使用imaps协议连接到邮件服务,证书不符合算法

时间:2017-01-23 15:04:32

标签: java ssl-certificate javamail imap zimbra

我正在尝试使用imaps协议访问邮件服务(zimbra)的电子邮件。 我正在使用javaMail jar版本1.4.7

Properties props = (Properties)System.getProperties().clone();
// SSL setting
props.put("mail.imaps.ssl.checkserveridentity", "false");
props.put("mail.imaps.ssl.trust", "*");
MailSSLSocketFactory socketFactory = new MailSSLSocketFactory();
socketFactory.setTrustAllHosts(true);
props.put("mail.imaps.ssl.socketFactory", socketFactory);
Store store = Session.getDefaultInstance(props).getStore("imaps");
store.connect(host, email, password); /* exception here */

打印例外:

 javax.mail.MessagingException: java.security.cert.CertificateException: Certificates does not conform to algorithm constraints;
  nested exception is:
    javax.net.ssl.SSLHandshakeException: java.security.cert.CertificateException: Certificates does not conform to algorithm constraints
    at com.sun.mail.imap.IMAPStore.protocolConnect(IMAPStore.java:670)
    at javax.mail.Service.connect(Service.java:295)
    at javax.mail.Service.connect(Service.java:176)

首先,我从网页上获得了证书(.crt文件),如下图所示。其次,我使用keytool命令导入了证书

keytool  -importcert -file company.net.crt -keystore company.net -alias "company.net" -storepass changeit

picture 1 picture 2

我在这里想念的是什么?

1 个答案:

答案 0 :(得分:0)

将您的代码更改为:

props.put("mail.imaps.ssl.checkserveridentity", "false");
props.put("mail.imaps.ssl.trust", "*");
Store store = Session.getInstance(props).getStore("imaps");
store.connect(host, email, password); /* exception here */

请注意关键更改为use Session.getInstance

希望您还按照Notes for use of SSL with JavaMail

中的说明设置信任存储库属性

如果仍然无效,请发布JavaMail debug output。您可能还希望启用某些SSL调试属性,如上面的说明所述。

哦,JavaMail 1.4.7已经很老了。如果可能,您应该升级到最新版本JavaMail 1.5.6