ohttp請(qǐng)求https的認(rèn)證

參考文章

Android Https相關(guān)完全解析 當(dāng)OkHttp遇到Https
Aandroid中https請(qǐng)求的單向認(rèn)證和雙向認(rèn)證
okhttp實(shí)現(xiàn)https請(qǐng)求

以上文章都有說(shuō)明單向認(rèn)證和雙向認(rèn)證的方法

最后參考了開(kāi)源項(xiàng)目
okhttputils

初始化okhttp時(shí)添加以下設(shè)置

addUnSafeSslSocketAndHostnameVerifier信任所有證書(shū)不做校驗(yàn)(大部分簡(jiǎn)單項(xiàng)目做法)
/**
 * 通過(guò)所有https的認(rèn)證。不做判斷灯荧,不安全
 * @param builder
 * @return
 */
private static Builder addUnSafeSslSocketAndHostnameVerifier(Builder builder) {
    //如果設(shè)置了sslSocketFactory卻沒(méi)有配置對(duì)應(yīng)的hostnameVerifier翘瓮,那么Https請(qǐng)求是無(wú)法成功的
    //不設(shè)置會(huì)報(bào):javax.net.ssl.SSLHandshakeException: java.security.cert.CertPathValidatorException: Trust anchor for certification path not found.
    HttpsSslFactroy.SSLParams sslParams = HttpsSslFactroy.getSslSocketFactory(); //獲取默認(rèn)的SSLParams,通過(guò)所有認(rèn)證
    addSSLSocketFactory(builder, sslParams.mSSLSocketFactory, sslParams.mTrustManager);

    //不設(shè)置請(qǐng)求https會(huì)報(bào)錯(cuò):javax.net.ssl.SSLPeerUnverifiedException: Hostname xxx地址的host not verified:
    //設(shè)置ip授權(quán)認(rèn)證:如果已經(jīng)安裝該證書(shū)磺樱,可以不設(shè)置,否則需要設(shè)置??????????????不設(shè)置會(huì)報(bào)錯(cuò)。台腥。投放。待處理
    HostnameVerifier hostnameVerifier = HttpsSslFactroy.getHostnameVerifierUnSafe();
    return addHostnameVerifier(builder, hostnameVerifier);
}

/**
 * 單向認(rèn)證
 * @param builder
 * @param context
 * @param certificates 服務(wù)器需要驗(yàn)證的證書(shū) 把證書(shū)放到raw目錄下
 * @return
 */
public static Builder addSSLSocketFactory(Builder builder, Context context, @RawRes int[] certificates) {
    HttpsSslFactroy.SSLParams sslParams = HttpsSslFactroy.getSslSocketFactory(context, certificates);
    return addSSLSocketFactory(builder, sslParams.mSSLSocketFactory, sslParams.mTrustManager);
}

/**
 * 雙向認(rèn)證
 * @param builder
 * @param context
 * @param certificates 服務(wù)器需要驗(yàn)證的證書(shū) 把證書(shū)放到raw目錄下
 * @param clientKeyStoreBksFile 本地驗(yàn)證證書(shū)奈泪。一般雙向驗(yàn)證才需要 把證書(shū)放到raw目錄下
 * @param password 本地驗(yàn)證證書(shū)的密碼
 * @return
 */
public static Builder addSSLSocketFactory(Builder builder, Context context, @RawRes int[] certificates, @RawRes int clientKeyStoreBksFile, String password) {
    HttpsSslFactroy.SSLParams sslParams = HttpsSslFactroy.getSslSocketFactory(context, certificates, clientKeyStoreBksFile, password);
    return addSSLSocketFactory(builder, sslParams.mSSLSocketFactory, sslParams.mTrustManager);
}

/**
 * 雙向認(rèn)證
 * @param builder
 * @param certificates 服務(wù)器需要驗(yàn)證的證書(shū) 把證書(shū)放到raw目錄下
 * @param bksFile 本地驗(yàn)證證書(shū)。一般雙向驗(yàn)證才需要 把證書(shū)放到raw目錄下
 * @param password 本地驗(yàn)證證書(shū)的密碼
 * @return
 */
public static Builder addSSLSocketFactory(Builder builder, InputStream[] certificates, InputStream bksFile, String password) {
    HttpsSslFactroy.SSLParams sslParams = HttpsSslFactroy.getSslSocketFactory(certificates, bksFile, password);
    return addSSLSocketFactory(builder, sslParams.mSSLSocketFactory, sslParams.mTrustManager);
}


public static Builder addSSLSocketFactory(Builder builder, SSLSocketFactory sslSocketFactory, X509TrustManager trustManager) {
    builder.sslSocketFactory(sslSocketFactory, trustManager);
    return builder;
}


