Стектрейс:
javax.net.ssl.SSLHandshakeException: ru.CryptoPro.ssl.pc_4.cl_5: PKIX path validation failed: java.security.cert.CertPathValidatorException: signature check failed
at ru.CryptoPro.ssl.cl_2.a(Unknown Source)
at ru.CryptoPro.ssl.SSLSocketImpl.a(Unknown Source)
at ru.CryptoPro.ssl.cl_59.a(Unknown Source)
at ru.CryptoPro.ssl.cl_59.a(Unknown Source)
at ru.CryptoPro.ssl.cl_16.a(Unknown Source)
at ru.CryptoPro.ssl.cl_16.a(Unknown Source)
at ru.CryptoPro.ssl.cl_59.s(Unknown Source)
at ru.CryptoPro.ssl.cl_59.a(Unknown Source)
at ru.CryptoPro.ssl.SSLSocketImpl.a(Unknown Source)
at ru.CryptoPro.ssl.SSLSocketImpl.n(Unknown Source)
at ru.CryptoPro.ssl.SSLSocketImpl.b(Unknown Source)
at ru.CryptoPro.ssl.SSLSocketImpl.startHandshake(Unknown Source)
at sun.net.www.protocol.https.HttpsClient.afterConnect(HttpsClient.java:559)
at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:185)
at sun.net.www.protocol.https.HttpsURLConnectionImpl.connect(HttpsURLConnectionImpl.java:162)
...
Caused by: ru.CryptoPro.ssl.pc_4.cl_5: PKIX path validation failed: java.security.cert.CertPathValidatorException: signature check failed
at ru.CryptoPro.ssl.pc_4.cl_2.a(Unknown Source)
at ru.CryptoPro.ssl.pc_4.cl_2.a(Unknown Source)
at ru.CryptoPro.ssl.pc_4.cl_4.b(Unknown Source)
at ru.CryptoPro.ssl.cl_121.a(Unknown Source)
at ru.CryptoPro.ssl.cl_121.a(Unknown Source)
at ru.CryptoPro.ssl.cl_121.checkServerTrusted(Unknown Source)
... 30 more
Caused by: java.security.cert.CertPathValidatorException: signature check failed
at sun.security.provider.certpath.PKIXMasterCertPathValidator.validate(PKIXMasterCertPathValidator.java:135)
at sun.security.provider.certpath.PKIXCertPathValidator.validate(PKIXCertPathValidator.java:233)
at sun.security.provider.certpath.PKIXCertPathValidator.validate(PKIXCertPathValidator.java:141)
at sun.security.provider.certpath.PKIXCertPathValidator.engineValidate(PKIXCertPathValidator.java:80)
at java.security.cert.CertPathValidator.validate(CertPathValidator.java:292)
at ru.CryptoPro.reprov.CPCertPathValidator.engineValidate(Unknown Source)
at java.security.cert.CertPathValidator.validate(CertPathValidator.java:292)
... 36 more
Caused by: java.security.SignatureException: Signature does not match.
at sun.security.x509.X509CertImpl.verify(X509CertImpl.java:449)
at sun.security.provider.certpath.BasicChecker.verifySignature(BasicChecker.java:166)
at sun.security.provider.certpath.BasicChecker.check(BasicChecker.java:147)
at sun.security.provider.certpath.PKIXMasterCertPathValidator.validate(PKIXMasterCertPathValidator.java:125)
... 42 more
Вот лог:
