亚洲香蕉成人av网站在线观看_欧美精品成人91久久久久久久_久久久久久久久久久亚洲_热久久视久久精品18亚洲精品_国产精自产拍久久久久久_亚洲色图国产精品_91精品国产网站_中文字幕欧美日韩精品_国产精品久久久久久亚洲调教_国产精品久久一区_性夜试看影院91社区_97在线观看视频国产_68精品久久久久久欧美_欧美精品在线观看_国产精品一区二区久久精品_欧美老女人bb

首頁 > 開發 > Java > 正文

java開發https請求ssl不受信任問題解決方法

2024-07-13 10:16:55
字體:
來源:轉載
供稿:網友

本文主要討論的是java/239233.html">java/98813.html">java開發https請求ssl不受信任的解決方法,具體分析及實現代碼如下。

在java代碼中請求https鏈接的時候,可能會報下面這個錯誤

javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

原因是沒有證書。在瀏覽器中直接使用url訪問是可以的,應該是瀏覽器之前就保存過對應的.cer證書。

解決方法有兩種,從目標機器獲得有效證書或者忽略證書信任問題。

一、獲得目標機器有效證書

1、編譯安裝證書程序 javac InstallCert.java(代碼如下)

/*  * Copyright 2006 Sun Microsystems, Inc. All Rights Reserved.  *  * Redistribution and use in source and binary forms, with or without  * modification, are permitted provided that the following conditions  * are met:  *  *  - Redistributions of source code must retain the above copyright  *   notice, this list of conditions and the following disclaimer.  *  *  - Redistributions in binary form must reproduce the above copyright  *   notice, this list of conditions and the following disclaimer in the  *   documentation and/or other materials provided with the distribution.  *  *  - Neither the name of Sun Microsystems nor the names of its  *   contributors may be used to endorse or promote products derived  *   from this software without specific prior written permission.  *  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS  * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR  * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR  * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,  * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,  * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR  * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF  * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING  * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.  *//**  * http://blogs.sun.com/andreas/resource/InstallCert.java  * Use:  * java InstallCert hostname  * Example:  *% java InstallCert ecc.fedora.redhat.com  */import javax.net.ssl.*;import java.io.*;import java.security.KeyStore;import java.security.MessageDigest;import java.security.cert.CertificateException;import java.security.cert.X509Certificate;/**  * Class used to add the server's certificate to the KeyStore  * with your trusted certificates.  */public class InstallCert {	public static void main(String[] args) throws Exception {		String host;		int port;		char[] passphrase;		if ((args.length == 1) || (args.length == 2)) {			String[] c = args[0].split(":");			host = c[0];			port = (c.length == 1) ? 443 : Integer.parseint(c[1]);			String p = (args.length == 1) ? "changeit" : args[1];			passphrase = p.toCharArray();		} else {			System.out.println("Usage: java InstallCert <host>[:port] [passphrase]");			return;		}		File file = new File("jssecacerts");		if (file.isFile() == false) {			char SEP = File.separatorchar;			File dir = new File(System.getProperty("java.home") + SEP 			          + "lib" + SEP + "security");			file = new File(dir, "jssecacerts");			if (file.isFile() == false) {				file = new File(dir, "cacerts");			}		}		System.out.println("Loading KeyStore " + file + "...");		InputStream in = new FileInputStream(file);		KeyStore ks = KeyStore.getInstance(KeyStore.getDefaultType());		ks.load(in, passphrase);		in.close();		SSLContext context = SSLContext.getInstance("TLS");		TrustManagerFactory tmf = 		        TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());		tmf.init(ks);		X509TrustManager defaultTrustManager = (X509TrustManager) tmf.getTrustManagers()[0];		