https的认证

public class MainActivity extends AppCompatActivity {


    @Override

    protected void onCreate(Bundle savedInstanceState) {

        super.onCreate(savedInstanceState);

        setContentView(R.layout.activity_main);

//        loadData();

        cardData();

    }


    /**

     * 带证书验证

     */

    private void cardData() {

        FormBody formbody = new FormBody.Builder().add("mobile", "18612991023").add("password", "111111").build();

        Request request = new Request.Builder().url("https://120.27.23.105/user/login").post(formbody).build();


        setCard().newCall(request).enqueue(new Callback() {

            @Override

            public void onFailure(Call call, IOException e) {


            }


            @Override

            public void onResponse(Call call, Response response) throws IOException {


            }

        });

    }


    /**

     * 信任所有https的请求:第一种实现

     */

    private void loadData() {

        OkHttpClient httpClient =

                new OkHttpClient.Builder()

                        .addInterceptor(new LogInterceptor())

                        .sslSocketFactory(createSSLSocketFactory())

                        .hostnameVerifier(new TrustAllHostnameVerifier())

                        .connectTimeout(10, TimeUnit.SECONDS)

                        .readTimeout(10, TimeUnit.SECONDS)

                        .writeTimeout(10, TimeUnit.SECONDS)

                        .retryOnConnectionFailure(false)

                        .build();

        FormBody formbody = new FormBody.Builder().add("mobile", "18612991023").add("password", "111111").build();

        Request request = new Request.Builder().url("https://120.27.23.105/user/login").post(formbody).build();


        httpClient.newCall(request).enqueue(new Callback() {

            @Override

            public void onFailure(Call call, IOException e) {


            }


            @Override

            public void onResponse(Call call, Response response) throws IOException {


            }

        });


    }


    private static class TrustAllCerts implements X509TrustManager {

        @Override

        public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException {

        }


        @Override

        public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException {

        }


        @Override

        public X509Certificate[] getAcceptedIssuers() {

            return new X509Certificate[0];

        }

    }


    private static class TrustAllHostnameVerifier implements HostnameVerifier {

        @Override

        public boolean verify(String hostname, SSLSession session) {

            return true;

        }

    }


    private static SSLSocketFactory createSSLSocketFactory() {

        SSLSocketFactory ssfFactory = null;


        try {

            SSLContext sc = SSLContext.getInstance("TLS");

            sc.init(null, new TrustManager[]{new TrustAllCerts()}, new SecureRandom());


            ssfFactory = sc.getSocketFactory();

        } catch (Exception e) {

        }


        return ssfFactory;

    }


    /**

     * app带证书验证

     * @return

     */

    public OkHttpClient setCard() {

        OkHttpClient.Builder builder = new OkHttpClient.Builder();

        try {

            CertificateFactory certificateFactory = CertificateFactory.getInstance("X.509");

            KeyStore keyStore = KeyStore.getInstance(KeyStore.getDefaultType());

            keyStore.load(null);

            String certificateAlias = Integer.toString(0);

            keyStore.setCertificateEntry(certificateAlias, certificateFactory.generateCertificate(getAssets().open("kson_server.cer")));//拷贝好的证书

            SSLContext sslContext = SSLContext.getInstance("TLS");

            final TrustManagerFactory trustManagerFactory =

              TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());

            trustManagerFactory.init(keyStore);

            sslContext.init

                    (

                            null,

                            trustManagerFactory.getTrustManagers(),

                            new SecureRandom()

                    );

            builder.sslSocketFactory(sslContext.getSocketFactory());

            builder.addInterceptor(new LogInterceptor());

            builder.hostnameVerifier(new HostnameVerifier() {

                @Override

                public boolean verify(String s, SSLSession sslSession) {

                    return true;

                }

            });

        } catch (Exception e) {

            e.printStackTrace();

        }

        return builder.build();

    }


}

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
在使用 `HttpURLConnection` 进行单向HTTPS认证时,可以通过以下步骤实现: 1. 创建一个信任管理器: ```java TrustManager[] trustAllCerts = new TrustManager[] { new X509TrustManager() { @Override public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException { // 不验证客户端证书 } @Override public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException { // 验证服务器证书 try { chain[0].checkValidity(); } catch (Exception e) { throw new CertificateException("证书无效"); } } @Override public X509Certificate[] getAcceptedIssuers() { return new X509Certificate[0]; } } }; ``` 2. 创建一个SSL上下文: ```java SSLContext sslContext = SSLContext.getInstance("TLS"); sslContext.init(null, trustAllCerts, new SecureRandom()); ``` 3. 设置`HttpURLConnection`的SSL Socket Factory: ```java HttpsURLConnection.setDefaultSSLSocketFactory(sslContext.getSocketFactory()); ``` 4. 发起HTTPS请求: ```java URL url = new URL("https://example.com"); HttpURLConnection connection = (HttpURLConnection) url.openConnection(); // 可选:设置其他请求参数 connection.setRequestMethod("GET"); connection.setConnectTimeout(5000); connection.setReadTimeout(5000); // 发起请求 int responseCode = connection.getResponseCode(); // 处理响应 if (responseCode == HttpURLConnection.HTTP_OK) { // 读取响应数据 InputStream inputStream = connection.getInputStream(); // ... } else { // 处理错误情况 } ``` 以上代码将忽略对客户端证书的验证,只验证服务器证书的有效性。同样需要注意,在生产环境中建议使用双向HTTPS认证来增强安全性,即同时验证客户端和服务器证书。

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值