package me.jessyan.mvparms.demo.app.utils;
import java.io.IOException;
import java.io.InputStream;
import java.security.KeyManagementException;
import java.security.KeyStore;
import java.security.KeyStoreException;
import java.security.NoSuchAlgorithmException;
import java.security.SecureRandom;
import java.security.UnrecoverableKeyException;
import java.security.cert.CertificateException;
import java.security.cert.CertificateFactory;
import java.security.cert.X509Certificate;
import javax.net.ssl.HostnameVerifier;
import javax.net.ssl.KeyManager;
import javax.net.ssl.KeyManagerFactory;
import javax.net.ssl.SSLContext;
import javax.net.ssl.SSLSession;
import javax.net.ssl.SSLSocketFactory;
import javax.net.ssl.TrustManager;
import javax.net.ssl.TrustManagerFactory;
import javax.net.ssl.X509TrustManager;
public class SSLContextFactory {
public static class SSLParams
{
public SSLSocketFactorysSLSocketFactory;
public X509TrustManagertrustManager;
}
public static SSLParamsgetSslSocketFactory(InputStream[] certificates, InputStream bksFile, String password)
{
SSLParams sslParams =new SSLParams();
try
{
TrustManager[] trustManagers =prepareTrustManager(certificates);
KeyManager[] keyManagers =prepareKeyManager(bksFile, password);
SSLContext sslContext = SSLContext.getInstance("TLS");
X509TrustManager trustManager =null;
if (trustManagers !=null)
{
trustManager =new MyTrustManager(chooseTrustManager(trustManagers));
}else
{
trustManager =new UnSafeTrustManager();
}
sslContext.init(keyManagers, new TrustManager[]{trustManager},null);
sslParams.sSLSocketFactory = sslContext.getSocketFactory();
sslParams.trustManager = trustManager;
return sslParams;
}catch (NoSuchAlgorithmException e)
{
throw new AssertionError(e);
}catch (KeyManagementException e)
{
throw new AssertionError(e);
}catch (KeyStoreException e)
{
throw new AssertionError(e);
}
}
private class UnSafeHostnameVerifierimplements HostnameVerifier
{
@Override
public boolean verify(String hostname, SSLSession session)
{
return true;
}
}
private static class UnSafeTrustManagerimplements X509TrustManager
{
@Override
public void checkClientTrusted(X509Certificate[] chain, String authType)
throws CertificateException
{
}
@Override
public void checkServerTrusted(X509Certificate[] chain, String authType)
throws CertificateException
{
}
@Override
public X509Certificate[]getAcceptedIssuers()
{
return new java.security.cert.X509Certificate[]{};
}
}
private static TrustManager[]prepareTrustManager(InputStream... certificates)
{
if (certificates ==null || certificates.length <=0)return null;
try
{
CertificateFactory certificateFactory = CertificateFactory.getInstance("X.509");
KeyStore keyStore = KeyStore.getInstance(KeyStore.getDefaultType());
keyStore.load(null);
int index =0;
for (InputStream certificate : certificates)
{
String certificateAlias = Integer.toString(index++);
keyStore.setCertificateEntry(certificateAlias, certificateFactory.generateCertificate(certificate));
try
{
if (certificate !=null)
certificate.close();
}catch (IOException e)
{
e.printStackTrace();
}
}
TrustManagerFactory trustManagerFactory =null;
trustManagerFactory = TrustManagerFactory.
getInstance(TrustManagerFactory.getDefaultAlgorithm());
trustManagerFactory.init(keyStore);
TrustManager[] trustManagers = trustManagerFactory.getTrustManagers();
return trustManagers;
}catch (NoSuchAlgorithmException e)
{
e.printStackTrace();
}catch (CertificateException e)
{
e.printStackTrace();
}catch (KeyStoreException e)
{
e.printStackTrace();
}catch (Exception e)
{
e.printStackTrace();
}
return null;
}
private static KeyManager[]prepareKeyManager(InputStream bksFile, String password)
{
try
{
if (bksFile ==null || password ==null)return null;
KeyStore clientKeyStore = KeyStore.getInstance("BKS");
clientKeyStore.load(bksFile, password.toCharArray());
KeyManagerFactory keyManagerFactory = KeyManagerFactory.getInstance(KeyManagerFactory.getDefaultAlgorithm());
keyManagerFactory.init(clientKeyStore, password.toCharArray());
return keyManagerFactory.getKeyManagers();
}catch (KeyStoreException e)
{
e.printStackTrace();
}catch (NoSuchAlgorithmException e)
{
e.printStackTrace();
}catch (UnrecoverableKeyException e)
{
e.printStackTrace();
}catch (CertificateException e)
{
e.printStackTrace();
}catch (IOException e)
{
e.printStackTrace();
}catch (Exception e)
{
e.printStackTrace();
}
return null;
}
private static X509TrustManagerchooseTrustManager(TrustManager[] trustManagers)
{
for (TrustManager trustManager : trustManagers)
{
if (trustManagerinstanceof X509TrustManager)
{
return (X509TrustManager) trustManager;
}
}
return null;
}
private static class MyTrustManagerimplements X509TrustManager
{
private X509TrustManagerdefaultTrustManager;
private X509TrustManagerlocalTrustManager;
public MyTrustManager(X509TrustManager localTrustManager)throws NoSuchAlgorithmException, KeyStoreException
{
TrustManagerFactory var4 = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());
var4.init((KeyStore)null);
defaultTrustManager =chooseTrustManager(var4.getTrustManagers());
this.localTrustManager = localTrustManager;
}
@Override
public void checkClientTrusted(X509Certificate[] chain, String authType)throws CertificateException
{
}
@Override
public void checkServerTrusted(X509Certificate[] chain, String authType)throws CertificateException
{
try
{
defaultTrustManager.checkServerTrusted(chain, authType);
}catch (CertificateException ce)
{
localTrustManager.checkServerTrusted(chain, authType);
}
}
@Override
public X509Certificate[]getAcceptedIssuers()
{
return new X509Certificate[0];
}
}
}
关于HTTPS 证书单项认证用SSLSocketFactory
©著作权归作者所有,转载或内容合作请联系作者
- 文/潘晓璐 我一进店门,熙熙楼的掌柜王于贵愁眉苦脸地迎上来,“玉大人,你说我怎么就摊上这事。” “怎么了?”我有些...
- 文/花漫 我一把揭开白布。 她就那样静静地躺着,像睡着了一般。 火红的嫁衣衬着肌肤如雪。 梳的纹丝不乱的头发上,一...
- 文/苍兰香墨 我猛地睁开眼,长吁一口气:“原来是场噩梦啊……” “哼!你这毒妇竟也来了?” 一声冷哼从身侧响起,我...
推荐阅读更多精彩内容
- HTTP Hyper Text Transfer Protocol 使用TCP端口默认为:80 超文本传输协议,是...
- 跳过fetch访问ssl限制 1 . iOS的解决办法: RCTNetwork.xcodeproj - RCTH...
- 单向认证流程: 客户端向服务端发送SSL协议版本号、加密算法种类、随机数等信息。 服务端给客户端返回SSL协议版本...