апр 17, 2023 4:58:36 PM ru.CryptoPro.JCP.pref.JCPPref getInt
CONFIG: System Preference Node: /ru/CryptoPro/ssl.RI_support=1
апр 17, 2023 4:58:36 PM ru.CryptoPro.JCP.pref.JCPPref getInt
CONFIG: System Preference Node: /ru/CryptoPro/ssl.RI_support=1
апр 17, 2023 4:58:36 PM ru.CryptoPro.JCP.pref.JCPPref getInt
CONFIG: System Preference Node: /ru/CryptoPro/ssl.RI_support=1
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Key.GostKeyFactory engineGeneratePublic
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Key.GostKeyFactory engineGeneratePublic
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Key.GostKeyFactory engineGeneratePublic
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Key.GostKeyFactory engineGeneratePublic
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: ENTRY
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: RETURN
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.pref.JCPPref getBoolean
CONFIG: System Preference Node: /ru/CryptoPro/ssl.Enable_revocation_default=false
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.pref.JCPPref getBoolean
CONFIG: System Preference Node: /ru/CryptoPro/reprov.disable_tsp_cert_app_ext_checker=false
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.tools.logger.LoggingUtils logBase64EncodedChain
FINER: %%% Validate chain. Chain size: 2
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.tools.logger.LoggingUtils logBase64EncodedChain
FINER: Certificate [0]:
serial number: 31e8310a0002000019ae
subject: CN=АО АТС ОРЭМ РФ, C=RU, ST=77 г.Москва, L=Москва, O=АО АТС, OID.1.2.643.100.1=#120D31303737373633383138343530, OID.1.2.643.3.131.1.1=#120C303037373033363531373932, EMAILADDRESS=atsca@rosenergo.com
issuer: CN=АО АТС, O="АО \"АТС\"", OU=УЦ, STREET="Краснопресненская набережная, дом 12, подъезд 7, этаж 8", L=Москва, ST=77 г.Москва, C=RU, OID.1.2.643.3.131.1.1=#120C303037373033363531373932, OID.1.2.643.100.1=#120D31303737373633383138343530
Valid from: 04.07.22 12:34 until: 04.07.27 12:34
[BASE64]
MIIHYTCCBw6gAwIBAgIKMegxCgACAAAZrjAKBggqhQMHAQEDAjCCAR8xGDAWBgUqhQNkARINMTA3
Nzc2MzgxODQ1MDEaMBgGCCqFAwOBAwEBEgwwMDc3MDM2NTE3OTIxCzAJBgNVBAYTAlJVMRswGQYD
VQQIDBI3NyDQsy7QnNC+0YHQutCy0LAxFTATBgNVBAcMDNCc0L7RgdC60LLQsDFpMGcGA1UECQxg
0JrRgNCw0YHQvdC+0L/RgNC10YHQvdC10L3RgdC60LDRjyDQvdCw0LHQtdGA0LXQttC90LDRjywg
0LTQvtC8IDEyLCDQv9C+0LTRitC10LfQtCA3LCDRjdGC0LDQtiA4MQ0wCwYDVQQLDATQo9CmMRYw
FAYDVQQKDA3QkNCeICLQkNCi0KEiMRQwEgYDVQQDDAvQkNCeINCQ0KLQoTAeFw0yMjA3MDQwOTM0
MjhaFw0yNzA3MDQwOTM0MjhaMIHVMSIwIAYJKoZIhvcNAQkBFhNhdHNjYUByb3NlbmVyZ28uY29t
MRowGAYIKoUDA4EDAQESDDAwNzcwMzY1MTc5MjEYMBYGBSqFA2QBEg0xMDc3NzYzODE4NDUwMRQw