//http://www.reibang.com/p/16994e49e2f6
//http://blog.csdn.net/sk719887916/article/details/51597816
/**
 * 指定支持的host
 * hostnameVerifier對(duì)服務(wù)端返回的一些信息進(jìn)行相關(guān)校驗(yàn)灸芳,用于客戶端判斷所連接的服務(wù)端是否可信涝桅,通常默認(rèn)return true,或者簡(jiǎn)單校驗(yàn)hostname是否正確,默認(rèn)不使用的話會(huì)調(diào)用okhttp的OkHostnameVerifier:
 http://www.reibang.com/p/1373889e74b2
 * @param builder
 * @param hosts 指定支持的host
 * @return
 */
public static Builder addHostnameVerifier(Builder builder, String[] hosts) {
    HostnameVerifier hostnameVerifier = HttpsSslFactroy.getHostnameVerifierSafe(hosts);
    return addHostnameVerifier(builder, hostnameVerifier);
}


public static Builder addHostnameVerifier(Builder builder, HostnameVerifier hostnameVerifier) {
    builder.hostnameVerifier(hostnameVerifier);
    return builder;
}

添加 HttpsSslFactroy .jva

 /**
     * 參考github項(xiàng)目okhttputils
     * https://github.com/hongyangAndroid/okhttputils
     * <p>
     * 服務(wù)器端需要驗(yàn)證的客戶端證書(shū)烙样,其實(shí)就是客戶端的keystore
     * 1冯遂、設(shè)置可訪問(wèn)所有的https網(wǎng)站
     * HttpsSslFactroy.SSLParams sslParams = HttpsSslFactroy.getSslSocketFactory(null, null, null);
     * <p>
     * 2、設(shè)置具體的證書(shū)
     * HttpsSslFactroy.SSLParams sslParams = HttpsSslFactroy.getSslSocketFactory(服務(wù)器證書(shū)的inputstream, null, null);
     * <p>
     * 3谒获、雙向認(rèn)證
     * HttpsSslFactroy.getSslSocketFactory(服務(wù)器證書(shū)的inputstream, 本地證書(shū)的inputstream,本地證書(shū)的密碼)
     * <p>
     * 使用
     * new OkHttpClient.Builder().sslSocketFactory(sslParams.mSSLSocketFactory, sslParams.mTrustManager)).build();
     */
    public class HttpsSslFactroy {
        public static class SSLParams {
            public SSLSocketFactory mSSLSocketFactory;
            public X509TrustManager mTrustManager;
        }
    
        /**
         * 默認(rèn)通過(guò)人所有證書(shū)
         * @return
         */
        public static SSLParams getSslSocketFactory() {
            return getSslSocketFactory(null, null, null);
        }
    
    
        /**
         * 單向認(rèn)證
         * @param context
         * @param certificates 服務(wù)器需要驗(yàn)證的證書(shū) 把證書(shū)放到raw目錄下
         * @return
         */
        public static SSLParams getSslSocketFactory(Context context, @RawRes int[] certificates) {
            InputStream[] certificatesInputStream = getInputStreamOfRaw(context, certificates);
            return getSslSocketFactory(certificatesInputStream, null, null);
        }
    
    
        /**
         * 雙向認(rèn)證
         * @param context
         * @param certificates 服務(wù)器需要驗(yàn)證的證書(shū) 把證書(shū)放到raw目錄下
         * @param clientKeyStoreBksFile 本地驗(yàn)證證書(shū)蛤肌。一般雙向驗(yàn)證才需要 把證書(shū)放到raw目錄下
         * @param password 本地驗(yàn)證證書(shū)的密碼
         * @return
         */
        public static SSLParams getSslSocketFactory(Context context, @RawRes int[] certificates, @RawRes int clientKeyStoreBksFile, String password) {
            InputStream[] certificatesInputStream = getInputStreamOfRaw(context, certificates);
            InputStream clientKeyStoreIs = context.getResources().openRawResource(clientKeyStoreBksFile);
            return getSslSocketFactory(certificatesInputStream, clientKeyStoreIs, password);
        }
    
    
        /**
         * @param certificates 服務(wù)器證書(shū)
         * @param bksFile      客戶端證書(shū)文件
         * @param password     客戶端證書(shū)密碼
         * @return
         */
        public static SSLParams getSslSocketFactory(InputStream[] certificates, InputStream bksFile, String password) {
            SSLParams sslParams = new SSLParams();
            try {
                //雙向認(rèn)證- 驗(yàn)證客戶端證書(shū)-通過(guò)本地證書(shū)和密碼本地認(rèn)證的keyManagers
                KeyManager[] keyManagers = prepareKeyManager(bksFile, password);
    