SavingTrustManager tm = new SavingTrustManager(defaultTrustManager);		context.init(null, new TrustManager[]{			tm		}		, null);		SSLSocketFactory factory = context.getSocketFactory();		System.out.println("Opening connection to " + host + ":" + port + "...");		SSLSocket socket = (SSLSocket) factory.createSocket(host, port);		socket.setSoTimeout(10000);		try {			System.out.println("Starting SSL handshake...");			socket.startHandshake();			socket.close();			System.out.println();			System.out.println("No errors, certificate is already trusted");		}		catch (SSLException e) {			System.out.println();			e.printStackTrace(System.out);		}		X509Certificate[] chain = tm.chain;		if (chain == null) {			System.out.println("Could not obtain server certificate chain");			return;		}		BufferedReader reader = 		        new BufferedReader(new InputStreamReader(System.in));		System.out.println();		System.out.println("Server sent " + chain.length + " certificate(s):");		System.out.println();		MessageDigest sha1 = MessageDigest.getInstance("SHA1");		MessageDigest md5 = MessageDigest.getInstance("MD5");		for (int i = 0; i < chain.length; i++) {			X509Certificate cert = chain[i];			System.out.println 			          (" " + (i + 1) + " Subject " + cert.getSubjectDN());			System.out.println("  Issuer " + cert.getIssuerDN());			sha1.update(cert.getEncoded());			System.out.println("  sha1  " + toHexString(sha1.digest()));			md5.update(cert.getEncoded());			System.out.println("  md5   " + toHexString(md5.digest()));			System.out.println();		}		System.out.println("Enter certificate to add to trusted keystore or 'q' to quit: [1]");		String line = reader.readLine().trim();		int k;		try {			k = (line.length() == 0) ? 0 : Integer.parseint(line) - 1;		}		catch (NumberFormatException e) {			System.out.println("KeyStore not changed");			return;		}		X509Certificate cert = chain[k];		String alias = host + "-" + (k + 1);		ks.setCertificateEntry(alias, cert);		OutputStream out = new FileOutputStream("jssecacerts");		ks.store(out, passphrase);		out.close();		System.out.println();		System.out.println(cert);		System.out.println();		System.out.println 		        ("Added certificate to keystore 'jssecacerts' using alias '" 		            + alias + "'");	}	private static final char[] HEXDIGITS = "0123456789abcdef".toCharArray();	private static String toHexString(byte[] bytes) {		StringBuilder sb = new StringBuilder(bytes.length * 3);		for (int b : bytes) {			b &= 0xff;			sb.append(HEXDIGITS[b >> 4]);			sb.append(HEXDIGITS[b & 15]);			sb.append(' ');		}		return sb.toString();	}	private static class SavingTrustManager implements X509TrustManager {		private final X509TrustManager tm;		private X509Certificate[] chain;		SavingTrustManager(X509TrustManager tm) {			this.tm = tm;		}		public X509Certificate[] getAcceptedIssuers() {			throw new UnsupportedOperationException();		}		public void checkClientTrusted(X509Certificate[] chain, String authType) 		        throws CertificateException {			throw new UnsupportedOperationException();		}		public void checkServerTrusted(X509Certificate[] chain, String authType) 		        throws CertificateException {			this.chain = chain;			tm.checkServerTrusted(chain, authType);		}	}}

2、運行安裝證書程序生成證書

java InstallCert my.hoolai.com

例如:java InstalCert smtp.zhangsan.com:465 admin
如果不加參數password和host的端口號,上面的獲取證書程序中默認給的端口號是:443,密碼是:changeit

3、根據運行提示信息,輸入1,回車,在當前目錄下生成名為: jssecacerts 的證書

將證書放置到$JAVA_HOME/jre/lib/security目錄下, 切記該JDK的jre是工程所用的環境!?。?/p>

或者:

System.setProperty("javax.net.ssl.trustStore", "你的jssecacerts證書路徑");

