You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为Netty WebSocket Server生成自签名证书遇错及解决

Netty 4.1.86 WebSocket Server自签名证书问题解决

问题场景

我正尝试为Netty(4.1.86)WebSocket Server生成自签名证书。服务器在无SSL及使用SelfSignedCertificate类生成证书时均可正常运行,但使用OpenSSL生成自签名证书时遇到问题。

报错代码

执行以下代码时出现异常:

SslContext sslCtx = SslContextBuilder.forServer(new File(certFile), new File(keyFile), password).build();

错误信息

抛出的错误详情如下:

ERROR Thread-5 com..application.NettyWSServer - Exception caught:
java.lang.IllegalArgumentException: File does not contain valid private key: /home/johnny/testbench/application/app.pkcs8.key
        at io.netty.handler.ssl.SslContextBuilder.keyManager(SslContextBuilder.java:386)
        at io.netty.handler.ssl.SslContextBuilder.forServer(SslContextBuilder.java:120)
        at com..application.NettyWSServer.start(NettyWSServer.java:78)
        at com..application.ApplicationLauncher$2.run(ApplicationLauncherncher.java:315)
        at java.base/java.lang.Thread.run(Thread.java:829)
Caused by: java.security.NoSuchAlgorithmException: 1.2.840.113549.1.5.13 SecretKeyFactory not available
        at java.base/javax.crypto.SecretKeyFactory.<init>(SecretKeyFactory.java:122)
        at java.base/javax.crypto.SecretKeyFactory.getInstance(SecretKeyFactory.java:168)
        at io.netty.handler.ssl.SslContext.generateKeySpec(SslContext.java:1084)
        at io.netty.handler.ssl.SslContext.getPrivateKeyFromByteBuffer(SslContext.java:1170)
        at io.netty.handler.ssl.SslContext.toPrivateKey(SslContext.java:1133)
        at io.netty.handler.ssl.SslContextBuilder.keyManager(SslContextBuilder.java:384)
        ... 4 more

原证书生成命令

我原本生成证书文件(app.pem)和密钥文件(app.pkcs8.key)的命令如下:

openssl genrsa -out app.key 2048

openssl pkcs8 -topk8 -in app.key -out app.pkcs8.key

openssl req -x509 -new -nodes -key app.key -sha256 -days 1024 -out app.pem

已知Netty要求使用PKCS8格式的密钥。

可行解决方案

感谢dave_thompson_085提供的可行解决方案,调整后的证书生成命令如下:

openssl genrsa -out app.key 2048

openssl pkcs8 -topk8 -v1 PBE-SHA1-3DES -nocrypt -in app.key -out app.pkcs8.key

openssl req -x509 -new -nodes -key app.key -sha256 -days 1024 -out app.pem

内容的提问来源于stack exchange,提问作者jcfrei

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 05:30:47