我一直在寻找这个问题的解决方案,但我似乎无法弄清楚
我正在尝试在Android应用和服务器之间的http连接上使用ssl, 我用自签名证书创建了一个密钥库
我有这段代码:
URL url;
SSLContext sslContext = null;
KeyStore keyStore = KeyStore.getInstance("BKS");
InputStream input = SportsApplication.getContext().getResources().openRawResource(R.raw.mykeystore);
keyStore.load(input, "mypass".toCharArray());
KeyManagerFactory kmf = KeyManagerFactory.getInstance("X509");
kmf.init(keyStore, "mypass".toCharArray());
KeyManager[] keyManagers = kmf.getKeyManagers();
sslContext = SSLContext.getInstance("TLS");
sslContext.init(keyManagers, null, null);
HttpsURLConnection connection = null;
String urlParameters = mJObject.toString();
try {
Log.w("client", mUrl);
Log.v("client", "request: "+urlParameters);
// Create connection
mUrl = mUrl.replaceFirst("http", "https");
url = new URL(mUrl);
connection = (HttpsURLConnection) url.openConnection();
try{
connection.setSSLSocketFactory(sslContext.getSocketFactory());
}
catch (Exception e1) {
e1.printStackTrace();
int tx =0;
}
try{
connection.setRequestMethod("POST");
connection.setRequestProperty("Content-type", "application/json");
connection.setRequestProperty("Accept", "application/json");
connection.setReadTimeout(dataTimeout);
connection.setConnectTimeout(com.inmobly.buckeyes.client.Constants.DEFAULT_CONN_TIMEOUT);
connection.setUseCaches(false);
connection.setDoInput(true);
connection.setDoOutput(true);
}
catch (Exception e1) {
e1.printStackTrace();
int tx =0;
}
// Send request
DataOutputStream wr = null;
try{
wr = new DataOutputStream(connection.getOutputStream());
}
catch (Exception e1) {
e1.printStackTrace();
int tx =0;
}
但我一直得到这个例外:
javax.net.ssl.SSLHandshakeException: javax.net.ssl.SSLProtocolException: SSL handshake aborted: ssl=0x1b1b0e0: Failure in SSL library, usually a protocol errorerror:140770FC:SSL routines:SSL23_GET_SERVER_HELLO:unknown protocol (external/openssl/ssl/s23_clnt.c:683 0x4029bcf5:0x00000000)
我做错了什么?
答案 0 :(得分:1)
因为SSL握手本身没有通过,而不是使用异常中的信息调试它,你可以在你的系统上安装wireshark(它也可以在模拟器上重现)并看一下数据包捕获os级别。如果错误是由于服务器和客户端上的ssl实现之间的协议版本不匹配,则数据包应具有必要的信息。您可以先尝试一个简单的ssl握手,以确保与服务器正确握手。让我们知道您获得的信息,我们将进一步调试!
答案 1 :(得分:0)