You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS Payment Cryptography Kotlin SDK导入根证书公钥遇验证异常

解决AWS Payment Cryptography Kotlin SDK导入X509证书的ValidationException问题

问题重现

导入根证书公钥时触发错误:
ValidationException: Provided public key is not a valid X509 certificate

相关证书格式、代码及完整错误信息如下:

证书字符串

val rootCert = """-----BEGIN CERTIFICATE-----
MIIFXjCCA0agAwIB ...<base64cert> ... wK0fe4Teg==
-----END CERTIFICATE-----"""

导入代码

val importedCert = paymentCryptographyClient.importKey(
        ImportKeyRequest.builder()
                .keyMaterial(
                        ImportKeyMaterial.fromRootCertificatePublicKey(
                                RootCertificatePublicKey.builder()
                                        .keyAttributes(
                                                KeyAttributes.builder()
                                                        .keyAlgorithm(KeyAlgorithm.RSA_4096)
                                                        .keyClass(KeyClass.PUBLIC_KEY)
                                                        .keyModesOfUse(
                                                                KeyModesOfUse.builder()
                                                                        .verify(true)
                                                                        .sign(true)
                                                                        .build()
                                                        )
                                                        .keyUsage(KeyUsage.TR31_S0_ASYMMETRIC_KEY_FOR_DIGITAL_SIGNATURE)
                                                        .build()
                                        )
                                        .publicKeyCertificate(rootCert)
                                        .build()
                        )
                ).build()
)

完整错误栈

software.amazon.awssdk.services.paymentcryptography.model.ValidationException: Provided public key is not a valid X509 certificate. (Service: PaymentCryptography, Status Code: 400, Request ID: ef5ca7f5-e980-4fe1-bc5d-867e68f4d63e)
    at software.amazon.awssdk.core.internal.http.CombinedResponseHandler.handleErrorResponse(CombinedResponseHandler.java:125)
    at software.amazon.awssdk.core.internal.http.CombinedResponseHandler.handleResponse(CombinedResponseHandler.java:82)

排查与解决方法

  1. 清理证书字符串隐藏字符
    AWS SDK对PEM格式解析严格,检查证书是否包含Windows换行符\r\n、首尾空格或制表符,建议手动标准化:

    val cleanRootCert = rootCert.trim().replace("\r\n", "\n")
    
  2. 匹配证书算法与代码配置
    确认证书实际算法和代码中KeyAlgorithm.RSA_4096一致,可通过openssl命令查看证书详情:

    openssl x509 -in your-cert.pem -text -noout
    

    若证书算法为RSA 2048,需将代码中的算法参数改为KeyAlgorithm.RSA_2048。

  3. 验证证书完整性
    检查Base64编码部分是否完整无截断,确保-----BEGIN CERTIFICATE-----和-----END CERTIFICATE-----标签拼写正确,无多余字符。

  4. 本地预校验证书有效性
    先通过Java原生API解析证书,确认证书本身合规后再传入SDK:

    import java.security.cert.CertificateFactory
    import java.io.ByteArrayInputStream
    
    val certFactory = CertificateFactory.getInstance("X.509")
    val cert = certFactory.generateCertificate(ByteArrayInputStream(rootCert.toByteArray())) as java.security.cert.X509Certificate
    // 若此处抛出异常,说明证书本身存在格式问题
    

内容的提问来源于stack exchange,提问作者arveduil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 00:22:43