OBIEE12c配置助手运行报错:无法找到DemoIdentity.jks身份密钥库文件
报错信息
weblogic.nodemanager.common.ConfigException: Identity key store file not found DemoIdentity.jks
关联错误日志:
<2021年2月6日 日本标准时间下午10:16:38,503> <无法在AdminServer服务器上找到身份密钥库文件 <DOMAIN_HOME>/security/DemoIdentity.jks>
<2021年2月6日 日本标准时间下午10:16:38,504> <安全配置不一致,weblogic.management.configuration.ConfigurationException: 无法在AdminServer服务器上找到身份密钥库文件 <DOMAIN_HOME>/security/DemoIdentity.jks>
<2021年2月6日 日本标准时间下午10:16:38,504> <未监听SSL,weblogic.management.configuration.ConfigurationException: 无法在AdminServer服务器上找到身份密钥库文件 <DOMAIN_HOME>/security/DemoIdentity.jks。>
<2021年2月6日 日本标准时间下午10:16:38,505> <服务器无法在通道"DefaultSecure[iiops][5]"上创建用于监听的服务器套接字。地址127.0.0.1可能不正确,或端口7002被其他进程占用:java.io.IOException: 无法在AdminServer服务器上找到身份密钥库文件 <DOMAIN_HOME>/security/DemoIdentity.jks>
排查步骤
- 校验文件存在性与权限:执行命令
ls <DOMAIN_HOME>/security/DemoIdentity.jks,确认文件是否存在,同时确认WebLogic运行用户对该文件具备可读权限 - 校验配置路径正确性:登录WebLogic控制台,依次进入服务器-AdminServer-配置-密钥库页签,确认身份密钥库路径是否与实际文件路径一致,无拼写错误
- 排查文件丢失原因:检查域创建阶段是否手动关闭了演示密钥库自动生成开关,或者是否有安全软件、清理脚本误删除了该文件
解决方案
场景1:文件未生成/已被删除
切换到域security目录执行命令生成演示密钥库:
- 生成证书与密钥文件:
java utils.CertGen -cn <你的主机名> -keyfilepass DemoIdentityPassPhrase -certfile democert -keyfile demokey - 导入生成jks密钥库文件:
java utils.ImportPrivateKey -keystore DemoIdentity.jks -storepass DemoIdentityKeyStorePassPhrase -keyfile demokey -keyfilepass DemoIdentityPassPhrase -certfile democert.pem -alias demoidentity - 修改文件权限适配WebLogic运行用户:
chown <WebLogic运行用户名>:<WebLogic用户组> DemoIdentity.jks && chmod 640 DemoIdentity.jks
操作完成后重启AdminServer即可恢复。
场景2:密钥库配置路径错误
如果文件实际存在,仅WebLogic配置中填写的路径错误,直接在WebLogic控制台的AdminServer密钥库配置页修改为正确的文件路径,保存后重启AdminServer即可。
场景3:测试环境临时绕过方案
如果是测试环境不需要启用SSL监听,可直接关闭SSL端口:登录WebLogic控制台进入服务器-AdminServer-配置-通用页签,取消勾选「SSL监听端口启用」,保存后重启服务即可绕过该报错。
内容的提问来源于stack exchange,提问作者Reja

