12 -keystore "C:\Program Files\Java\jre8\lib\security\cacerts"

触发异常的RestAssured代码

RestAssured.proxy("ipaddress", portno);
//RestAssured.useRelaxedHTTPSValidation("TLSv1.2");
RestAssured
      .given()
          .auth().basic("username", "Pwd")
          .contentType(ContentType.JSON)
          .baseUri("https://apiURL")               
      .when()
          .get()
      .then()
          .assertThat()
          //.body(null, null, null)
          .statusCode(200);

解决方案

1. 确认Eclipse实际使用的JRE密钥库

Eclipse可能未使用系统默认JRE,需验证:

  • 打开Eclipse → Window → Preferences → Java → Installed JREs,查看当前项目绑定的JRE路径
  • 若路径不是C:\Program Files\Java\jre8,则将证书导入到该JRE对应的lib\security\cacerts中,执行导入命令时替换keystore路径为Eclipse使用的JRE路径,确保以管理员权限运行命令(修改Program Files目录需要权限)

2. 验证证书是否成功导入

执行以下命令检查目标密钥库中是否存在你的证书(别名cd12):

keytool -list -keystore "C:\Program Files\Java\jre8\lib\security\cacerts" -alias cd12

默认密钥库密码为changeit,若提示找不到别名,需重新执行导入命令,确认证书文件路径正确。

3. 在RestAssured中指定自定义密钥库(推荐)

避免修改系统级密钥库,可在项目中使用自定义密钥库:

  1. 将证书导入到项目内的自定义密钥库:
keytool -importcert -file location_of_cert -alias cd12 -keystore src/main/resources/custom-cacerts.jks
  1. 在代码中配置RestAssured使用该密钥库:
String customKeystorePath = "src/main/resources/custom-cacerts.jks";
String keystorePassword = "changeit"; // 导入时设置的密码

RestAssured.config = RestAssured.config()
    .sslConfig(new SSLConfig()
        .trustStore(customKeystorePath, keystorePassword));

RestAssured.proxy("zscaler-proxy-ip", zscaler-port);
RestAssured
      .given()
          .auth().basic("username", "Pwd")
          .contentType(ContentType.JSON)
          .baseUri("https://apiURL")               
      .when()
          .get()
      .then()
          .assertThat()
          .statusCode(200);

4. 完善ZScaler代理配置

确保代理为ZScaler的IP和端口,若代理需要认证,需添加代理凭证:

RestAssured.proxy("zscaler-proxy-ip", zscaler-port)
    .proxyCredentials("zscaler-username", "zscaler-password");

5. 临时调试(生产环境禁用)

若需快速验证是否为证书问题,可临时启用宽松HTTPS验证:

RestAssured.useRelaxedHTTPSValidation("TLSv1.2");

注意:此方式跳过证书校验,存在安全风险,仅用于调试排查,生产环境禁止使用。


内容的提问来源于stack exchange,提问作者Santosh D D

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 00:33:36