zoukankan      html  css  js  c++  java
  • Ignoring HTTPS certificates

    Our Development setups won't have valid or trusted certificates. When do you want test our webserver code over HTTPS, we need to handle these certificates with special code.

    The common approach is to import these HTTPS certificates into JDK cacerts or override the trust store:
    In Java:

    System.setProperty("javax.net.ssl.trustStore","clientTrustStore.key");
    System.setProperty("javax.net.ssl.trustStorePassword","qwerty");

    If you are working with many such systems or test setups in LAN or internet, it is time taking to import these certificates in our trust stores. So we can allow a setting in our code to ignore these certificates with below code snippets.

    HostnameVerifier hostNameVerifier = new HostnameVerifier()
    {
     
        public boolean verify(String s, SSLSession sslSession)
        {
            return true;
        }
    };
    HttpsURLConnection.setDefaultHostnameVerifier(hostNameVerifier);
     
    TrustManager[] trustAllCerts = new TrustManager[]{
            new X509TrustManager()
            {
                public java.security.cert.X509Certificate[] getAcceptedIssuers()
                {
                    return null;
                }
     
                public void checkClientTrusted(X509Certificate[] certs, String authType)
                {
                }
     
                public void checkServerTrusted(X509Certificate[] certs, String authType)
                {
                }
            }
    };
     
    // Install the all-trusting trust manager
    try {
        SSLContext sc = SSLContext.getInstance("SSL");
        sc.init(null, trustAllCerts, new java.security.SecureRandom());
        HttpsURLConnection.setDefaultSSLSocketFactory(sc.getSocketFactory());
        logger.fine("Socket factory initialized");
        System.out.println("Ignoring server certificates");
    } catch (Exception e) {
        logger.log(Level.SEVERE, "Failed initializing socket factory to ignore certificates.", e);
    }

    In Java using Apache Commons HTTP Util: 

     Protocol easyhttps = new Protocol("https", (ProtocolSocketFactory) new EasySSLProtocolSocketFactory(), 443);
            Protocol.registerProtocol("https", easyhttps);

    In PHP using PHP CURL: 

    //open connection
    $ch = curl_init();
    curl_setopt($ch,CURLOPT_URL,$url);
     
    // ignore certs
    curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
    curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 1);
  • 相关阅读:
    Eclipse 3.0.1插件方案(Java版) zt
    Vs2003使用时出现这个问题,正在郁闷中,网上找了好久,居然看到同样问题,马上拷贝来:)开心中
    Eclipse+Tomcat集成开发servletzt
    管理定律
    张小娴“禁果之味”
    上海主要特色医院一览表
    分布式网站数据库同步方案——sqlserver数据库同步复制,好文收藏之
    Eclipse 插件汇总(转载+不断更新) zt
    Eclipse零起步系列讲座 zt
    结婚这件事
  • 原文地址:https://www.cnblogs.com/fengjian/p/3534410.html
Copyright © 2011-2022 走看看