You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Java 11环境下OkHttp SSL相关异常问题咨询

OkHttp + Java 11 SSL Issues in Kubernetes/Docker Environment

Let’s break down your problem and the known compatibility quirks between OkHttp and Java 11 that could be causing these intermittent failures:

Root Cause Analysis

Both exceptions point to SSL handshake failures related to missing or unretrievable certificate chains, which only surface in your Kubernetes/Docker environment (not locally). Here’s why this happens with Java 11:

  1. TLS 1.3 Compatibility Gaps
    Java 11 enables TLS 1.3 by default, but older OkHttp versions (like 3.12.1 and even 3.14.2) have incomplete support for TLS 1.3. When negotiating TLS 1.3 with certain servers (like graph.facebook.com), OkHttp may fail to properly retrieve the certificate chain, leading to either:

    • IndexOutOfBoundsException (empty certificate list accessed in 3.12.1)
    • SSLPeerUnverifiedException (explicit "no certificates" error in 3.14.2)
  2. Docker/Java 11 CA Certificate Differences
    Java 11 uses a different default cacerts truststore path compared to Java 8. If your Docker image doesn’t include the full set of root CA certificates (especially those needed for Facebook’s SSL chain), OkHttp can’t verify the server’s identity. Local environments usually have a complete truststore, which is why you don’t see the issue there.

  3. Kubernetes Network Interference
    Sidecar proxies (e.g., Istio, Linkerd) or network policies in Kubernetes might intercept HTTPS traffic and modify the SSL handshake flow, leading to unexpected certificate chain issues that don’t occur in direct local networking.

Fixes to Try

1. Force TLS 1.2 in OkHttp

Disable TLS 1.3 to avoid compatibility bugs in older OkHttp versions. Add this configuration to your OkHttpClient builder:

// Explicitly use TLS 1.2 only
ConnectionSpec tls12Spec = new ConnectionSpec.Builder(ConnectionSpec.MODERN_TLS)
    .tlsVersions(TlsVersion.TLS_1_2)
    .build();

OkHttpClient httpClient = new OkHttpClient.Builder()
    .connectTimeout(10000, TimeUnit.MILLISECONDS)
    .readTimeout(10000, TimeUnit.MILLISECONDS)
    .connectionSpecs(Collections.singletonList(tls12Spec))
    .build();

2. Ensure Complete CA Certificates in Docker

Update your Docker image to include a full truststore:

  • For Debian/Ubuntu-based images, install the ca-certificates-java package, which populates /etc/ssl/certs/java/cacerts with all standard root CAs.
  • Alternatively, copy your local Java 11 cacerts file into the container’s $JAVA_HOME/lib/security directory.

3. Upgrade OkHttp to a Java 11-Compatible Version

Older OkHttp 3.x versions have limited Java 11 support. Upgrade to:

  • OkHttp 3.14.9 (the last stable 3.x release with better Java 11 fixes)
  • Or directly to OkHttp 4.x (fully optimized for Java 11+, with resolved TLS 1.3 compatibility issues)

4. Check Kubernetes Sidecar/Network Configs

If you’re using a service mesh like Istio, verify that:

  • The sidecar isn’t stripping or modifying SSL certificates for outbound requests to graph.facebook.com.
  • You’ve configured proper TLS passthrough or mTLS rules if required.

Why This Doesn’t Reproduce Locally

Your local environment likely has:

  • A complete truststore with all necessary root CAs.
  • No network proxies interfering with SSL handshakes.
  • More consistent resource availability (no CPU/memory throttling that could disrupt SSL handshake processes in Kubernetes pods).

内容的提问来源于stack exchange,提问作者Alex Kamornikov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:05:30