部署含IEnterpriseSession的WAR至JBoss遇ExceptionInInitializerError求助
我有一个会创建IEnterpriseSession的WAR文件,在Tomcat上运行完全正常,但部署到JBoss后,执行sessionMgr.logon(trustedPrincipal);这一步时抛出了初始化异常,错误栈如下:
Caused by: java.lang.ExceptionInInitializerError at com.businessobjects.bcm.BCM.<clinit>(BCM.java:1144) at com.crystaldecisions.sdk.framework.internal.TrustedPrincipal.getRandomString(TrustedPrincipal.java:252) at com.crystaldecisions.sdk.framework.internal.TrustedPrincipal.getPassword(TrustedPrincipal.java:195) at com.crystaldecisions.sdk.framework.internal.SessionMgr.logon_aroundBody22(SessionMgr.java:850) at com.crystaldecisions.sdk.framework.internal.SessionMgr.logon(SessionMgr.java:1) at com.crystaldecisions.sdk.framework.internal.SessionMgr.logon_aroundBody20(SessionMgr.java:818) at com.crystaldecisions.sdk.framework.internal.SessionMgr.logon_aroundBody21$advice(SessionMgr.java:512) at com.crystaldecisions.sdk.framework.internal.SessionMgr.logon(SessionMgr.java:1)
我尝试了Stack Overflow上《ExceptionInInitializerError - JBoss 7.0.2》里提到的解决方案,但问题依然没有解决。进一步排查后,现在卡在了这个FIPS相关的安全异常:
Caused by: java.lang.SecurityException: An internal FIPS 140 self-verification test has failed. Algorithm HMAC has been disabled at com.rsa.cryptoj.f.ug.d(Unknown Source) at com.rsa.cryptoj.f.ug.b(Unknown Source) at com.rsa.cryptoj.f.nd.b(Unknown Source) at com.rsa.cryptoj.f.nd.c(Unknown Source) at com.rsa.jsafe.CryptoJ.isFIPS140Compliant(Unknown Source) at com.businessobjects.bcm.internal.BcmRsaLib.initialize(BcmRsaLib.java:214) at com.businessobjects.bcm.internal.BcmRsaLib.<clinit>(BcmRsaLib.java:289)
可能的解决方法
关闭JBoss的FIPS模式:JBoss默认可能开启了FIPS合规检查,而BusinessObjects的BCM组件和这个模式不兼容。你可以在JBoss的配置文件(比如
standalone.xml或domain.xml)里找到<security>节点,修改<fips>配置为<fips enabled="false"/>,然后重启JBoss试试。排除加密库冲突:JBoss自带的RSA CryptoJ加密库可能和你的WAR包中BusinessObjects自带的库冲突。可以在WAR的
WEB-INF目录下创建jboss-deployment-structure.xml文件,添加排除规则让应用使用自身的加密库:<jboss-deployment-structure> <deployment> <exclusions> <module name="com.rsa.cryptoj"/> <module name="org.jboss.security.fips"/> </exclusions> </deployment> </jboss-deployment-structure>配置好后重新部署应用。
检查JVM启动参数:确认JVM没有启用FIPS相关的系统属性。查看JBoss的启动脚本,移除类似
-Djava.security.properties=/path/to/fips.properties或者-Dcom.rsa.jsafe.defaultFIPS=true这类参数。验证版本兼容性:确认你使用的BusinessObjects SDK版本和JBoss版本是兼容的。有些旧版BO SDK在JBoss 7及以上环境中会有加密相关的兼容性问题,尝试升级到官方推荐的兼容版本。
内容的提问来源于stack exchange,提问作者Mukunda Pasumarthi

