Java 11环境下OkHttp SSL相关异常问题咨询
Let’s break down your problem and the known compatibility quirks between OkHttp and Java 11 that could be causing these intermittent failures:
Root Cause Analysis
Both exceptions point to SSL handshake failures related to missing or unretrievable certificate chains, which only surface in your Kubernetes/Docker environment (not locally). Here’s why this happens with Java 11:
TLS 1.3 Compatibility Gaps
Java 11 enables TLS 1.3 by default, but older OkHttp versions (like 3.12.1 and even 3.14.2) have incomplete support for TLS 1.3. When negotiating TLS 1.3 with certain servers (like graph.facebook.com), OkHttp may fail to properly retrieve the certificate chain, leading to either:IndexOutOfBoundsException(empty certificate list accessed in 3.12.1)SSLPeerUnverifiedException(explicit "no certificates" error in 3.14.2)
Docker/Java 11 CA Certificate Differences
Java 11 uses a different defaultcacertstruststore path compared to Java 8. If your Docker image doesn’t include the full set of root CA certificates (especially those needed for Facebook’s SSL chain), OkHttp can’t verify the server’s identity. Local environments usually have a complete truststore, which is why you don’t see the issue there.Kubernetes Network Interference
Sidecar proxies (e.g., Istio, Linkerd) or network policies in Kubernetes might intercept HTTPS traffic and modify the SSL handshake flow, leading to unexpected certificate chain issues that don’t occur in direct local networking.
Fixes to Try
1. Force TLS 1.2 in OkHttp
Disable TLS 1.3 to avoid compatibility bugs in older OkHttp versions. Add this configuration to your OkHttpClient builder:
// Explicitly use TLS 1.2 only ConnectionSpec tls12Spec = new ConnectionSpec.Builder(ConnectionSpec.MODERN_TLS) .tlsVersions(TlsVersion.TLS_1_2) .build(); OkHttpClient httpClient = new OkHttpClient.Builder() .connectTimeout(10000, TimeUnit.MILLISECONDS) .readTimeout(10000, TimeUnit.MILLISECONDS) .connectionSpecs(Collections.singletonList(tls12Spec)) .build();
2. Ensure Complete CA Certificates in Docker
Update your Docker image to include a full truststore:
- For Debian/Ubuntu-based images, install the
ca-certificates-javapackage, which populates/etc/ssl/certs/java/cacertswith all standard root CAs. - Alternatively, copy your local Java 11
cacertsfile into the container’s$JAVA_HOME/lib/securitydirectory.
3. Upgrade OkHttp to a Java 11-Compatible Version
Older OkHttp 3.x versions have limited Java 11 support. Upgrade to:
- OkHttp 3.14.9 (the last stable 3.x release with better Java 11 fixes)
- Or directly to OkHttp 4.x (fully optimized for Java 11+, with resolved TLS 1.3 compatibility issues)
4. Check Kubernetes Sidecar/Network Configs
If you’re using a service mesh like Istio, verify that:
- The sidecar isn’t stripping or modifying SSL certificates for outbound requests to
graph.facebook.com. - You’ve configured proper TLS passthrough or mTLS rules if required.
Why This Doesn’t Reproduce Locally
Your local environment likely has:
- A complete truststore with all necessary root CAs.
- No network proxies interfering with SSL handshakes.
- More consistent resource availability (no CPU/memory throttling that could disrupt SSL handshake processes in Kubernetes pods).
内容的提问来源于stack exchange,提问作者Alex Kamornikov