                //單向認(rèn)證-只驗(yàn)證服務(wù)器證書(shū)
                TrustManager[] trustManagers = prepareTrustManager(certificates);
    
                X509TrustManager trustManager;
                if (trustManagers != null) {
                    trustManager = new MyTrustManager(chooseTrustManager(trustManagers));
                } else {
                    trustManager = new UnSafeTrustManager(); //不校驗(yàn)、認(rèn)證所有證書(shū)
                }
    
    
                //初始化SSLContext實(shí)例
                SSLContext sslContext = SSLContext.getInstance("TLS");
                sslContext.init(keyManagers, new TrustManager[]{trustManager}, null);
    
                //設(shè)置對(duì)外使用的參數(shù)
                sslParams.mSSLSocketFactory = sslContext.getSocketFactory();
                sslParams.mTrustManager = trustManager;
    
                return sslParams;
            } catch (NoSuchAlgorithmException e) {
                throw new AssertionError(e);
            } catch (KeyManagementException e) {
                throw new AssertionError(e);
            } catch (KeyStoreException e) {
                throw new AssertionError(e);
            }
        }
    
    
        private static TrustManager[] prepareTrustManager(InputStream... certificates) {
            if (certificates == null || certificates.length <= 0) {
                return null;
            }
    
            try {
                CertificateFactory certificateFactory = CertificateFactory.getInstance("X.509");
    
                //使用默認(rèn)證書(shū)
                KeyStore keyStore = KeyStore.getInstance(KeyStore.getDefaultType());
    
                //去掉系統(tǒng)默認(rèn)證書(shū)
                keyStore.load(null);
    
                int index = 0;
    
                //遍歷證書(shū)
                for (InputStream certificate : certificates) {
                    String certificateAlias = Integer.toString(index++);
    
                    //設(shè)置自己的證書(shū)
                    keyStore.setCertificateEntry(certificateAlias, certificateFactory.generateCertificate(certificate));
                    try {
                        if (certificate != null) {
                            certificate.close();
                        }
                    } catch (IOException e) {
                    }
                }
    
                //通過(guò)信任管理器獲取一個(gè)默認(rèn)的算法
                String algorithm = TrustManagerFactory.getDefaultAlgorithm();
    
                //算法工廠創(chuàng)建
                TrustManagerFactory trustManagerFactory = TrustManagerFactory.getInstance(algorithm);
                trustManagerFactory.init(keyStore);
    
                TrustManager[] trustManagers = trustManagerFactory.getTrustManagers();
    
                return trustManagers;
            } catch (NoSuchAlgorithmException e) {
                e.printStackTrace();
            } catch (CertificateException e) {
                e.printStackTrace();
            } catch (KeyStoreException e) {
                e.printStackTrace();
            } catch (Exception e) {
                e.printStackTrace();
            }
            return null;
    
        }
    
        /**
         * Java平臺(tái)默認(rèn)識(shí)別jks格式的證書(shū)文件批狱,但是android平臺(tái)只識(shí)別bks格式的證書(shū)文件裸准。所以導(dǎo)入的流應(yīng)該是bks的文件
         *
         * @param bksFile
         * @param password
         * @return
         */
        private static KeyManager[] prepareKeyManager(InputStream bksFile, String password) {
            try {
                if (bksFile == null || password == null) return null;
    
                KeyStore clientKeyStore = KeyStore.getInstance("BKS");
                clientKeyStore.load(bksFile, password.toCharArray());
                KeyManagerFactory keyManagerFactory = KeyManagerFactory.getInstance(KeyManagerFactory.getDefaultAlgorithm());
                keyManagerFactory.init(clientKeyStore, password.toCharArray());
                return keyManagerFactory.getKeyManagers();
    
            } catch (KeyStoreException e) {
                e.printStackTrace();
            } catch (NoSuchAlgorithmException e) {
                e.printStackTrace();
            } catch (UnrecoverableKeyException e) {
                e.printStackTrace();
            } catch (CertificateException e) {
                e.printStackTrace();
            } catch (IOException e) {
                e.printStackTrace();
            } catch (Exception e) {
                e.printStackTrace();
            }
            return null;
        }
    
        private static X509TrustManager chooseTrustManager(TrustManager[] trustManagers) {
            for (TrustManager trustManager : trustManagers) {
                if (trustManager instanceof X509TrustManager) {
                    return (X509TrustManager) trustManager;
                }
            }
            return null;
        }
    
    
        private static class MyTrustManager implements X509TrustManager {
            private X509TrustManager defaultTrustManager;
            private X509TrustManager localTrustManager;
    
            public MyTrustManager(X509TrustManager localTrustManager) throws NoSuchAlgorithmException, KeyStoreException {
                TrustManagerFactory var4 = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());
                var4.init((KeyStore) null);
                defaultTrustManager = chooseTrustManager(var4.getTrustManagers());
                this.localTrustManager = localTrustManager;
            }
    
