You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

连接Azure SQL Server时出现Java证书错误求助

连接Azure SQL Server时遇到PKIX路径构建失败错误

错误详情

Failed to authenticate the user ************* in Active Directory (Authentication=ActiveDirectoryPassword). javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
  java.lang.RuntimeException: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
  java.lang.RuntimeException: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
    javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
    javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

问题场景

当前使用DBeaver连接Azure SQL Server时触发该错误,同时在Java代码中采用相同认证方式连接也会出现相同问题,认证方式为ActiveDirectoryPassword。

已尝试的解决方案

  • 参考过Stack Overflow上关于PKIX路径错误的通用解决方法
  • 替换过同事可正常连接的cacerts证书文件
  • 替换DBeaver程序目录下的cacerts文件后重试连接
  • 启用DBeaver中的“信任服务器证书”选项
  • 导入过微软官方的TLS证书
  • 导入过目标Azure SQL Server自身的证书
  • 卸载JDK 17并升级至JDK 19,同时替换对应版本的cacerts文件

针对性解决建议

1. 确认JDK的cacerts文件路径是否正确

Java程序(包括DBeaver)可能会调用不同JDK的cacerts文件,需先确认当前使用的JDK位置:

  • 代码中:运行System.out.println(System.getProperty("java.home"))查看JDK路径
  • DBeaver中:打开偏好设置->连接->驱动->JDBC驱动,查看对应SQL Server驱动绑定的JDK路径

找到路径后,cacerts文件的位置:JDK 8及以下在{java.home}/lib/security/cacerts;JDK 9+在{java.home}/conf/security/cacerts。

2. 用keytool命令正确导入根CA证书

Azure SQL Server的SSL认证需要信任其根CA证书,而非服务器本身的证书,步骤如下:

  1. 用浏览器访问你的Azure SQL Server的FQDN(格式类似xxx.database.windows.net),导出网站的根CA证书
  2. 打开命令行,切换到目标JDK的bin目录,执行导入命令:
keytool -importcert -alias azure-sql-root -file /本地证书文件路径/root-cert.cer -keystore /cacerts文件的完整路径/ -storepass changeit
  • changeit是cacerts文件的默认密码,若修改过需替换为新密码
  • 导入时输入yes确认信任该证书

3. 检查DBeaver的SSL连接配置

在DBeaver的连接设置中,除启用“信任服务器证书”外,还需确认:

  • 在连接设置->SSL标签下,勾选“使用SSL”
  • 确保连接URL中包含encrypt=true参数(Azure SQL默认强制加密连接)
  • 若导入了自定义证书,可在SSL设置中指定“SSL证书文件”路径

4. 验证证书导入是否成功

执行以下命令,查看cacerts文件中是否存在导入的证书:

keytool -list -keystore /cacerts文件的完整路径/ -alias azure-sql-root -storepass changeit

若能返回证书的详细信息,说明导入成功。

5. 排查代理或网络问题

如果你的网络需要通过代理连接Azure,需确保Java程序和DBeaver都配置了正确的代理参数,且代理不会拦截或篡改SSL证书链。


内容的提问来源于stack exchange,提问作者user12477310

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 10:45:34