使用CocoaAsyncSocket和Java套接字的SSL / TLS

时间:2011-08-23 14:33:05

标签: ssl ssl-certificate asyncsocket cocoaasyncsocket

我想在cocoa中创建一个套接字服务器,使用AsyncSockets并与Java连接。如果Java是服务器并且cocoa是客户端,则启用SSL可以工作,但我需要相反的方式才能工作。我想我只是缺少cocoa中的一些设置,所以继承我的java代码: 我通过传递来启动客户端:

-Djavax.net.ssl.trustStore=${project_loc}/myKeystore 
-Djavax.net.ssl.trustStorePassword=myPass
-Djavax.net.debug=all

_

public class Client {
    public static void main(String[] arstring) {
        try {
            SSLSocketFactory sslsocketfactory = (SSLSocketFactory) SSLSocketFactory
                    .getDefault();
            SSLSocket sslsocket = (SSLSocket) sslsocketfactory.createSocket(
                    "localhost", 9999);

            InputStream inputstream = System.in;
            InputStreamReader inputstreamreader = new InputStreamReader(
                    inputstream);
            BufferedReader bufferedreader = new BufferedReader(
                    inputstreamreader);

            OutputStream outputstream = sslsocket.getOutputStream();
            OutputStreamWriter outputstreamwriter = new OutputStreamWriter(
                    outputstream);
            BufferedWriter bufferedwriter = new BufferedWriter(
                    outputstreamwriter);

            String string = null;
            while ((string = bufferedreader.readLine()) != null) {
                bufferedwriter.write(string + "\r\n");
                bufferedwriter.flush();
            }
        } catch (Exception exception) {
            exception.printStackTrace();
        }
    }
}

和我的可可代码:

- (void)socket:(GCDAsyncSocket *)socket didAcceptNewSocket:(GCDAsyncSocket *)newSocket
{
    NSLog(@"new conn");
    // read again for further messages with undefined timeout

    NSMutableDictionary *settings = [NSMutableDictionary dictionaryWithCapacity:3];


    [settings setObject:[NSNumber numberWithBool:NO]
                 forKey:(NSString *)kCFStreamSSLValidatesCertificateChain];

    [settings setObject:(NSString*)kCFStreamPropertySocketSecurityLevel
                 forKey:(NSString*)kCFStreamSocketSecurityLevelNegotiatedSSL];


    DDLogVerbose(@"Starting TLS with settings:\n%@", settings);

    [newSocket startTLS:settings];

    [newSocket readDataToData:[GCDAsyncSocket CRLFData] withTimeout:-1 tag:0];
}

一旦我从java客户端向cocoa服务器发送消息,我就会收到以下错误:

main, READ: TLSv1 Handshake, length = 117
main, handling exception: javax.net.ssl.SSLProtocolException: Illegal client handshake msg, 1
main, SEND TLSv1 ALERT:  fatal, description = unexpected_message
main, WRITE: TLSv1 Alert, length = 2
[Raw write]: length = 7
0000: 15 03 01 00 02 02 0A                               .......
main, called closeSocket()
javax.net.ssl.SSLProtocolException: Illegal client handshake msg, 1

是否有人提示如何正确使用它?

0 个答案:

没有答案