从Elytron凭证存储取密码时遇NoClassDefFoundError问题求助
Elytron CredStore 依赖导致启动报错问题
问题描述
我用一段代码从Elytron的credstore中通过别名获取密码(代码里的sysout忽略,没法正常调试只能用日志输出)。代码逻辑本身没问题,但添加最新版Wildfly-elytron依赖后,应用启动就触发org.wildfly.commons.assert.NoClassDefFoundError,而且是启动阶段就报错,不是调用该方法的时候。下面是我的代码和依赖配置,请问依赖是不是有问题?有没有遇到过这类情况?
代码示例
String clearTextPswd = null; System.out.println("Prueba0"); Provider CREDENTIAL_STORE_PROVIDER = new WildFlyElytronCredentialStoreProvider(); Provider PASSWORD_PROVIDER = new WildFlyElytronPasswordProvider(); Security.addProvider(PASSWORD_PROVIDER); Password storePassword = ClearPassword.createRaw(ClearPassword.ALGORITHM_CLEAR, "StorePassword".toCharArray()); ProtectionParameter protectionParameter = new CredentialSourceProtectionParameter(IdentityCredentials.NONE.withCredential(new PasswordCredential(storePassword))); System.out.println("prueba1"); System.out.println("prueba2"); CredentialStore credentialStore = null; System.out.println("prueba3"); try { credentialStore = CredentialStore.getInstance("KeyStoreCredentialStore", CREDENTIAL_STORE_PROVIDER); } catch (NoSuchAlgorithmException e) { e.printStackTrace(); } System.out.println("prueba4"); HashMap<String, String> configuration = new HashMap<String,String>(); configuration.put("location", "mycredstore.cs"); configuration.put("create", "true"); try { credentialStore.initialize(configuration, protectionParameter); } catch (CredentialStoreException e) { e.printStackTrace(); } System.out.println(credentialStore.isInitialized()); Password password = null; try { password = credentialStore.retrieve("dbPassword", PasswordCredential.class).getPassword(); } catch (UnsupportedCredentialTypeException e) { e.printStackTrace(); } catch (CredentialStoreException e) { e.printStackTrace(); } System.out.println("prueba5"); clearTextPswd = password.toString(); System.out.println(clearTextPswd); return clearTextPswd; }
依赖配置
<dependency> <groupId>org.pushingpixels</groupId> <artifactId>trident</artifactId> <version>1.3</version> </dependency> <dependency> <groupId>commons-io</groupId> <artifactId>commons-io</artifactId> <version>2.0.1</version> </dependency> <dependency> <groupId>commons-configuration</groupId> <artifactId>commons-configuration</artifactId> <version>1.6</version> </dependency> <dependency> <groupId>commons-codec</groupId> <artifactId>commons-codec</artifactId> <version>1.6</version> </dependency> <!-- WildFly Elytron 依赖 --> <dependency> <groupId>org.wildfly.security</groupId> <artifactId>wildfly-elytron</artifactId> <version>2.1.0.Final</version> </dependency> <dependency> <groupId>org.picketbox</groupId> <artifactId>picketbox</artifactId> <version>5.1.0.Final</version> </dependency>
问题原因与解决方案
这个错误的核心原因是WildFly Elytron 2.x版本依赖org.wildfly.common包,但你的依赖列表里没有显式引入。WildFly Elytron在新版本中把公共断言工具类等拆分到了独立的wildfly-common包中,应用启动时加载类路径找不到这个包的类,直接抛出NoClassDefFoundError。
解决步骤:
- 添加缺失的依赖:在pom.xml中引入
org.wildfly.common,版本要和你的WildFly Elytron版本兼容(比如2.1.0.Final对应的common版本可以用1.6.0.Final,也可以让Maven自动解析匹配版本):
<dependency> <groupId>org.wildfly.common</groupId> <artifactId>wildfly-common</artifactId> <version>1.6.0.Final</version> </dependency>
- 排查依赖冲突:你引入的
picketbox 5.1.0.Final本身也依赖安全组件,可能和WildFly Elytron存在依赖重叠或版本冲突。如果你的应用不需要picketbox,建议直接移除这个依赖;如果必须保留,需要排查两个包的依赖树,确保版本兼容。 - 版本兼容性校验:确保所有安全相关依赖的版本匹配,WildFly Elytron的官方文档会标注对应依赖的版本要求,建议参考官方说明调整版本。
内容的提问来源于stack exchange,提问作者Cpt-Proxy
相关产品推荐
相关产品推荐

