Spring Security Shibboleth Open SAML集成时Maven依赖解析失败问题求助
解决Maven依赖解析失败:PKIX路径构建失败(Shibboleth仓库证书问题)
我之前处理过好多次这类Maven依赖拉取失败的问题,你的情况一看就是JVM不信任Shibboleth仓库的SSL证书导致的。先给你理清楚问题本质,再一步步给你解决方法:
问题详情
你的项目 com.xx.app:XXXX:war:0.0.1-SNAPSHOT 在解析依赖时触发了核心错误:
无法从/向Shibboleth仓库(https://build.shibboleth.net/nexus/content/repositories/releases/)传输构件org.opensaml:opensaml:pom:2.6.6,报错信息为:sun.security.validator.ValidatorException: PKIX路径构建失败: sun.security.provider.certpath.SunCertPathBuilderException: 无法找到请求目标的有效认证路径。
简单来说,Maven访问Shibboleth的HTTPS仓库时,JVM的系统信任库中没有该网站的SSL证书,导致安全连接无法建立,自然拉取不到依赖。
你的项目POM配置
<repositories> <repository> <id>Shibboleth</id> <name>Shibboleth</name> <url>https://build.shibboleth.net/nexus/content/repositories/releases/</url> </repository> </repositories> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-web</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-security</artifactId> </dependency> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-thymeleaf</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-tomcat</artifactId> <scope>provided</scope> </dependency> <dependency> <groupId>org.springframework.security.extensions</groupId> <artifactId>spring-security-saml2-core</artifactId> <version>1.0.10.RELEASE</version> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-test</artifactId> <scope>test</scope> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-data-jpa</artifactId> </dependency> <!-- ojdbc8.jar --> <dependency> <groupId>com.oracle.database.jdbc</groupId> <artifactId>ojdbc8</artifactId> <scope>runtime</scope> </dependency> <dependency> <groupId>org.apache.poi</groupId> <artifactId>poi-ooxml</artifactId> <version>3.17</version> </dependency> <!-- https://mvnrepository.com/artifact/javax.validation/validation-api --> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-validation</artifactId> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-mail</artifactId> <!-- <version>2.0.1.RELEASE</version> --> </dependency> <dependency> <groupId>javax.validation</groupId> <artifactId>validation-api</artifactId> <version>2.0.1.Final</version> </dependency> <dependency> <groupId>org.projectlombok</groupId> <artifactId>lombok</artifactId> <version>${lombok-version}</version> <scope>provided</scope> </dependency> <dependency> <groupId>org.mapstruct</groupId> <artifactId>mapstruct</artifactId> <version>1.3.1.Final</version> </dependency> </dependencies>
解决方案
方案1:手动导入证书到JVM信任库(推荐生产/长期使用)
这是最安全合规的做法,步骤如下:
- 导出证书:用浏览器打开Shibboleth仓库地址,点击地址栏的锁图标 → 「查看证书」→ 「导出证书」(保存为DER或PEM格式,比如命名为
shibboleth.cer) - 导入到JVM信任库:打开终端/命令行,执行以下命令(替换
$JAVA_HOME为你的JDK安装路径,/path/to/shibboleth.cer为证书文件的实际路径):
# Linux/Mac环境(需要sudo权限) sudo keytool -import -alias shibboleth-repo -keystore $JAVA_HOME/jre/lib/security/cacerts -file /path/to/shibboleth.cer # Windows环境(需用管理员身份打开命令行) keytool -import -alias shibboleth-repo -keystore %JAVA_HOME%\jre\lib\security\cacerts -file C:\path\to\shibboleth.cer
默认信任库密码是changeit,按提示输入密码并确认导入即可。
方案2:Maven临时跳过SSL验证(仅开发环境使用)
如果只是开发阶段临时测试,可以让Maven跳过SSL证书验证,修改Maven的settings.xml(通常在~/.m2/settings.xml或Maven安装目录下的conf/settings.xml):
<profiles> <profile> <id>skip-ssl-check</id> <properties> <maven.wagon.http.ssl.insecure>true</maven.wagon.http.ssl.insecure> <maven.wagon.http.ssl.allowall>true</maven.wagon.http.ssl.allowall> <maven.wagon.http.ssl.ignore.validity.dates>true</maven.wagon.http.ssl.ignore.validity.dates> </properties> </profile> </profiles> <activeProfiles> <activeProfile>skip-ssl-check</activeProfile> </activeProfiles>
也可以直接在项目pom.xml中添加配置:
<build> <extensions> <extension> <groupId>org.apache.maven.wagon</groupId> <artifactId>wagon-http</artifactId> <version>3.5.3</version> <!-- 使用与你的Maven版本兼容的最新版 --> </extension> </extensions> </build> <properties> <maven.wagon.http.ssl.insecure>true</maven.wagon.http.ssl.insecure> <maven.wagon.http.ssl.allowall>true</maven.wagon.http.ssl.allowall> <maven.wagon.http.ssl.ignore.validity.dates>true</maven.wagon.http.ssl.ignore.validity.dates> </properties>
方案3:检查网络代理配置
如果你的网络使用了公司代理,需要确保Maven的代理配置正确,并且代理的证书也被JVM信任。可以在settings.xml中添加代理配置:
<proxies> <proxy> <id>company-proxy</id> <active>true</active> <protocol>https</protocol> <host>proxy.example.com</host> <port>8080</port> <!-- 如果代理需要认证,取消下面两行注释并填写信息 --> <!-- <username>proxy-username</username> --> <!-- <password>proxy-password</password> --> <nonProxyHosts>localhost|127.0.0.1</nonProxyHosts> </proxy> </proxies>
内容的提问来源于stack exchange,提问作者Chiranjit Jasu
相关产品推荐
相关产品推荐

