Solved

Weblogic11 Load Balancer and SecurityException: does not match trust level of other classes in the same package

Posted on 2011-09-14
1
1,829 Views
Last Modified: 2012-05-12
Hi guys, getting stuck on very strange problem

1) We have a java swing app lauched via webstart and uses an EJB for backend, pretty standard flow.
2) Every jar we use are signed during each build/deploy
3) We have a weblogic11 cluster with 2 managed servers and a load balancer url that forwards to either of the managed servers
4) When launching the java swing app from either of the managed server directly there is no problem.
5) When launching the java swing app from the load balancer url we get the below exception that appears randomly all over the place for various class files in the jars.
6) We shutdown 1 managed server with only 1 server running, the issue remains when using the load balancer.

Basically this only happens when launching from the load balancer url, but if launched from the actual server url no problems.  I tried recreating the keystore etc.. but none of it helps.  

Any ideas?

Note: This is just 1 example in weblogic.jar but many different classes all over the place are throwing this exception as you use the java swing app. It happens randomly, click 1 would work, then click same button and this appears.

security: resource name "weblogic/kernel/KernelLogger.class" in OUR_LOAD_BALANCER_URL/weblogic.jar : java.lang.SecurityException: class "weblogic.kernel.KernelLogger" does not match trust level of other classes in the same package
Exception in thread "ExecuteThread: '0' for queue: 'default'" java.lang.SecurityException: class "weblogic.kernel.KernelLogger" does not match trust level of other classes in the same package
	at com.sun.deploy.security.CPCallbackHandler$ChildElement.checkResource(Unknown Source)
	at com.sun.deploy.security.DeployURLClassPath$JarLoader.checkResource(Unknown Source)
	at com.sun.deploy.security.DeployURLClassPath$JarLoader.getResource(Unknown Source)
	at com.sun.deploy.security.DeployURLClassPath.getResource(Unknown Source)
	at java.net.URLClassLoader$1.run(Unknown Source)
	at java.security.AccessController.doPrivileged(Native Method)
	at java.net.URLClassLoader.findClass(Unknown Source)
	at com.sun.jnlp.JNLPClassLoader.findClass(Unknown Source)
	at java.lang.ClassLoader.loadClass(Unknown Source)
	at java.lang.ClassLoader.loadClass(Unknown Source)
	at weblogic.kernel.ExecuteThread.execute(ExecuteThread.java:155)
	at weblogic.kernel.ExecuteThread.run(ExecuteThread.java:117)

security: resource name "weblogic/rjvm/PeerGoneEvent.class" in OUR_LOAD_BALANCER_URL/weblogic.jar : java.lang.SecurityException: class "weblogic.rjvm.PeerGoneEvent" does not match trust level of other classes in the same package

Open in new window

0
Comment
Question by:gagaliya
1 Comment
 
LVL 8

Accepted Solution

by:
allen-davis earned 500 total points
ID: 36552798
I found these links that seem to indicate it could be a class name collision if the files are signed with different certs from maybe different jars.  Do you possibly have some weblogic code/classes in your signed jars that could be colliding with the default classes?

http://stackoverflow.com/questions/2877262/java-securityexception-signer-information-does-not-match

http://stackoverflow.com/questions/4680823/java-lang-securityexception-class-org-apache-log4j-logger-does-not-match-trust
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Why do we like using grid based layouts in website design? Let's look at the live examples of websites and compare them to grid based WordPress themes.
Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo‚Ķ
This theoretical tutorial explains exceptions, reasons for exceptions, different categories of exception and exception hierarchy.
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now