Android https 自定义ssl证书使用

Android https自定义ssl证书使用

1,服务端配置单向认证,给出server.crt

2,通过命令生成bks文件

keytool -import -alias cert123 -file server.crt -keystore cert123.bks -storetype BKS -providerClass org.bouncycastle.jce.provider.BouncyCastleProvider -providerpath ./bcprov-jdk15on-146.jar -storepass cert160223

keytool使用java自带keytool工具

另外一个重要JCE Provider 必须使用http://www.bouncycastle.org/download/bcprov-jdk15on-146.jar ,而且必须此版本,其他版本会有问题

3,android 中代码配置

1import java.io.InputStream; 2import java.security.KeyStore; 3  4import android.content.Context; 5  6public class MyHttpClient extends DefaultHttpClient { 7    8 private static Context context; 9   10 public static void setContext(Context context) { 11  MyHttpClient.context = context; 12 } 13  14 public MyHttpClient(HttpParams params) { 15  super(params); 16 } 17  18 public MyHttpClient(ClientConnectionManager httpConnectionManager, HttpParams params) { 19  super(httpConnectionManager, params); 20 } 21  22 @Override 23    protected ClientConnectionManager createClientConnectionManager() { 24        SchemeRegistry registry = new SchemeRegistry(); 25        registry.register(new Scheme("http", PlainSocketFactory.getSocketFactory(), 80)); 26          27        // 用我们自己定义的 SSLSocketFactory 在 ConnectionManager 中注册一个 443 端口   28        registry.register(new Scheme("https", newSslSocketFactory(), 443)); 29        return new SingleClientConnManager(getParams(), registry); 30    } 31   32    private SSLSocketFactory newSslSocketFactory() { 33        try { 34            // Get an instance of the Bouncy Castle KeyStore format 35            KeyStore trusted = KeyStore.getInstance("BKS"); 36            // 从资源文件中读取你自己创建的那个包含证书的 keystore 文件 37              38            InputStream in = MyHttpClient.context.getResources().openRawResource(R.raw.codeprojectssl); //这个参数改成你的 keystore 文件名 39            try { 40                // 用 keystore 的密码跟证书初始化 trusted                             41                trusted.load(in, "这里是你的 keystore 密码".toCharArray()); 42            } finally { 43                in.close(); 44            } 45            // Pass the keystore to the SSLSocketFactory. The factory is responsible 46            // for the verification of the server certificate. 47            SSLSocketFactory sf = new SSLSocketFactory(trusted); 48            // Hostname verification from certificate 49            // http://hc.apache.org/httpcomponents-client-ga/tutorial/html/connmgmt.html#d4e506 50            sf.setHostnameVerifier(SSLSocketFactory.STRICT_HOSTNAME_VERIFIER); // 这个参数可以根据需要调整, 如果对主机名的验证不需要那么严谨, 可以将这个严谨程度调低些. 51            return sf; 52        } catch (Exception e) { 53            throw new AssertionError(e); 54        } 55    } 56}

此时应该就可以了,这是单向认证代码。

点赞
收藏

评论区

加载中...

相关推荐

MySQL:[Err] 1292 - Incorrect datetime value: ‘0000-00-00 00:00:00‘ for column ‘CREATE_TIME‘ at row 1

文章目录问题用navicat导入数据时,报错:原因这是因为当前的MySQL不支持datetime为0的情况。解决修改sql\mode:sql\mode:SQLMode定义了MySQL应支持的SQL语法、数据校验等,这样可以更容易地在不同的环境中使用MySQL。全局s

Oracle 分组与拼接字符串同时使用

SELECTT.,ROWNUMIDFROM(SELECTT.EMPLID,T.NAME,T.BU,T.REALDEPART,T.FORMATDATE,SUM(T.S0)S0,MAX(UPDATETIME)CREATETIME,LISTAGG(TOCHAR(

MySQL部分从库上面因为大量的临时表tmp_table造成慢查询

背景描述Time:20190124T00:08:14.70572408:00User@Host:@Id:Schema:sentrymetaLast_errno:0Killed:0Query_time:0.315758Lock_

皕杰报表之UUID

​在我们用皕杰报表工具设计填报报表时,如何在新增行里自动增加id呢?能新增整数排序id吗?目前可以在新增行里自动增加id,但只能用uuid函数增加UUID编码,不能新增整数排序id。uuid函数说明:获取一个UUID,可以在填报表中用来创建数据ID语法:uuid()或uuid(sep)参数说明:sep布尔值,生成的uuid中是否包含分隔符'',缺省为

手写Java HashMap源码

HashMap的使用教程HashMap的使用教程HashMap的使用教程HashMap的使用教程HashMap的使用教程22

2020年前端实用代码段,为你的工作保驾护航

有空的时候,自己总结了几个代码段,在开发中也经常使用,谢谢。1、使用解构获取json数据let jsonData  id: 1,status: "OK",data: 'a', 'b';let  id, status, data: number   jsonData;console.log(id, status, number )

Android https 自定义ssl证书使用 - HelloWorld