可以更改密碼,在security目錄下運行命令

keytool -storepasswd -new xxxcom -keystore cacerts

就可以修改密碼,修改后使用命令

keytool -list -v -keystore cacerts

查看文件的信息,會提示需要密碼才能查看,如果輸入密碼與修改后的密碼匹配,說明修改成功了。

PS:至此這種方式可以成功使用ssl了,另外再補充一下,根據剛才生成的文件jssecacerts,可以生成cer文件,

命令如下

keytool -export -alias xxx.com-1 -keystore jssecacerts -rfc -file xxx.cer

如上,之前的工具類中默認命名別名是加上"-1"。使用InstallCert設置的密碼需要跟cacerts文件中的密碼一致,

如果修改過密碼,就需要修改InstallCert類中對應的密碼字符串,否則會有下面這個異常:

java.security.UnrecoverableKeyException: Password verification failed

二、忽略證書信任問題

源碼:http://mengyang.iteye.com/blog/575671

一定要注意需要在connection創建之前調用文章里所述的方法,像這個樣子:

trustAllHttpsCertificates();HostnameVerifier hv = new HostnameVerifier() {     public boolean verify(String urlHostName, SSLSession session) {       return true;     }   };HttpsURLConnection.setDefaultHostnameVerifier(hv);connection = (HttpURLConnection) url.openConnection();

好吧,兩種方法都試過有效。

總結

以上就是本文關于java開發https請求ssl不受信任問題解決方法的全部內容,希望對大家有所幫助。感興趣的朋友可以繼續參閱本站其他相關專題,如有不足之處,歡迎留言指出。感謝朋友們對本站的支持!


