我需要通过Android手机上的SSLSocket(不是http / https)连接服务器。我首先使用私有/公共对生成jks密钥库,然后生成仅具有客户端公钥的jks。 然后我首先尝试将SSLSocketFactory从java设置为java,然后让它工作。 Android没有接受我的jks密钥库,所以我将其转换为Android端的bks。 但是,当我测试它时,服务器端会抛出一个
javax.net.ssl.SSLHandshakeException: Received fatal alert: certificate_unknown
android方面抛出一个
java.security.cert.CertPathValidatorException: Trust anchor for certification path not found.
以下是测试服务器的代码:
System.setProperty("javax.net.ssl.keyStore","edkey.jks");
System.setProperty("javax.net.ssl.keyStorePassword","password");
ServerSocketFactory ssocketFactory = SSLServerSocketFactory.getDefault();
ServerSocket ssocket = ssocketFactory.createServerSocket(port);
System.out.println(ansiPurple("Starting"));
socket = ssocket.accept();
InputStream in = socket.getInputStream();
OutputStream out = socket.getOutputStream();
....
以下是工作java客户端的代码:
System.setProperty("javax.net.ssl.trustStore","edkey_public.jks");
System.setProperty("javax.net.ssl.trustStorePassword","password");
SSLSocketFactory f = (SSLSocketFactory)SSLSocketFactory.getDefault();
socket = (SSLSocket)f.createSocket(host, port);
InputStream in = socket.getInputStream();
OutputStream out = socket.getOutputStream();
....
以下是非工作Android应用程序的代码:
InputStream ki = a.getResources().openRawResource(a.getResources().getIdentifier("raw/edkey_public", "raw", a.getPackageName()));
KeyManagerFactory kmfactory = KeyManagerFactory.getInstance(KeyManagerFactory.getDefaultAlgorithm());
KeyStore ks = KeyStore.getInstance("BKS");
ks.load(ki,"password".toCharArray());
kmfactory.init(ks, "password".toCharArray());
ki.close();
KeyManager[] keymanagers = kmfactory.getKeyManagers();
TrustManagerFactory tmf=TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());
tmf.init(ks);
TrustManager[] tms = tmf.getTrustManagers();
SSLContext sslContext=SSLContext.getInstance("TLSv1.2");
sslContext.init(keymanagers, tms, new SecureRandom());
SSLSocketFactory f=sslContext.getSocketFactory();
Socket socket = (SSLSocket)f.createSocket(host, port);
InputStream in = socket.getInputStream();
OutputStream out = socket.getOutputStream();
....
有人知道问题所在吗?
答案 0 :(得分:-1)
也许是因为在Android应用中你说
KeyStore ks = KeyStore.getInstance("BKS");
应该是
KeyStore ks = KeyStore.getInstance("JKS");