构建项目后获取.p12证书时出现DerInputStream.getLength()错误
解决构建后加载PKCS12证书出现
DerInputStream.getLength(): lengthTag=111, too big错误 问题场景
- IDE直接运行项目时,加载
cert.p12证书完全正常 - 执行
mvn clean package构建后运行,触发DerInputStream.getLength(): lengthTag=111, too big错误 - 已尝试转换证书为JKS格式、在pom.xml中配置资源过滤排除.p12文件,但均未解决问题
可用解决方案
1. 修正Maven资源过滤配置优先级
你当前的资源过滤规则可能因为节点顺序问题未生效,二进制证书文件被错误地当成文本文件处理,导致内容损坏。调整配置顺序,让禁用过滤的规则优先:
<resources> <!-- 先配置不过滤.p12文件的规则,确保优先级更高 --> <resource> <directory>src/main/resources</directory> <filtering>false</filtering> <includes> <include>**/*.p12</include> </includes> </resource> <!-- 再配置需要过滤的其他资源 --> <resource> <directory>src/main/resources</directory> <filtering>true</filtering> <excludes> <exclude>**/*.p12</exclude> </excludes> </resource> </resources>
配置完成后,对比构建前后cert.p12文件的大小,如果一致则说明过滤规则生效。
2. 修正OpenSSL证书生成命令
你的生成命令中-passout pass: 123456存在多余空格,可能导致密码设置异常,进而影响证书文件结构:
原命令:
openssl pkcs12 -export -out cert.p12 -in cert_crt.pem -inkey cert_key.pem -passout pass: 123456
修改为(移除pass:后的空格):
openssl pkcs12 -export -out cert.p12 -in cert_crt.pem -inkey cert_key.pem -passout pass:123456
重新生成证书后替换原文件,再执行构建测试。
3. 优化证书加载代码
确保以二进制流方式完整读取证书文件,避免流读取不完整导致解析失败:
InputStream keyInput = classLoader.getResourceAsStream("certfile/cert.p12"); BufferedInputStream bis = new BufferedInputStream(keyInput); KeyStore keyStore = KeyStore.getInstance("PKCS12"); keyStore.load(bis, p12password.toCharArray()); bis.close(); keyInput.close();
4. 检查Spring Boot打包插件(若使用)
如果项目依赖spring-boot-maven-plugin,需要在插件配置中单独指定证书文件不被过滤:
<plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> <configuration> <resources> <resource> <directory>src/main/resources</directory> <filtering>false</filtering> <includes> <include>**/*.p12</include> </includes> </resource> </resources> </configuration> </plugin>
内容的提问来源于stack exchange,提问作者Lftbrito
相关产品推荐
相关产品推荐