注:相關教程知識閱讀請移步到JAVA教程頻道。
發表評論 共有條評論
用戶名: 密碼:
驗證碼: 匿名發表
亚洲香蕉成人av网站在线观看_欧美精品成人91久久久久久久_久久久久久久久久久亚洲_热久久视久久精品18亚洲精品_国产精自产拍久久久久久_亚洲色图国产精品_91精品国产网站_中文字幕欧美日韩精品_国产精品久久久久久亚洲调教_国产精品久久一区_性夜试看影院91社区_97在线观看视频国产_68精品久久久久久欧美_欧美精品在线观看_国产精品一区二区久久精品_欧美老女人bb
亚洲国产精品999| 4438全国亚洲精品在线观看视频| 日韩欧美在线观看| 91社影院在线观看| 久久久久久久久国产精品| 国产精品视频专区| 黑人极品videos精品欧美裸| 久久久久久九九九| 国产日韩在线观看av| 欧洲亚洲免费在线| 日韩最新在线视频| 久久久免费高清电视剧观看| 日韩国产一区三区| 91精品国产综合久久香蕉的用户体验| 国产精品69av| 国产精品成人一区| 日韩av最新在线| 国产黑人绿帽在线第一区| 久久久电影免费观看完整版| 亚洲欧美国产精品| 日韩精品中文字幕在线观看| 永久免费看mv网站入口亚洲| 亚洲www在线观看| 亚洲国产精品久久91精品| 精品久久久久久久久久久久| 人体精品一二三区| 国产网站欧美日韩免费精品在线观看| 欧美乱大交xxxxx| 久久精品视频在线播放| 精品久久久久久久久久久| 欧美性xxxxx极品| 精品中文字幕在线观看| 亚洲淫片在线视频| 国产在线拍偷自揄拍精品| 欧美成人剧情片在线观看| 精品高清一区二区三区| 午夜精品蜜臀一区二区三区免费| 国产精品普通话| 国产a级全部精品| 成人免费高清完整版在线观看| 久久精品91久久香蕉加勒比| 亚洲精品久久久久国产| 国产一区二区三区欧美| 国产精品国产自产拍高清av水多| 丰满岳妇乱一区二区三区| 国产精品扒开腿做爽爽爽男男| 深夜福利91大全| 韩国19禁主播vip福利视频| 91亚洲精品一区二区| 国产亚洲a∨片在线观看| 国产成人自拍视频在线观看| 国产精品丝袜久久久久久不卡| 欧美电影免费播放| 欧美激情一区二区三区成人| 久久99精品视频一区97| 欧美黑人性猛交| 欧美日韩不卡合集视频| 亚洲a∨日韩av高清在线观看| 亚洲免费伊人电影在线观看av| 最近2019中文字幕mv免费看| 中文字幕亚洲综合久久| 亚洲国产精品yw在线观看| 精品久久久91| 亚洲国产成人精品久久久国产成人一区| 一区二区三区 在线观看视| 国产日韩欧美在线播放| 国产精品av电影| 国产女人18毛片水18精品| 亚洲欧美日韩另类| 精品久久久久久久久国产字幕| 日韩av一区在线| 精品中文视频在线| 日韩国产在线播放| 日韩小视频在线观看| 欧美精品一区三区| 国产香蕉精品视频一区二区三区| 国产精品福利在线观看| 欧美在线性爱视频| 国产91在线视频| 在线观看日韩www视频免费| 96精品视频在线| 国内伊人久久久久久网站视频| 色小说视频一区| 欧美精品亚州精品| 亚洲成人久久一区| 亚州欧美日韩中文视频| 亚洲福利影片在线| 久久中文字幕在线视频| 精品久久久久久中文字幕一区奶水| 精品久久久精品| 色综合五月天导航| 欧美极品少妇与黑人| 成人黄色在线免费| 国产精品日日摸夜夜添夜夜av| 青青草成人在线| 亚洲精品自拍第一页| www.日韩不卡电影av| 亚洲综合最新在线| 欧美一区二区三区艳史| 日韩精品视频在线| 欧美巨大黑人极品精男| 欧美精品少妇videofree| 亚洲最大福利视频网站| 91精品国产免费久久久久久| 亚洲裸体xxxx| 国产亚洲视频在线观看| 亚洲va欧美va在线观看| 黑人精品xxx一区| 午夜精品免费视频| 日韩欧美在线中文字幕| 一本色道久久88综合日韩精品| 欧美色道久久88综合亚洲精品| 一区二区三区动漫| 色www亚洲国产张柏芝| 欧美乱人伦中文字幕在线| 久久久噜噜噜久久| 日韩在线视频一区| 97香蕉久久超级碰碰高清版| 亚洲图片欧美午夜| 国产91露脸中文字幕在线| 亚洲丝袜一区在线| 欧美久久精品午夜青青大伊人| 亚洲二区中文字幕| 亚洲人成网站999久久久综合| 亚洲韩国青草视频| 91精品国产自产在线| 亚洲国产成人精品电影| 久久99久久久久久久噜噜| 亚洲黄色在线观看| 国产成人福利视频| 国产一区二区三区在线观看视频| 国产精品美女999| 国产精品www| 亚洲男女自偷自拍图片另类| 国产美女精品视频免费观看| 日本精品久久久久影院| 亚洲欧美中文日韩在线| 国产精品极品尤物在线观看| 69av在线播放| 久久激情五月丁香伊人| 欧美有码在线视频| 国语自产偷拍精品视频偷| 日韩精品在线电影| 国产精品爽爽ⅴa在线观看| 国产成人97精品免费看片| 久久久噜久噜久久综合| 亚洲福利在线观看| 亚洲国产成人久久综合一区| 日韩电影中文字幕在线| 亚洲精品99久久久久中文字幕| 欧美成人一二三| 国产性猛交xxxx免费看久久| 亚洲欧美日韩精品久久| 在线看欧美日韩| 日韩av在线最新| 欧美国产日韩免费| 日韩精品视频中文在线观看| 精品福利在线看| 日本成人精品在线| 国产日韩综合一区二区性色av| 美乳少妇欧美精品| 成人国产精品免费视频| 中文字幕亚洲欧美| 亚洲午夜av久久乱码|