You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Java SDK查询Kusto时如何规避PKIX路径构建失败错误?

Kusto Java SDK PKIX证书路径错误排查与解决

问题背景

使用Kusto(Azure Data Explorer)Java SDK,依赖配置如下:

<groupId>com.microsoft.azure.kusto</groupId>
<artifactId>kusto-data</artifactId>
<version>5.0.3</version>

通过AAD应用注册连接Kusto时,执行查询抛出以下错误:

com.microsoft.azure.kusto.data.exceptions.DataServiceException: IOException when trying to retrieve cluster metadata:PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
    at com.microsoft.azure.kusto.data.auth.CloudInfo.lambda$retrieveCloudInfoForCluster$0(CloudInfo.java:108)
    at com.microsoft.azure.kusto.data.ExponentialRetry.execute(ExponentialRetry.java:39)
    at com.microsoft.azure.kusto.data.auth.CloudInfo.retrieveCloudInfoForCluster(CloudInfo.java:100)
    at com.microsoft.azure.kusto.data.auth.CloudDependentTokenProviderBase.lambda$initialize$0(CloudDependentTokenProviderBase.java:38)
    at com.microsoft.azure.kusto.data.instrumentation.MonitoredActivity.invoke(MonitoredActivity.java:33)
    at com.microsoft.azure.kusto.data.auth.CloudDependentTokenProviderBase.initialize(CloudDependentTokenProviderBase.java:37)
    at com.microsoft.azure.kusto.data.auth.TokenProviderBase.acquireAccessToken(TokenProviderBase.java:30)
    at com.microsoft.azure.kusto.data.ClientImpl.generateIngestAndCommandHeaders(ClientImpl.java:405)
    at com.microsoft.azure.kusto.data.ClientImpl.executeToJsonResult(ClientImpl.java:213)
    at com.microsoft.azure.kusto.data.ClientImpl.executeImpl(ClientImpl.java:173)
    at com.microsoft.azure.kusto.data.ClientImpl.lambda$execute$0(ClientImpl.java:122)
    at com.microsoft.azure.kusto.data.instrumentation.MonitoredActivity.invoke(MonitoredActivity.java:33)
    at com.microsoft.azure.kusto.data.ClientImpl.execute(ClientImpl.java:121)
    at com.microsoft.azure.kusto.data.ClientImpl.execute(ClientImpl.java:116)
    at com.microsoft.azure.kusto.data.ClientImpl.execute(ClientImpl.java:111)

已尝试通过keytool将微软CA证书添加到JDK,但问题未解决。

可能原因

  • 证书未添加到应用实际使用的JVM信任库:若应用使用的是IDE自带JVM、容器内JVM等非系统默认JDK,修改系统JDK的cacerts不会生效。
  • 证书链不完整:Kusto集群的SSL证书依赖完整的信任链(根CA+中间CA),仅导入根CA无法完成验证。
  • 证书导入操作有误:keytool命令参数错误(如路径指定错误、密码不正确、证书格式不兼容),导致证书未成功导入信任库。
  • 网络代理拦截:环境中的代理服务器可能替换了SSL证书,此时需导入代理的CA证书而非微软CA。

解决方法

1. 确认应用使用的JVM路径

执行以下代码获取应用实际依赖的JVM路径:

System.out.println(System.getProperty("java.home"));

该路径下的lib/security/cacerts才是需要修改的目标信任库。

2. 完整导入证书链

  • 访问Kusto集群URL(如https://<cluster-name>.kusto.windows.net),在浏览器中导出完整证书链(包含根CA、中间CA)。
  • 使用keytool将所有证书导入目标信任库:
keytool -importcert -file <证书文件路径> -alias <唯一别名> -keystore <目标cacerts路径> -storepass changeit

注:默认cacerts密码为changeit,若已修改需使用对应密码。

3. 验证证书导入结果

执行以下命令检查证书是否成功导入:

keytool -list -keystore <目标cacerts路径> -storepass changeit | grep <证书别名或关键词>

确认目标证书已存在于信任库中。

4. 代理场景处理

若环境存在代理服务器:

  • 获取代理服务器的CA证书。
  • 按照上述证书导入步骤,将代理CA证书添加到应用使用的JVM信任库。

5. 临时跳过证书验证(仅测试环境)

生产环境禁止使用此方法,可通过以下方式临时绕过验证:

  • JVM参数:
-Dcom.microsoft.azure.kusto.data.disableSslValidation=true
  • 代码配置:
Client client = ClientFactory.createClientWithSslDisabled(clusterUrl, tokenProvider);

内容的提问来源于stack exchange,提问作者Shlomo Prayev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 05:54:58