如何在WildFly Elytron中访问现有Credential Store并获取密码
WildFly Elytron凭证存储别名不存在排查方案
一、确认当前访问的凭证存储是否匹配
你创建的凭证存储名为mycredstore,但代码中使用externalPath指定了外部文件Wildfly\\standalone\\configuration\\credStore.cs,这里需要先验证两个关键点:
- 路径正确性:Windows路径建议用正斜杠
/或双反斜杠\\,同时打印文件绝对路径确认实际位置:File storeFile = new File("Wildfly\\standalone\\configuration\\credStore.cs"); System.out.println("凭证存储绝对路径:" + storeFile.getAbsolutePath()); System.out.println("文件是否存在:" + storeFile.exists()); - 存储类型匹配:如果是绑定到WildFly配置的内部凭证存储(而非外部独立文件),初始化参数需指定
credentialStoreName,而非仅externalPath:configuration.put("location", "credStore.cs"); configuration.put("credentialStoreName", "mycredstore");
二、正确检查凭证存储别名
你的代码已包含别名遍历逻辑,可优化为更直接的排查方式:
- 先确认凭证存储初始化状态:
credentialStore.isInitialized()返回true才说明初始化有效,否则需检查存储密码、路径是否错误。 - 直接判断目标别名是否存在:
if (credentialStore.exists(ALIAS)) { System.out.println("别名" + ALIAS + "存在"); password = credentialStore.retrieve(ALIAS, PasswordCredential.class).getPassword(); } else { System.out.println("别名" + ALIAS + "不存在"); } - 完整遍历所有别名,确认存储内的实际内容:
System.out.println("当前凭证存储所有别名:"); for (String alias : credentialStore.getAliases()) { System.out.println("- " + alias); }
三、CLI检查凭证存储的有效命令
之前CLI操作无效可能是命令错误,使用以下命令直接检查mycredstore:
- 连接WildFly服务器:
./jboss-cli.sh -c - 查看凭证存储配置详情:
/subsystem=elytron/credential-store=mycredstore:read-resource(recursive=true) - 列出所有别名:
/subsystem=elytron/credential-store=mycredstore:read-aliases() - 验证目标别名是否存在:
/subsystem=elytron/credential-store=mycredstore:exists(alias=dbPassword)
四、修正后的完整代码示例
String clearTextPswd = null; Provider CREDENTIAL_STORE_PROVIDER = new WildFlyElytronCredentialStoreProvider(); Provider PASSWORD_PROVIDER = new WildFlyElytronPasswordProvider(); Security.addProvider(PASSWORD_PROVIDER); Password password = null; final String ALIAS = "dbPassword"; // 注意:此处密码需与创建凭证存储时设置的存储密码一致 Password storePassword = ClearPassword.createRaw(ClearPassword.ALGORITHM_CLEAR, "StorePassword".toCharArray()); ProtectionParameter protectionParameter = new CredentialSourceProtectionParameter(IdentityCredentials.NONE.withCredential(new PasswordCredential(storePassword))); try { CredentialStore credentialStore = CredentialStore.getInstance("KeyStoreCredentialStore", CREDENTIAL_STORE_PROVIDER); HashMap<String, String> configuration = new HashMap<>(); // 内部存储配置(对应mycredstore) configuration.put("location", "credStore.cs"); configuration.put("credentialStoreName", "mycredstore"); // 若使用外部文件,替换为以下配置并确认路径正确 // configuration.put("externalPath", "Wildfly/standalone/configuration/credStore.cs"); credentialStore.initialize(configuration, protectionParameter); System.out.println("凭证存储初始化状态:" + credentialStore.isInitialized()); if (!credentialStore.isInitialized()) { System.err.println("初始化失败,请检查存储密码或路径"); return; } System.out.println("************************************"); System.out.println("当前所有别名:"); for (String aliasExist : credentialStore.getAliases()) { System.out.println(" - " + aliasExist); } System.out.println("************************************"); if (credentialStore.exists(ALIAS)) { password = credentialStore.retrieve(ALIAS, PasswordCredential.class).getPassword(); // 转换为明文(按需使用) if (password instanceof ClearPassword) { clearTextPswd = new String(((ClearPassword) password).getPassword()); System.out.println("获取到密码:" + clearTextPswd); } } else { System.err.println("别名" + ALIAS + "不存在于当前凭证存储"); } } catch (Exception e) { e.printStackTrace(); }
内容的提问来源于stack exchange,提问作者Cpt-Proxy
相关产品推荐
相关产品推荐

