关于DigiCert根证书升级遇到的问题及解决

553 阅读1分钟

相关公告

image.png

关于java

查看java自带密钥库信息,已经jdk11为列。

cd /use/local/jdk11/lib/security

# 解析一下cacert,输入的密钥库口令为:输入密钥库口令:  changeit
# keytool在jdk11/bin/keytools

keytool -list -v -keystore ../lib/security/cacerts > /tmp/cacerts-info.txt

然后在解析的文件中可以查询到DigiCert Global Root G2。

image.png

关于java应用程序运行可能出现的异常如下:

Caused by: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

证书下载:cacerts.digicert.com/DigiCertGlo…

证书安装:

keytool -keystore cacerts -importcert -alias DigiCertGlobalRootG2With2024 -file /opt/DigiCertGlobalRootG2.crt.pem