Eclipse 2023-06 Maven依赖解析报PKIX路径构建失败的原因及解决
Eclipse 2023-06版本Maven依赖解析PKIX证书错误解决方案
问题背景
我们公司采用部署在HTTPS服务器、带有企业证书的Nexus Maven仓库,通过Chocolatey包为开发机分发Eclipse安装程序。Eclipse 2023-03及更早版本运行正常,但从2023-06版本开始,Maven依赖解析时频繁抛出PKIX path building failed证书错误。
已尝试但无效的操作:
- 在
eclipse.ini中指定配置了企业证书的JDK(-vm选项,常规场景有效但本次无效) - 替换Eclipse自带JRE中的
cacerts文件(常规场景有效但本次无效) - 通过
MAVEN_OPTS或eclipse.ini为Maven传递忽略SSL参数(无效果)
注意到Eclipse偏好设置中“Maven依赖解析始终使用嵌入式Maven安装”,似乎无法让其识别企业证书,疑问:该版本是否有变更?是否是Bug?如何让Maven模块使用企业证书?
更新验证信息
- 证书未过期,编写Java测试程序访问仓库HTTPS地址,在多个JVM及Eclipse内均可正常运行:
public class Demo { public static void main(final String[] args) throws Throwable { final String url = "https://COMPANYURL/"; System.out.printf("trying to read from %s%n%n", url); final var target = new URL(url); try (final var in = new BufferedReader(new InputStreamReader(target.openStream()))) { String inputLine; while ((inputLine = in.readLine()) != null) { System.out.println(inputLine); } } } }
- 尝试将仓库主机添加到“首选项>安装/更新>信任>证书颁发机构”并勾选“信任所有内容”,仍出现相同错误。
关键日志片段
!SESSION 2023-06-20 08:06:52.786 ----------------------------------------------- eclipse.buildId=4.28.0.20230608-1200 java.version=17.0.7 java.vendor=Eclipse Adoptium BootLoader constants: OS=win32, ARCH=x86_64, WS=win32, NL=en_US Framework arguments: -product org.eclipse.epp.package.jee.product Command-line arguments: -os win32 -ws win32 -arch x86_64 -product org.eclipse.epp.package.jee.product !SUBENTRY 1 org.eclipse.m2e.core 4 0 2023-06-20 08:10:17.701 !MESSAGE Could not calculate build plan: Plugin org.apache.maven.plugins:maven-resources-plugin:3.3.0 or one of its dependencies could not be resolved: Failed to read artifact descriptor for org.apache.maven.plugins:maven-resources-plugin:jar:3.3.0 !STACK 0 org.apache.maven.plugin.PluginResolutionException: Plugin org.apache.maven.plugins:maven-resources-plugin:3.3.0 or one of its dependencies could not be resolved: Failed to read artifact descriptor for org.apache.maven.plugins:maven-resources-plugin:jar:3.3.0 at org.apache.maven.plugin.internal.DefaultPluginDependenciesResolver.resolve(DefaultPluginDependenciesResolver.java:125) at org.eclipse.m2e.core.internal.project.registry.EclipsePluginDependenciesResolver.resolve(EclipsePluginDependenciesResolver.java:47) ... Caused by: org.eclipse.aether.transfer.ArtifactTransferException: org.apache.maven.plugins:maven-resources-plugin:pom:3.3.0 failed to transfer from https://COMPANYURL/repository/public-maven during a previous attempt. This failure was cached in the local repository and resolution is not reattempted until the update interval of UBSMavenRepository has elapsed or updates are forced. Original error: Could not transfer artifact org.apache.maven.plugins:maven-resources-plugin:pom:3.3.0 from/to UBSMavenRepository (https://COMPANYURL/repository/public-maven): PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at org.eclipse.aether.internal.impl.DefaultUpdateCheckManager.newException(DefaultUpdateCheckManager.java:214) ...
问题根源与解决方案
版本变更点
Eclipse 2023-06(4.28)的m2e插件升级到1.20.x版本,该版本默认使用Eclipse独立的SSL信任存储而非JVM的cacerts,这是之前JDK/JRE证书配置失效的核心原因。
有效解决方案
方案1:将企业证书导入Eclipse信任存储
Eclipse的信任存储文件位置:
- Windows:
{Eclipse安装目录}\configuration\org.eclipse.osgi\*\*.cp\lib\security\cacerts(*为随机生成的文件夹名,可通过搜索cacerts定位) - macOS/Linux:
{Eclipse安装目录}/configuration/org.eclipse.osgi/*/*.cp/lib/security/cacerts
使用keytool命令导入证书:
keytool -importcert -file /path/to/your/enterprise.crt -keystore /path/to/eclipse/cacerts -alias enterprise-cert
默认密钥库密码为changeit。
方案2:强制m2e使用JVM信任存储
在eclipse.ini中添加以下参数,强制m2e复用JVM的证书配置:
-Dorg.eclipse.m2e.core.security.useJvmTrustStore=true
添加后重启Eclipse即可生效。
方案3:清理Maven本地仓库缓存
日志显示错误已被缓存,需手动删除本地仓库中对应失败的artifact目录,例如:
~/.m2/repository/org/apache/maven/plugins/maven-resources-plugin/3.3.0
删除后右键项目 → Maven → Update Project(勾选“Force Update of Snapshots/Releases”),强制重新拉取依赖。
验证步骤
- 应用任一方案后重启Eclipse
- 执行Maven更新操作并强制刷新依赖
- 检查依赖解析是否成功,无PKIX错误提示
内容的提问来源于stack exchange,提问作者JanDasWiesel
相关产品推荐
相关产品推荐

