java 0dh_Java为什么SSL联合会产生“无法生成DH密钥对”异常?

当我与某些IRC服务器(而非其他IRC服务器)建立SSL连接时(大概是由于服务器的首选加密方法),出现以下异常:

Caused by: java.lang.RuntimeException: Could not generate DH keypair

at com.sun.net.ssl.internal.ssl.DHCrypt.(DHCrypt.java:106)

at com.sun.net.ssl.internal.ssl.ClientHandshaker.serverKeyExchange(ClientHandshaker.java:556)

at com.sun.net.ssl.internal.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:183)

at com.sun.net.ssl.internal.ssl.Handshaker.processLoop(Handshaker.java:593)

at com.sun.net.ssl.internal.ssl.Handshaker.process_record(Handshaker.java:529)

at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:893)

at com.sun.net.ssl.internal.ssl.SSLSocketImpl.performInitialHandshake(SSLSocketImpl.java:1138)

at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1165)

... 3 more

最终原因:

Caused by: java.security.InvalidAlgorithmParameterException: Prime size must be multiple of 64, and can only range from 512 to 1024 (inclusive)

at com.sun.crypto.provider.DHKeyPairGenerator.initialize(DashoA13*..)

at java.security.KeyPairGenerator$Delegate.initialize(KeyPairGenerator.java:627)

at com.sun.net.ssl.internal.ssl.DHCrypt.(DHCrypt.java:100)

... 10 more

演示此问题的服务器示例是perfection.esper.net:6697(这是一个IRC服务器)。未显示问题的服务器的示例是kornbluth.freenode.net:6697。[不足为奇的是,每个网络上的所有服务器都共享相同的行为。]

我的代码(如所述,在连接到某些SSL服务器时有效)是:

SSLContext sslContext = SSLContext.getInstance("SSL");

sslContext.init(null, trustAllCerts, new SecureRandom());

s = (SSLSocket)sslContext.getSocketFactory().createSocket();

s.connect(new InetSocketAddress(host, port), timeout);

s.setSoTimeout(0);

((SSLSocket)s).startHandshake();

是最后一个startHandshake引发异常。是的,’trustAllCerts’正在进行一些魔术。该代码会强制SSL系统不验证证书。(所以…这不是证书问题。)

显然,一种可能性是esper的服务器配置错误,但是我进行了搜索,但没有找到其他任何提及esper的SSL端口有问题的人,并且’openssl’连接到它(请参见下文)。所以我想知道这是否是Java默认SSL支持的限制或其他原因。有什么建议么?

~ $ openssl s_client -connect aperture.esper.net:6697

CONNECTED(00000003)

depth=0 /C=GB/ST=England/L=London/O=EsperNet/OU=aperture.esper.net/CN=*.esper.net/emailAddress=support@esper.net

verify error:num=18:self signed certificate

verify return:1

depth=0 /C=GB/ST=England/L=London/O=EsperNet/OU=aperture.esper.net/CN=*.esper.net/emailAddress=support@esper.net

verify return:1

---

Certificate chain

0 s:/C=GB/ST=England/L=London/O=EsperNet/OU=aperture.esper.net/CN=*.esper.net/emailAddress=support@esper.net

i:/C=GB/ST=England/L=London/O=EsperNet/OU=aperture.esper.net/CN=*.esper.net/emailAddress=support@esper.net

---

Server certificate

-----BEGIN CERTIFICATE-----

[There was a certificate here, but I deleted it to save space]

-----END CERTIFICATE-----

subject=/C=GB/ST=England/L=London/O=EsperNet/OU=aperture.esper.net/CN=*.esper.net/emailAddress=support@esper.net

issuer=/C=GB/ST=England/L=London/O=EsperNet/OU=aperture.esper.net/CN=*.esper.net/emailAddress=support@esper.net

---

No client certificate CA names sent

---

SSL handshake has read 2178 bytes and written 468 bytes

---

New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA

Server public key is 2048 bit

Secure Renegotiation IS supported

Compression: NONE

Expansion: NONE

SSL-Session:

Protocol : TLSv1

Cipher : DHE-RSA-AES256-SHA

Session-ID: 51F1D40A1B044700365D3BD1C61ABC745FB0C347A334E1410946DCB5EFE37AFD

Session-ID-ctx:

Master-Key: DF8194F6A60B073E049C87284856B5561476315145B55E35811028C4D97F77696F676DB019BB6E271E9965F289A99083

Key-Arg : None

Start Time: 1311801833

Timeout : 300 (sec)

Verify return code: 18 (self signed certificate)

---

如前所述,毕竟,它确实可以成功连接,这远远超过了我的Java应用程序所能说的。

如果相关,我正在使用OS X 10.6.8,Java版本1.6.0_26。

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值