EgYDVQQKDAvQkNCeINCQ0KLQoTEVMBMGA1UEBwwM0JzQvtGB0LrQstCwMRswGQYDVQQIDBI3NyDQ
sy7QnNC+0YHQutCy0LAxCzAJBgNVBAYTAlJVMSIwIAYDVQQDDBnQkNCeINCQ0KLQoSDQntCg0K3Q
nCDQoNCkMGYwHwYIKoUDBwEBAQEwEwYHKoUDAgIkAAYIKoUDBwEBAgIDQwAEQFESNSPeY5XU7fNZ
0yu9kvIFSTXKjZ0/zqXn4xceJQYyfJ5ptNrHNeiWJRmdm+lLtkGSqOYZYR9DGdBWHKyhlKWjggRq
MIIEZjATBgNVHSUEDDAKBggrBgEFBQcDATAOBgNVHQ8BAf8EBAMCBPAwUQYDVR0RBEowSIIOKi5h
dHNlbmVyZ28ucnWCDGF0c2VuZXJnby5ydYIQKi4qLmF0c2VuZXJnby5ydYIWcHJvdGVjdGVkLmF0
c2VuZXJnby5ydTATBgNVHSAEDDAKMAgGBiqFA2RxATArBgNVHRAEJDAigA8yMDIyMDcwNDA5MzQy
N1qBDzIwMjMwNzA0MDkzNDI3WjCCATEGBSqFA2RwBIIBJjCCASIMRyLQmtGA0LjQv9GC0L7Qn9GA
0L4gQ1NQIiDQktC10YDRgdC40Y8gNC4wICjQuNGB0L/QvtC70L3QtdC90LjQtSAyLUJhc2UpDHsi
0KPQtNC+0YHRgtC+0LLQtdGA0Y/RjtGJ0LjQuSDRhtC10L3RgtGAICLQmtGA0LjQv9GC0L7Qn9GA
0L4g0KPQpiIg0LLQtdGA0YHQuNC4IDIuMCIo0LLQsNGA0LjQsNC90YIg0LjRgdC/0L7Qu9C90LXQ
vdC40Y8gNSkMK9Ch0KQvMTI0LTM2MTEg0L7RgiAxMCDRj9C90LLQsNGA0Y8gMjAxOSDQsy4MLdCh
0KQvMTI4LTM1OTIg0L7RgiAxNyDQvtC60YLRj9Cx0YDRjyAyMDE4INCzLjA9BgUqhQNkbwQ0DDLQ
odCa0JfQmCAi0JrRgNC40L/RgtC+0J/RgNC+IENTUCIg0LLQtdGA0YHQuNGPIDQuMDCBuAYDVR0f
BIGwMIGtMFWgU6BRhk9odHRwOi8vd3d3LnJvc2VuZXJnby5jb20vYXRzY2EvY2RwL2VjNjdkOWY0
YzNjOWI1OWNkMTJjMjhmNGJjZGIyN2Q5NmVlMjg4YjAuY3JsMFSgUqBQhk5odHRwOi8vd3d3LmF0
c2VuZXJnby5ydS9hdHNjYS9jZHAvZWM2N2Q5ZjRjM2M5YjU5Y2QxMmMyOGY0YmNkYjI3ZDk2ZWUy
ODhiMC5jcmwwggFaBgNVHSMEggFRMIIBTYAU7GfZ9MPJtZzRLCj0vNsn2W7iiLChggEnpIIBIzCC
AR8xGDAWBgUqhQNkARINMTA3Nzc2MzgxODQ1MDEaMBgGCCqFAwOBAwEBEgwwMDc3MDM2NTE3OTIx
CzAJBgNVBAYTAlJVMRswGQYDVQQIDBI3NyDQsy7QnNC+0YHQutCy0LAxFTATBgNVBAcMDNCc0L7R
gdC60LLQsDFpMGcGA1UECQxg0JrRgNCw0YHQvdC+0L/RgNC10YHQvdC10L3RgdC60LDRjyDQvdCw
0LHQtdGA0LXQttC90LDRjywg0LTQvtC8IDEyLCDQv9C+0LTRitC10LfQtCA3LCDRjdGC0LDQtiA4
MQ0wCwYDVQQLDATQo9CmMRYwFAYDVQQKDA3QkNCeICLQkNCi0KEiMRQwEgYDVQQDDAvQkNCeINCQ
0KLQoYIKa69R/QACAAAVUTAdBgNVHQ4EFgQUJRzTVXEQLfb5BeUrwnKi8Vx+lSowCgYIKoUDBwEB
AwIDQQCrEfJr5uKBdd8oUJEibFdtSaW+HZQydqmiqz0MBhMjf3DaMxl5M+UmtBieR6R1iPCx0PBN
/DUqKmZdJwVPHGbT
апр 17, 2023 4:58:38 PM ru.CryptoPro.JCP.tools.logger.LoggingUtils logBase64EncodedChain
FINER: Certificate [1]:
serial number: 6baf51fd000200001551
subject: CN=АО АТС, O="АО \"АТС\"", OU=УЦ, STREET="Краснопресненская набережная, дом 12, подъезд 7, этаж 8", L=Москва, ST=77 г.Москва, C=RU, OID.1.2.643.3.131.1.1=#120C303037373033363531373932, OID.1.2.643.100.1=#120D31303737373633383138343530
issuer: CN=АО АТС, O="АО \"АТС\"", OU=УЦ, STREET="Краснопресненская набережная, дом 12, подъезд 7, этаж 8", L=Москва, ST=77 г.Москва, C=RU, OID.1.2.643.3.131.1.1=#120C303037373033363531373932, OID.1.2.643.100.1=#120D31303737373633383138343530
