You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Eclipse 2023-06 Maven依赖解析报PKIX路径构建失败的原因及解决

Eclipse 2023-06版本Maven依赖解析PKIX证书错误解决方案

问题背景

我们公司采用部署在HTTPS服务器、带有企业证书的Nexus Maven仓库,通过Chocolatey包为开发机分发Eclipse安装程序。Eclipse 2023-03及更早版本运行正常,但从2023-06版本开始,Maven依赖解析时频繁抛出PKIX path building failed证书错误。

已尝试但无效的操作:

  • 在eclipse.ini中指定配置了企业证书的JDK(-vm选项,常规场景有效但本次无效)
  • 替换Eclipse自带JRE中的cacerts文件(常规场景有效但本次无效)
  • 通过MAVEN_OPTS或eclipse.ini为Maven传递忽略SSL参数(无效果)

注意到Eclipse偏好设置中“Maven依赖解析始终使用嵌入式Maven安装”,似乎无法让其识别企业证书,疑问:该版本是否有变更?是否是Bug?如何让Maven模块使用企业证书?

更新验证信息

  1. 证书未过期,编写Java测试程序访问仓库HTTPS地址,在多个JVM及Eclipse内均可正常运行:
public class Demo {
  public static void main(final String[] args) throws Throwable {
    final String url = "https://COMPANYURL/";
    System.out.printf("trying to read from %s%n%n", url);
    final var target = new URL(url);
    try (final var in = new BufferedReader(new InputStreamReader(target.openStream()))) {
      String inputLine;
      while ((inputLine = in.readLine()) != null) {
        System.out.println(inputLine);
      }
    }
  }
}
  1. 尝试将仓库主机添加到“首选项>安装/更新>信任>证书颁发机构”并勾选“信任所有内容”,仍出现相同错误。

关键日志片段

!SESSION 2023-06-20 08:06:52.786 -----------------------------------------------
eclipse.buildId=4.28.0.20230608-1200
java.version=17.0.7
java.vendor=Eclipse Adoptium
BootLoader constants: OS=win32, ARCH=x86_64, WS=win32, NL=en_US
Framework arguments:  -product org.eclipse.epp.package.jee.product
Command-line arguments:  -os win32 -ws win32 -arch x86_64 -product org.eclipse.epp.package.jee.product

!SUBENTRY 1 org.eclipse.m2e.core 4 0 2023-06-20 08:10:17.701
!MESSAGE Could not calculate build plan: Plugin org.apache.maven.plugins:maven-resources-plugin:3.3.0 or one of its dependencies could not be resolved: Failed to read artifact descriptor for org.apache.maven.plugins:maven-resources-plugin:jar:3.3.0
!STACK 0
org.apache.maven.plugin.PluginResolutionException: Plugin org.apache.maven.plugins:maven-resources-plugin:3.3.0 or one of its dependencies could not be resolved: Failed to read artifact descriptor for org.apache.maven.plugins:maven-resources-plugin:jar:3.3.0
    at org.apache.maven.plugin.internal.DefaultPluginDependenciesResolver.resolve(DefaultPluginDependenciesResolver.java:125)
    at org.eclipse.m2e.core.internal.project.registry.EclipsePluginDependenciesResolver.resolve(EclipsePluginDependenciesResolver.java:47)
    ...
Caused by: org.eclipse.aether.transfer.ArtifactTransferException: org.apache.maven.plugins:maven-resources-plugin:pom:3.3.0 failed to transfer from https://COMPANYURL/repository/public-maven during a previous attempt. This failure was cached in the local repository and resolution is not reattempted until the update interval of UBSMavenRepository has elapsed or updates are forced. Original error: Could not transfer artifact org.apache.maven.plugins:maven-resources-plugin:pom:3.3.0 from/to UBSMavenRepository (https://COMPANYURL/repository/public-maven): PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
    at org.eclipse.aether.internal.impl.DefaultUpdateCheckManager.newException(DefaultUpdateCheckManager.java:214)
    ...

问题根源与解决方案

版本变更点

Eclipse 2023-06(4.28)的m2e插件升级到1.20.x版本,该版本默认使用Eclipse独立的SSL信任存储而非JVM的cacerts,这是之前JDK/JRE证书配置失效的核心原因。

有效解决方案

方案1:将企业证书导入Eclipse信任存储

Eclipse的信任存储文件位置:

  • Windows:{Eclipse安装目录}\configuration\org.eclipse.osgi\*\*.cp\lib\security\cacerts(*为随机生成的文件夹名,可通过搜索cacerts定位)
  • macOS/Linux:{Eclipse安装目录}/configuration/org.eclipse.osgi/*/*.cp/lib/security/cacerts

使用keytool命令导入证书:

keytool -importcert -file /path/to/your/enterprise.crt -keystore /path/to/eclipse/cacerts -alias enterprise-cert

默认密钥库密码为changeit。

方案2:强制m2e使用JVM信任存储

在eclipse.ini中添加以下参数,强制m2e复用JVM的证书配置:

-Dorg.eclipse.m2e.core.security.useJvmTrustStore=true

添加后重启Eclipse即可生效。

方案3:清理Maven本地仓库缓存

日志显示错误已被缓存,需手动删除本地仓库中对应失败的artifact目录,例如:

~/.m2/repository/org/apache/maven/plugins/maven-resources-plugin/3.3.0

删除后右键项目 → Maven → Update Project(勾选“Force Update of Snapshots/Releases”),强制重新拉取依赖。

验证步骤

  1. 应用任一方案后重启Eclipse
  2. 执行Maven更新操作并强制刷新依赖
  3. 检查依赖解析是否成功,无PKIX错误提示

内容的提问来源于stack exchange,提问作者JanDasWiesel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 15:45:05