Spring Boot 3.1.x的SslBundle是否支持自定义KeyStore?
问题:Spring Boot的JKS SSL Bundle是否支持无文件的自定义KeyStore类型?
不支持。
Spring Boot提供的JksSslStoreBundle仅支持从非空输入流加载密钥库,它的loadKeyStore方法实现中,只调用了KeyStore.load(InputStream, char[])重载方法,完全没有用到KeyStoreSpi中接受LoadStoreParameter参数的engineLoad重载逻辑——而像Azure Key Vault KeyStore这类自定义实现,正是依赖后者来完成无物理文件的密钥库加载。
相关代码佐证:
JksSslStoreBundle的loadKeyStore核心逻辑:
private KeyStore loadKeyStore(SslStoreDetails details) throws Exception { KeyStore keyStore = KeyStore.getInstance(details.getType()); try (InputStream inputStream = details.getInputStream()) { keyStore.load(inputStream, details.getPassword().toCharArray()); } return keyStore; }
KeyStoreSpi中支持参数化加载的重载方法:
public void engineLoad(KeyStore.LoadStoreParameter param) throws IOException, NoSuchAlgorithmException, CertificateException { engineLoad(null, param); }
替代方案
如果要使用Azure Key Vault这类无文件自定义KeyStore,建议:
- 自定义实现
SslBundle接口,直接对接目标KeyStore的加载逻辑 - 使用Spring Cloud Azure提供的官方集成方案,它已经封装了针对Azure Key Vault密钥库的SSL适配逻辑
内容的提问来源于stack exchange,提问作者Sarah Dai
相关产品推荐
相关产品推荐

