启用javax.net.debug系统属性后无法打印服务器证书的求助
启用javax.net.debug系统属性后无法打印服务器证书的求助
我最近遇到了一个TLS握手的调试难题,想向大家求助:
我正在排查这个TLS握手错误:
sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
按照相关指引,我开启了javax.net.debug=all系统属性来调试SSL握手细节,但目前日志只输出了信任存储的内容,完全看不到握手过程中服务器出示的证书和证书链信息。
这是我目前看到的日志片段:
javax.net.ssl|DEBUG|D3|grpc-default-worker-ELG-3-17|2025-06-19 12:03:55.710 UTC|TrustStoreManager.java:162|Inaccessible trust store: /usr/lib/jvm/java-17-openjdk-amd64/lib/security/jssecacerts javax.net.ssl|DEBUG|D3|grpc-default-worker-ELG-3-17|2025-06-19 12:03:55.710 UTC|TrustStoreManager.java:113|trustStore is: /usr/lib/jvm/java-17-openjdk-amd64/lib/security/cacerts trustStore type is: pkcs12 trustStore provider is: the last modified time is: Wed Jun 18 20:18:53 UTC 2025 javax.net.ssl|DEBUG|D3|grpc-default-worker-ELG-3-17|2025-06-19 12:03:55.733 UTC|X509TrustManagerImpl.java:82|adding as trusted certificates ( "certificate" : { "version" : "v3", "serial number" : "0d:6a:5f:08:3f:28:5c:3e:51:95:df:5d", "signature algorithm": "SHA256withECDSA", "issuer" : "CN=Trustwave Global ECC P256 Certification Authority, O="Trustwave Holdings, Inc.", L=Chicago, ST=Illinois, C=US", . . .
我检查了整个日志,发现里面完全没有出现"chain"这个关键词。虽然官方提到过SSL调试日志的格式是非标准的,但正常情况下应该能看到服务器证书相关的输出才对。
有没有大佬知道,我该怎么调整配置,才能让日志打印出服务器发送的证书和证书链信息呢?
内容来源于stack exchange
相关产品推荐
相关产品推荐

