Java异常客户端身份验证TLS:密码不能为null

时间:2014-09-12 10:43:11

标签: java ssl passwords keystore ejbca

我写了这段代码与ejbca(JBoss 5.1.0.GA-jdk6和EJBCA 4.0.10。和openjdk-6-jdk)服务器进行通信:

CryptoProviderTools.installBCProvider();    
String urlstr = "https://ejbca05:8443/ejbca/ejbcaws/ejbcaws?wsdl";

System.setProperty("javax.net.ssl.trustStore","C:\\Users\\l.\\keystore.jks"); 
System.setProperty("javax.net.ssl.trustStorePassword","provae); 
System.setProperty("javax.net.ssl.keyStore","C:\\Users\\l.\\keystore.jks");
System.setProperty("javax.net.sslews.keyStorePassword","provae"); 
QName qname = new QName("http://ws.protocol.core.ejbca.org/", "EjbcaWSService");
EjbcaWSService service = null;
try {
    service = new EjbcaWSService(new URL(urlstr),qname);
} catch (MalformedURLException e) {
    // TODO Auto-generated catch block
    System.out.println("errore nell'url");
}
EjbcaWS ejbcaraws = service.getEjbcaWSPort(); 

但我有这个例外:

Exception in thread "main" javax.xml.ws.WebServiceException: Failed to access the WSDL at: https://ejbca05:8443/ejbca/ejbcaws/ejbcaws?wsdl. It failed with: 
    Got java.security.NoSuchAlgorithmException: Error constructing implementation (algorithm: Default, provider: SunJSSE, class: sun.security.ssl.SSLContextImpl$DefaultSSLContext) while opening stream from https://ejbca05:8443/ejbca/ejbcaws/ejbcaws?wsdl.
    at com.sun.xml.internal.ws.wsdl.parser.RuntimeWSDLParser.tryWithMex(RuntimeWSDLParser.java:173)
..........
.......
Caused by: java.security.UnrecoverableKeyException: Password must not be null
    at sun.security.provider.JavaKeyStore.engineGetKey(JavaKeyStore.java:124)
    at sun.security.provider.JavaKeyStore$JKS.engineGetKey(JavaKeyStore.java:55)
    at java.security.KeyStore.getKey(KeyStore.java:792)

密钥库是在jks中转换的superadmin.p12 ....我也试过用ejbca或keytool创建的其他密钥库但我得到了同样的错误。 谁知道为什么?

2 个答案:

答案 0 :(得分:1)

看起来该属性设置错误

<强>错误:

System.setProperty("javax.net.sslews.keyStorePassword","provae"); 

纠正一个:

System.setProperty("javax.net.ssl.keyStorePassword","provae"); 

答案 1 :(得分:0)

使用此代码似乎可以正常工作

String urlstr = "https://ejbca05.prv:8443/ejbca/ejbcaws/ejbcaws?wsdl";
        System.setProperty("javax.net.ssl.trustStore","C:/Users/l./Downloads/truststore.jks");
        System.setProperty("javax.net.ssl.trustStorePassword","provae");
        System.setProperty("javax.net.ssl.keyStore","C:/Users/l./Downloads/superadmin.p12");
        System.setProperty("javax.net.ssl.keyStoreType", "pkcs12");
        System.setProperty("javax.net.ssl.keyStorePassword","provae");

可能将p12转换为jks密钥库无法正常工作。

编辑:使用此命令可以转换为jks

keytool -importkeystore -srckeystore [MY_FILE.p12] -srcstoretype pkcs12
 -srcalias [ALIAS_SRC] -destkeystore [MY_KEYSTORE.jks]
 -deststoretype jks -deststorepass [PASSWORD_JKS] -destalias [ALIAS_DEST]