java 配置ssl访问https

本文介绍了如何在本地配置HTTPS证书,包括生成证书、放置于资源目录并配置YML,以及实现HTTP到HTTPS的重定向。同时,讲解了访问加密HTTPS支付网站时,如何下载并导入对方证书到JDK密钥库,确保安全访问。
摘要由CSDN通过智能技术生成

1、访问本机,配置证书:

默认密钥:
changeit

生成证书:

keytool -genkey -alias mytomcat -storetype PKCS12 -keyalg RSA -keysize 2048 -keystore D:/keystore.p12 -validity 3650 -keypass 123456 -dname "CN=Web Server,OU=Unit,O=Organization,L=City,S=State,C=US" -storepass 123456


证书放入resources路径下:

yml配置:

ssl:
  key-store: classpath:keystore.p12
  key-store-password: 123456
  key-password: 123456
  key-store-type: PKCS12
  key-alias: mytomcat
https:
  port: 443

如果想http和https都能访问,还得来个配置类:

package com.dkt.web.core.config;
/*
 *@ClassName t
 *@Description TODO
 *@Author wangchao
 *@Date 2022/4/6 17:13
 *@Version 1.0
 */

import org.apache.catalina.connector.Connector;
import org.apache.coyote.http11.Http11NioProtocol;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.boot.web.embedded.tomcat.TomcatConnectorCustomizer;
import org.springframework.boot.web.embedded.tomcat.TomcatServletWebServerFactory;
import org.springframework.boot.web.server.WebServerFactoryCustomizer;
import org.springframework.boot.web.servlet.server.ConfigurableServletWebServerFactory;
import org.springframework.stereotype.Component;


@Component
public class CustomContainer implements WebServerFactoryCustomizer<ConfigurableServletWebServerFactory> {
    @Value("${https.port}")
    private int httpsPort;
    @Value("${server.port}")
    private int serverPort;
    @Value("${server.ssl.key-store}")
    private String keystoreFile;
    @Value("${server.ssl.key-store-type}")
    private String keystoreType;
    @Value("${server.ssl.key-store-password}")
    private String keystorePass;

    @Override
    public void customize(ConfigurableServletWebServerFactory factory) {
        ((TomcatServletWebServerFactory)factory).addConnectorCustomizers(new TomcatConnectorCustomizer() {
            @Override
            public void customize(Connector httpsconnector) {
                httpsconnector.setPort(httpsPort);
                httpsconnector.setSecure(true);
                httpsconnector.setScheme("https");
                Http11NioProtocol protocol = (Http11NioProtocol) httpsconnector.getProtocolHandler();
                protocol.setMaxConnections(200);
                protocol.setMaxThreads(200);
                protocol.setSelectorTimeout(3000);
                protocol.setSessionTimeout(3000);
                protocol.setConnectionTimeout(3000);
                protocol.setSSLEnabled(true);
                protocol.setKeystoreFile(keystoreFile);
                protocol.setKeystorePass(keystorePass);
                protocol.setKeystoreType(keystoreType);
                //先构造一个http的tomcat服务再重定向到https

                Connector httpconnector = new Connector(TomcatServletWebServerFactory.DEFAULT_PROTOCOL);
                httpconnector.setPort(serverPort);
                httpconnector.setScheme("http");
                httpconnector.setSecure(false);
                httpconnector.setRedirectPort(httpsPort);
                ((TomcatServletWebServerFactory)factory).addAdditionalTomcatConnectors(httpconnector);
            }
        });


    }
}

这样OK;

2、如果是访问一个支付网站,对方是加密https的接口,这时候需要下载对方网站的证书,安装到jdk的路径里

2.1 访问该网站,url左边的锁-->连接是安全的-》证书有效-》详细信息-》复制到文件,比如1.cer

2.2keytool 命令导入到jdk密钥库;

keytool -import -alias ssodemo3 -file D:/2.cer -keystore "D:\Program Files\Java\jdk1.8.0_172\jre\lib\security\cacerts"  -storepass changeit -trustcacerts
 

如此,访问该单独的https网站就可以了。 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值