OpenJDK 8启用FIPS模式时抛出java.security.InvalidKeyException求助
问题:OpenJDK 1.8.0搭配NSS 3.79.0启用FIPS模式时HMAC测试报错CKR_ATTRIBUTE_VALUE_INVALID
已完成的配置操作
1. 修改java.security配置
- 安全提供者配置:
security.provider.1=sun.security.pkcs11.SunPKCS11 /opt/fipsconfig/pkcs11.cfg security.provider.2=sun.security.provider.Sun security.provider.3=sun.security.ec.SunEC security.provider.4=com.sun.net.ssl.internal.ssl.Provider SunPKCS11-NSSFIPS - 密钥库类型配置:
keystore.type=PKCS11
2. 配置PKCS11参数文件/opt/fipsconfig/pkcs11.cfg
name = NSSFIPS nssLibraryDirectory = /usr/lib64 nssSecmodDirectory = /etc/pki/nssdb nssModule = fips nssDbMode = readOnly
3. 验证NSS FIPS状态及令牌
- 验证FIPS启用:
输出:modutil -chkfips true -dbdir /etc/pki/nssdbFIPS mode enabled. - 验证令牌状态:
输出:modutil -dbdir /etc/pki/nssdb -listListing of PKCS #11 Modules ----------------------------------------------------------- 1. NSS Internal PKCS #11 Module uri: pkcs11:library-manufacturer=Mozilla%20Foundation;library-description=NSS%20Internal%20Crypto%20Services;library-version=3.79 slots: 1 slot attached status: loaded slot: NSS FIPS 140-2 User Private Key Services token: NSS FIPS 140-2 Certificate DB uri: pkcs11:token=NSS%20FIPS%20140-2%20Certificate%20DB;manufacturer=Mozilla%20Foundation;serial=0000000000000000;model=NSS%203
测试报错详情
执行HMAC测试命令:
java hmac HmacSHA256 "key" "The quick brown fox jumps over the lazy dog"
抛出错误堆栈:
keystore PKCS11 type = PKCS11 keystore PKCS11 provider = SunPKCS11-NSSFIPS version 1.8 keystore PKCS11 size = 2 Exception in thread "main" java.security.InvalidKeyException: Could not create key at sun.security.pkcs11.P11SecretKeyFactory.createKey(P11SecretKeyFactory.java:274) at sun.security.pkcs11.P11SecretKeyFactory.convertKey(P11SecretKeyFactory.java:179) at sun.security.pkcs11.P11SecretKeyFactory.convertKey(P11SecretKeyFactory.java:111) at sun.security.pkcs11.P11Mac.engineInit(P11Mac.java:204) at javax.crypto.Mac.chooseProvider(Mac.java:350) at javax.crypto.Mac.init(Mac.java:415) at hmac.encode(hmac.java:19) at hmac.main(hmac.java:34) Caused by: sun.security.pkcs11.wrapper.PKCS11Exception: CKR_ATTRIBUTE_VALUE_INVALID at sun.security.pkcs11.wrapper.PKCS11.C_CreateObject(Native Method) at sun.security.pkcs11.P11SecretKeyFactory.createKey(P11SecretKeyFactory.java:269) ... 7 more
已排查情况及需求
启用全Java调试模式后仅末尾出现上述异常,查看P11SecretKeyFactory.java的createKey()方法,发现该方法设置了三个属性,怀疑后两个属性导致CKR_ATTRIBUTE_VALUE_INVALID错误,寻求进一步排查线索。
内容的提问来源于stack exchange,提问作者user21176218
相关产品推荐
相关产品推荐