Valid from: 03.12.21 17:28 until: 03.12.27 17:28
[BASE64]
MIIFhzCCBTSgAwIBAgIKa69R/QACAAAVUTAKBggqhQMHAQEDAjCCAR8xGDAWBgUqhQNkARINMTA3
Nzc2MzgxODQ1MDEaMBgGCCqFAwOBAwEBEgwwMDc3MDM2NTE3OTIxCzAJBgNVBAYTAlJVMRswGQYD
VQQIDBI3NyDQsy7QnNC+0YHQutCy0LAxFTATBgNVBAcMDNCc0L7RgdC60LLQsDFpMGcGA1UECQxg
0JrRgNCw0YHQvdC+0L/RgNC10YHQvdC10L3RgdC60LDRjyDQvdCw0LHQtdGA0LXQttC90LDRjywg
0LTQvtC8IDEyLCDQv9C+0LTRitC10LfQtCA3LCDRjdGC0LDQtiA4MQ0wCwYDVQQLDATQo9CmMRYw
FAYDVQQKDA3QkNCeICLQkNCi0KEiMRQwEgYDVQQDDAvQkNCeINCQ0KLQoTAeFw0yMTEyMDMxNDI4
MjNaFw0yNzEyMDMxNDI4MjNaMIIBHzEYMBYGBSqFA2QBEg0xMDc3NzYzODE4NDUwMRowGAYIKoUD
A4EDAQESDDAwNzcwMzY1MTc5MjELMAkGA1UEBhMCUlUxGzAZBgNVBAgMEjc3INCzLtCc0L7RgdC6
0LLQsDEVMBMGA1UEBwwM0JzQvtGB0LrQstCwMWkwZwYDVQQJDGDQmtGA0LDRgdC90L7Qv9GA0LXR
gdC90LXQvdGB0LrQsNGPINC90LDQsdC10YDQtdC20L3QsNGPLCDQtNC+0LwgMTIsINC/0L7QtNGK
0LXQt9C0IDcsINGN0YLQsNC2IDgxDTALBgNVBAsMBNCj0KYxFjAUBgNVBAoMDdCQ0J4gItCQ0KLQ
oSIxFDASBgNVBAMMC9CQ0J4g0JDQotChMGYwHwYIKoUDBwEBAQEwEwYHKoUDAgIjAQYIKoUDBwEB
AgIDQwAEQLdph8h4hQuS9UGxH7PMLer0C+w7GcpmF7HTaZWVh/ruIiY7wVXOEY0GyPZ8K9h1cd5Q
FxLdNCpImg51tRPKxD2jggJFMIICQTAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0OBBYEFOxn2fTDybWc
0Swo9LzbJ9lu4oiwMA8GA1UdEwEB/wQFMAMBAf8wJQYDVR0gBB4wHDAGBgRVHSAAMAgGBiqFA2Rx
ATAIBgYqhQNkcQIwggExBgUqhQNkcASCASYwggEiDEci0JrRgNC40L/RgtC+0J/RgNC+IENTUCIg
0JLQtdGA0YHQuNGPIDQuMCAo0LjRgdC/0L7Qu9C90LXQvdC40LUgMi1CYXNlKQx7ItCj0LTQvtGB
0YLQvtCy0LXRgNGP0Y7RidC40Lkg0YbQtdC90YLRgCAi0JrRgNC40L/RgtC+0J/RgNC+INCj0KYi
INCy0LXRgNGB0LjQuCAyLjAiKNCy0LDRgNC40LDQvdGCINC40YHQv9C+0LvQvdC10L3QuNGPIDUp
DCvQodCkLzEyNC0zNjExINC+0YIgMTAg0Y/QvdCy0LDRgNGPIDIwMTkg0LMuDC3QodCkLzEyOC0z
NTkyINC+0YIgMTcg0L7QutGC0Y/QsdGA0Y8gMjAxOCDQsy4wWwYFKoUDZG8EUgxQ0KHQmtCX0Jgg
ItCa0YDQuNC/0YLQvtCf0YDQviBDU1AiINCy0LXRgNGB0LjRjyA0LjAgKNC40YHQv9C+0LvQvdC1
0L3QuNC1IDItQmFzZSkwEQYJKwYBBAGCNxQCBAQMAkNBMBIGCSsGAQQBgjcVAQQFAgMCAAIwHwYJ
KwYBBAGCNxUHBBIwEAYIKoUDAgIuAAACAQECAQAwCgYIKoUDBwEBAwIDQQBXW0HpX8AlluX87IbX
AMMU3dW5CHVcUOG6I7eaWzp20O3lZBiaAWR3lrC5x+INJo6VErcOgOZfHdEahVJz30+H
апр 17, 2023 4:58:40 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: ENTRY
апр 17, 2023 4:58:40 PM ru.CryptoPro.JCP.Sign.cl_0 engineInitVerify
FINER: RETURN
апр 17, 2023 4:58:40 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: ENTRY
апр 17, 2023 4:58:40 PM ru.CryptoPro.JCP.Sign.cl_0 engineVerify
FINER: RETURN
Вопросы:
1. В чём может быть проблема?
Вроде все сертификаты есть, но не соединяется
2. Где можно взять какие-нибудь тестовые сертификаты для доступа к тестовым страницам КриптоПро? В идеале хочется получить какой-нибудь файл хранилище и попробовать доступиться к какой-нибудь тестовой странице?