    
            @Override
            public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException {
    
            }
    
            @Override
            public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException {
                try {
                    defaultTrustManager.checkServerTrusted(chain, authType);
                } catch (CertificateException ce) {
                    localTrustManager.checkServerTrusted(chain, authType);
                }
            }
    
    
            @Override
            public X509Certificate[] getAcceptedIssuers() {
                return new X509Certificate[0];
            }
        }
    
        private static class UnSafeTrustManager implements X509TrustManager {
            @Override
            public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException {
            }
    
            @Override
            public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException {
            }
    
            @Override
            public X509Certificate[] getAcceptedIssuers() {
                return new java.security.cert.X509Certificate[]{};
            }
        }
    
    
        /**
         * https請(qǐng)求才會(huì)判斷獲取host校驗(yàn)HostnameVerifier
         * 信任所有host
         */
        public static HostnameVerifier getHostnameVerifierUnSafe() {
            HostnameVerifier hostnameVerifier = new HostnameVerifier() {
                /**
                 * @param hostname 請(qǐng)求地址的host
                 * @param session 包括了從服務(wù)端返回的證書(shū)鏈
                 */
                @Override
                public boolean verify(String hostname, SSLSession session) {
                    Log.i("lch", "證書(shū)校驗(yàn):" + hostname);
                    return true;
                }
            };
            return hostnameVerifier;
        }
    
    
        /**
         * 獲取host校驗(yàn)HostnameVerifier
         * 需要校驗(yàn)host
         * {@link HostnameVerifier}
         * 有證書(shū)認(rèn)證,貌似不用設(shè)置這個(gè)
         * hostnameVerifier則是對(duì)服務(wù)端返回的一些信息進(jìn)行相關(guān)校驗(yàn)的地方赔硫,用于客戶端判斷所連接的服務(wù)端是否可信炒俱,通常默認(rèn)return true,或者簡(jiǎn)單校驗(yàn)hostname是否正確,默認(rèn)不使用的話會(huì)調(diào)用okhttp的OkHostnameVerifier:
         */
        public static HostnameVerifier getHostnameVerifierSafe(final String[] hostUrls) {
            HostnameVerifier hostnameVerifier = new HostnameVerifier() {
                /**
                 * @param hostname 請(qǐng)求地址的host
                 * @param session 包括了從服務(wù)端返回的證書(shū)鏈
                 */
                @Override
                public boolean verify(String hostname, SSLSession session) {
                    boolean ret = false;
                    for (String host : hostUrls) {
                        if (host.equalsIgnoreCase(hostname)) {
                            ret = true;
                        }
                    }
                    return ret;
                }
            };
            return hostnameVerifier;
        }
    
    
        public static InputStream[] getInputStreamOfRaw(Context context, @RawRes int[] certificates) {
            InputStream[] certificatesInputStream = null;
            if (certificates != null && certificates.length > 0) {
                certificatesInputStream = new InputStream[]{};
                for (int i = 0; i < certificates.length; i++) {
                    certificatesInputStream[i] = context.getResources().openRawResource(certificates[i]);
                }
            }
            return certificatesInputStream;
        }
    
