我正在编写一个Java JSP代码,它使用openid对WSO2 IS服务器进行验证。我从de developer获取了示例代码,因此我得到以下内容:
<%
ConsumerManager manager = new ConsumerManager ();
String _returnURL = "https://192.168.15.48:9443/ficlient/secret.jsp";
List discoveries = manager.discover("https://myserverIP/openid");
DiscoveryInformation discovered = manager.associate(discoveries);
session.setAttribute("discovered", discovered);
AuthRequest authReq = manager.authenticate(discovered, _returnURL);
nextlink = authReq.getDestinationUrl(true);
%>
<a href="<%out.println(nextlink);%>">Secret data</a>
在第3行(列出发现......)我得到一个例外:
org.openid4java.discovery.yadis.YadisException: 0x704: I/O transport error: peer not authenticated
据我所知,这是因为为https通讯发出的无效ssl证书,并尝试包含以下内容(如Internet上所示),以避免验证:
<%
// Create a trust manager that does not validate certificate chains
TrustManager[] trustAllCerts = new TrustManager[]{
new X509TrustManager() {
public java.security.cert.X509Certificate[] getAcceptedIssuers() {
return null;
}
public void checkClientTrusted( java.security.cert.X509Certificate[] certs, String authType) {}
public void checkServerTrusted( java.security.cert.X509Certificate[] certs, String authType) {}
}
};
HostnameVerifier allHostsValid = new HostnameVerifier() {
public boolean verify(String hostname, SSLSession session) {
return true;
}
};
try {
SSLContext sc = SSLContext.getInstance("SSL");
sc.init(null, trustAllCerts, new java.security.SecureRandom());
HttpsURLConnection.setDefaultSSLSocketFactory(sc.getSocketFactory());
HttpsURLConnection.setDefaultHostnameVerifier(allHostsValid);
} catch (Exception e) {}
%>
但它仍然无效。我错过了什么?
答案 0 :(得分:0)
我终于通过使用Oltu库进行身份验证来解决它。