You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

BlindSSLSocketFactory实现LDAPS证书绕过在生产环境失效

Troubleshooting LDAPS Certificate Bypass Failure in Packaged Java App (Amazon Corretto 1.8.0_275)

Hey there, let's break down why your LDAPS certificate bypass works in Eclipse but fails when your app is packaged and run. Since you've already got the BlindSSLSocketFactory working in development, the issue almost always boils down to differences between the IDE runtime and your packaged environment. Here are the key fixes to try:

1. Ensure Your Custom Socket Factory is Properly Loaded & Configured

Eclipse's classloader handles dependencies differently than a packaged JAR/WAR. Your BlindSSLSocketFactory might not be getting registered correctly with JNDI in production. Instead of relying on injection, explicitly set the factory in your LDAP environment properties:

Hashtable<String, Object> ldapEnv = new Hashtable<>();
ldapEnv.put(Context.INITIAL_CONTEXT_FACTORY, "com.sun.jndi.ldap.LdapCtxFactory");
ldapEnv.put(Context.PROVIDER_URL, "ldaps://your-ldap-host:636");
ldapEnv.put(Context.SECURITY_PROTOCOL, "ssl");
// Explicitly point to your bypass factory
ldapEnv.put("java.naming.ldap.factory.socket", "com.your.package.BlindSSLSocketFactory");
ldapEnv.put(Context.SECURITY_AUTHENTICATION, "simple");
ldapEnv.put(Context.SECURITY_PRINCIPAL, userDn);
ldapEnv.put(Context.SECURITY_CREDENTIALS, password);

// Force endpoint identification disable BEFORE initializing JNDI
System.setProperty("com.sun.jndi.ldap.object.disableEndpointIdentification", "true");

// Initialize context
DirContext context = new InitialDirContext(ldapEnv);

Double-check that BlindSSLSocketFactory is included in your packaged artifact (open your JAR/WAR to confirm the class exists in the correct package path).

2. Verify Your JVM Startup Parameters Are Applied Correctly

When running your packaged app, the -Dcom.sun.jndi.ldap.object.disableEndpointIdentification=true parameter must come before the -jar flag in your startup command. If you put it after, it won't be picked up by the JVM:

# Correct order
java -Dcom.sun.jndi.ldap.object.disableEndpointIdentification=true -jar your-app.jar

# Wrong order (parameter won't apply)
java -jar your-app.jar -Dcom.sun.jndi.ldap.object.disableEndpointIdentification=true

If you're unsure, add debug logs to your LdapAuthentication code to confirm the property is set:

System.out.println("Endpoint identification disabled: " + 
    System.getProperty("com.sun.jndi.ldap.object.disableEndpointIdentification"));

3. Fix Potential SSLContext Conflicts in Your BlindSSLSocketFactory

Amazon Corretto 8 might have stricter SSL defaults than Eclipse's runtime. Ensure your factory fully bypasses all certificate checks by using a trust-all X509TrustManager and properly initializing the SSLContext:

public class BlindSSLSocketFactory extends SSLSocketFactory {
    private final SSLSocketFactory delegate;

    public BlindSSLSocketFactory() throws NoSuchAlgorithmException, KeyManagementException {
        SSLContext sslContext = SSLContext.getInstance("TLS");
        sslContext.init(null, new TrustManager[]{
            new X509TrustManager() {
                @Override
                public X509Certificate[] getAcceptedIssuers() { return new X509Certificate[0]; }
                @Override
                public void checkClientTrusted(X509Certificate[] certs, String authType) {}
                @Override
                public void checkServerTrusted(X509Certificate[] certs, String authType) {}
            }
        }, new SecureRandom());
        this.delegate = sslContext.getSocketFactory();
    }

    // Delegate all other SSLSocketFactory methods to the initialized factory
    @Override
    public Socket createSocket(Socket s, String host, int port, boolean autoClose) throws IOException {
        Socket socket = delegate.createSocket(s, host, port, autoClose);
        // Disable hostname verification entirely (critical for bypass)
        if (socket instanceof SSLSocket) {
            ((SSLSocket) socket).setEnabledProtocols(((SSLSocket) socket).getSupportedProtocols());
        }
        return socket;
    }

    // Implement remaining abstract methods by delegating to this.delegate
    @Override
    public String[] getDefaultCipherSuites() { return delegate.getDefaultCipherSuites(); }
    @Override
    public String[] getSupportedCipherSuites() { return delegate.getSupportedCipherSuites(); }
    @Override
    public Socket createSocket(String host, int port) throws IOException { return delegate.createSocket(host, port); }
    @Override
    public Socket createSocket(String host, int port, InetAddress localHost, int localPort) throws IOException { return delegate.createSocket(host, port, localHost, localPort); }
    @Override
    public Socket createSocket(InetAddress host, int port) throws IOException { return delegate.createSocket(host, port); }
    @Override
    public Socket createSocket(InetAddress host, int port, InetAddress localHost, int localPort) throws IOException { return delegate.createSocket(host, port, localHost, localPort); }
}

Make sure no other code in your app is overriding the global SSLContext or TrustManager—this could silently undo your bypass settings.

4. Check for Packaging Tool Conflicts

If you're using Maven Shade or Gradle Shadow to package your app, you might be hitting classpath conflicts or missing service provider entries:

  • For Maven Shade, add a filter to exclude conflicting SSL-related dependencies (if any) and ensure your BlindSSLSocketFactory isn't being renamed or excluded.
  • Verify that META-INF/services/com.sun.jndi.ldap.LdapSocketFactory (if you're using service providers) is correctly included in your package.

Debugging Tip

Add logs to print the actual SSLSocketFactory being used by JNDI:

SocketFactory factory = (SocketFactory) ldapEnv.get("java.naming.ldap.factory.socket");
System.out.println("Using socket factory: " + factory.getClass().getName());

This will confirm if your custom factory is actually being picked up at runtime.


内容的提问来源于stack exchange,提问作者Ahmet Eroğlu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:05:30