You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security Shibboleth Open SAML集成时Maven依赖解析失败问题求助

解决Maven依赖解析失败:PKIX路径构建失败(Shibboleth仓库证书问题)

我之前处理过好多次这类Maven依赖拉取失败的问题,你的情况一看就是JVM不信任Shibboleth仓库的SSL证书导致的。先给你理清楚问题本质,再一步步给你解决方法:


问题详情

你的项目 com.xx.app:XXXX:war:0.0.1-SNAPSHOT 在解析依赖时触发了核心错误:

无法从/向Shibboleth仓库(https://build.shibboleth.net/nexus/content/repositories/releases/)传输构件org.opensaml:opensaml:pom:2.6.6,报错信息为:sun.security.validator.ValidatorException: PKIX路径构建失败: sun.security.provider.certpath.SunCertPathBuilderException: 无法找到请求目标的有效认证路径。

简单来说,Maven访问Shibboleth的HTTPS仓库时,JVM的系统信任库中没有该网站的SSL证书,导致安全连接无法建立,自然拉取不到依赖。

你的项目POM配置

<repositories>
    <repository>
        <id>Shibboleth</id>
        <name>Shibboleth</name>
        <url>https://build.shibboleth.net/nexus/content/repositories/releases/</url>
    </repository>
</repositories>
<dependencies>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-web</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-security</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.security</groupId>
        <artifactId>spring-security-test</artifactId>
        <scope>test</scope>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-thymeleaf</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-tomcat</artifactId>
        <scope>provided</scope>
    </dependency>
    <dependency>
        <groupId>org.springframework.security.extensions</groupId>
        <artifactId>spring-security-saml2-core</artifactId>
        <version>1.0.10.RELEASE</version>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-test</artifactId>
        <scope>test</scope>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-data-jpa</artifactId>
    </dependency>
    <!-- ojdbc8.jar -->
    <dependency>
        <groupId>com.oracle.database.jdbc</groupId>
        <artifactId>ojdbc8</artifactId>
        <scope>runtime</scope>
    </dependency>
    <dependency>
        <groupId>org.apache.poi</groupId>
        <artifactId>poi-ooxml</artifactId>
        <version>3.17</version>
    </dependency>
    <!-- https://mvnrepository.com/artifact/javax.validation/validation-api -->
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-validation</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-mail</artifactId>
        <!-- <version>2.0.1.RELEASE</version> -->
    </dependency>
    <dependency>
        <groupId>javax.validation</groupId>
        <artifactId>validation-api</artifactId>
        <version>2.0.1.Final</version>
    </dependency>
    <dependency>
        <groupId>org.projectlombok</groupId>
        <artifactId>lombok</artifactId>
        <version>${lombok-version}</version>
        <scope>provided</scope>
    </dependency>
    <dependency>
        <groupId>org.mapstruct</groupId>
        <artifactId>mapstruct</artifactId>
        <version>1.3.1.Final</version>
    </dependency>
</dependencies>

解决方案

方案1:手动导入证书到JVM信任库(推荐生产/长期使用)

这是最安全合规的做法,步骤如下:

  • 导出证书:用浏览器打开Shibboleth仓库地址,点击地址栏的锁图标 → 「查看证书」→ 「导出证书」(保存为DER或PEM格式,比如命名为shibboleth.cer)
  • 导入到JVM信任库:打开终端/命令行,执行以下命令(替换$JAVA_HOME为你的JDK安装路径,/path/to/shibboleth.cer为证书文件的实际路径):
# Linux/Mac环境(需要sudo权限)
sudo keytool -import -alias shibboleth-repo -keystore $JAVA_HOME/jre/lib/security/cacerts -file /path/to/shibboleth.cer

# Windows环境(需用管理员身份打开命令行)
keytool -import -alias shibboleth-repo -keystore %JAVA_HOME%\jre\lib\security\cacerts -file C:\path\to\shibboleth.cer

默认信任库密码是changeit,按提示输入密码并确认导入即可。

方案2:Maven临时跳过SSL验证(仅开发环境使用)

如果只是开发阶段临时测试,可以让Maven跳过SSL证书验证,修改Maven的settings.xml(通常在~/.m2/settings.xml或Maven安装目录下的conf/settings.xml):

<profiles>
    <profile>
        <id>skip-ssl-check</id>
        <properties>
            <maven.wagon.http.ssl.insecure>true</maven.wagon.http.ssl.insecure>
            <maven.wagon.http.ssl.allowall>true</maven.wagon.http.ssl.allowall>
            <maven.wagon.http.ssl.ignore.validity.dates>true</maven.wagon.http.ssl.ignore.validity.dates>
        </properties>
    </profile>
</profiles>

<activeProfiles>
    <activeProfile>skip-ssl-check</activeProfile>
</activeProfiles>

也可以直接在项目pom.xml中添加配置:

<build>
    <extensions>
        <extension>
            <groupId>org.apache.maven.wagon</groupId>
            <artifactId>wagon-http</artifactId>
            <version>3.5.3</version> <!-- 使用与你的Maven版本兼容的最新版 -->
        </extension>
    </extensions>
</build>

<properties>
    <maven.wagon.http.ssl.insecure>true</maven.wagon.http.ssl.insecure>
    <maven.wagon.http.ssl.allowall>true</maven.wagon.http.ssl.allowall>
    <maven.wagon.http.ssl.ignore.validity.dates>true</maven.wagon.http.ssl.ignore.validity.dates>
</properties>

方案3:检查网络代理配置

如果你的网络使用了公司代理,需要确保Maven的代理配置正确,并且代理的证书也被JVM信任。可以在settings.xml中添加代理配置:

<proxies>
    <proxy>
        <id>company-proxy</id>
        <active>true</active>
        <protocol>https</protocol>
        <host>proxy.example.com</host>
        <port>8080</port>
        <!-- 如果代理需要认证,取消下面两行注释并填写信息 -->
        <!-- <username>proxy-username</username> -->
        <!-- <password>proxy-password</password> -->
        <nonProxyHosts>localhost|127.0.0.1</nonProxyHosts>
    </proxy>
</proxies>

内容的提问来源于stack exchange,提问作者Chiranjit Jasu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 14:57:30