You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenJDK 8启用FIPS模式时抛出java.security.InvalidKeyException求助

问题:OpenJDK 1.8.0搭配NSS 3.79.0启用FIPS模式时HMAC测试报错CKR_ATTRIBUTE_VALUE_INVALID

已完成的配置操作

1. 修改java.security配置

  • 安全提供者配置:
    security.provider.1=sun.security.pkcs11.SunPKCS11 /opt/fipsconfig/pkcs11.cfg
    security.provider.2=sun.security.provider.Sun
    security.provider.3=sun.security.ec.SunEC
    security.provider.4=com.sun.net.ssl.internal.ssl.Provider SunPKCS11-NSSFIPS
    
  • 密钥库类型配置:
    keystore.type=PKCS11
    

2. 配置PKCS11参数文件/opt/fipsconfig/pkcs11.cfg

name = NSSFIPS
nssLibraryDirectory = /usr/lib64
nssSecmodDirectory = /etc/pki/nssdb
nssModule = fips
nssDbMode = readOnly

3. 验证NSS FIPS状态及令牌

  • 验证FIPS启用:
    modutil -chkfips true -dbdir /etc/pki/nssdb
    
    输出:
    FIPS mode enabled.
    
  • 验证令牌状态:
    modutil -dbdir /etc/pki/nssdb -list
    
    输出:
    Listing of PKCS #11 Modules
    -----------------------------------------------------------
      1. NSS Internal PKCS #11 Module
           uri: pkcs11:library-manufacturer=Mozilla%20Foundation;library-description=NSS%20Internal%20Crypto%20Services;library-version=3.79
         slots: 1 slot attached
        status: loaded
    
         slot: NSS FIPS 140-2 User Private Key Services
        token: NSS FIPS 140-2 Certificate DB
          uri: pkcs11:token=NSS%20FIPS%20140-2%20Certificate%20DB;manufacturer=Mozilla%20Foundation;serial=0000000000000000;model=NSS%203
    

测试报错详情

执行HMAC测试命令:

java hmac HmacSHA256 "key" "The quick brown fox jumps over the lazy dog"

抛出错误堆栈:

keystore PKCS11 type = PKCS11
keystore PKCS11 provider = SunPKCS11-NSSFIPS version 1.8
keystore PKCS11 size = 2
Exception in thread "main" java.security.InvalidKeyException: Could not create key
    at sun.security.pkcs11.P11SecretKeyFactory.createKey(P11SecretKeyFactory.java:274)
    at sun.security.pkcs11.P11SecretKeyFactory.convertKey(P11SecretKeyFactory.java:179)
    at sun.security.pkcs11.P11SecretKeyFactory.convertKey(P11SecretKeyFactory.java:111)
    at sun.security.pkcs11.P11Mac.engineInit(P11Mac.java:204)
    at javax.crypto.Mac.chooseProvider(Mac.java:350)
    at javax.crypto.Mac.init(Mac.java:415)
    at hmac.encode(hmac.java:19)
    at hmac.main(hmac.java:34)
Caused by: sun.security.pkcs11.wrapper.PKCS11Exception: CKR_ATTRIBUTE_VALUE_INVALID
    at sun.security.pkcs11.wrapper.PKCS11.C_CreateObject(Native Method)
    at sun.security.pkcs11.P11SecretKeyFactory.createKey(P11SecretKeyFactory.java:269)
    ... 7 more

已排查情况及需求

启用全Java调试模式后仅末尾出现上述异常,查看P11SecretKeyFactory.java的createKey()方法,发现该方法设置了三个属性,怀疑后两个属性导致CKR_ATTRIBUTE_VALUE_INVALID错误,寻求进一步排查线索。


内容的提问来源于stack exchange,提问作者user21176218

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 04:15:49