    
    }
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
  • 序言:七十年代末爪膊,一起剝皮案震驚了整個(gè)濱河市权悟,隨后出現(xiàn)的幾起案子,更是在濱河造成了極大的恐慌推盛,老刑警劉巖峦阁,帶你破解...
    沈念sama閱讀 216,843評(píng)論 6 502
  • 序言:濱河連續(xù)發(fā)生了三起死亡事件,死亡現(xiàn)場(chǎng)離奇詭異小槐,居然都是意外死亡拇派,警方通過(guò)查閱死者的電腦和手機(jī)荷辕,發(fā)現(xiàn)死者居然都...
    沈念sama閱讀 92,538評(píng)論 3 392
  • 文/潘曉璐 我一進(jìn)店門(mén),熙熙樓的掌柜王于貴愁眉苦臉地迎上來(lái)件豌,“玉大人疮方,你說(shuō)我怎么就攤上這事〖胪” “怎么了骡显?”我有些...
    開(kāi)封第一講書(shū)人閱讀 163,187評(píng)論 0 353
  • 文/不壞的土叔 我叫張陵,是天一觀的道長(zhǎng)曾掂。 經(jīng)常有香客問(wèn)我惫谤,道長(zhǎng),這世上最難降的妖魔是什么珠洗? 我笑而不...
    開(kāi)封第一講書(shū)人閱讀 58,264評(píng)論 1 292
  • 正文 為了忘掉前任溜歪,我火速辦了婚禮,結(jié)果婚禮上许蓖,老公的妹妹穿的比我還像新娘蝴猪。我一直安慰自己,他們只是感情好膊爪,可當(dāng)我...
    茶點(diǎn)故事閱讀 67,289評(píng)論 6 390
  • 文/花漫 我一把揭開(kāi)白布自阱。 她就那樣靜靜地躺著,像睡著了一般米酬。 火紅的嫁衣襯著肌膚如雪沛豌。 梳的紋絲不亂的頭發(fā)上,一...
    開(kāi)封第一講書(shū)人閱讀 51,231評(píng)論 1 299
  • 那天赃额,我揣著相機(jī)與錄音加派,去河邊找鬼。 笑死跳芳,一個(gè)胖子當(dāng)著我的面吹牛哼丈,可吹牛的內(nèi)容都是我干的。 我是一名探鬼主播筛严,決...
    沈念sama閱讀 40,116評(píng)論 3 418
  • 文/蒼蘭香墨 我猛地睜開(kāi)眼,長(zhǎng)吁一口氣:“原來(lái)是場(chǎng)噩夢(mèng)啊……” “哼饶米!你這毒婦竟也來(lái)了桨啃?” 一聲冷哼從身側(cè)響起,我...
    開(kāi)封第一講書(shū)人閱讀 38,945評(píng)論 0 275
  • 序言:老撾萬(wàn)榮一對(duì)情侶失蹤檬输,失蹤者是張志新(化名)和其女友劉穎照瘾,沒(méi)想到半個(gè)月后,有當(dāng)?shù)厝嗽跇?shù)林里發(fā)現(xiàn)了一具尸體丧慈,經(jīng)...
    沈念sama閱讀 45,367評(píng)論 1 313
  • 正文 獨(dú)居荒郊野嶺守林人離奇死亡析命,尸身上長(zhǎng)有42處帶血的膿包…… 初始之章·張勛 以下內(nèi)容為張勛視角 年9月15日...
    茶點(diǎn)故事閱讀 37,581評(píng)論 2 333
  • 正文 我和宋清朗相戀三年主卫,在試婚紗的時(shí)候發(fā)現(xiàn)自己被綠了。 大學(xué)時(shí)的朋友給我發(fā)了我未婚夫和他白月光在一起吃飯的照片鹃愤。...
    茶點(diǎn)故事閱讀 39,754評(píng)論 1 348
  • 序言:一個(gè)原本活蹦亂跳的男人離奇死亡簇搅,死狀恐怖,靈堂內(nèi)的尸體忽然破棺而出软吐,到底是詐尸還是另有隱情瘩将,我是刑警寧澤,帶...
    沈念sama閱讀 35,458評(píng)論 5 344
  • 正文 年R本政府宣布凹耙,位于F島的核電站姿现,受9級(jí)特大地震影響,放射性物質(zhì)發(fā)生泄漏肖抱。R本人自食惡果不足惜备典,卻給世界環(huán)境...
    茶點(diǎn)故事閱讀 41,068評(píng)論 3 327
  • 文/蒙蒙 一、第九天 我趴在偏房一處隱蔽的房頂上張望意述。 院中可真熱鬧提佣,春花似錦、人聲如沸欲险。這莊子的主人今日做“春日...
    開(kāi)封第一講書(shū)人閱讀 31,692評(píng)論 0 22
  • 文/蒼蘭香墨 我抬頭看了看天上的太陽(yáng)天试。三九已至槐壳,卻和暖如春,著一層夾襖步出監(jiān)牢的瞬間喜每,已是汗流浹背务唐。 一陣腳步聲響...
    開(kāi)封第一講書(shū)人閱讀 32,842評(píng)論 1 269
  • 我被黑心中介騙來(lái)泰國(guó)打工, 沒(méi)想到剛下飛機(jī)就差點(diǎn)兒被人妖公主榨干…… 1. 我叫王不留带兜,地道東北人枫笛。 一個(gè)月前我還...
    沈念sama閱讀 47,797評(píng)論 2 369
  • 正文 我出身青樓,卻偏偏與公主長(zhǎng)得像刚照,于是被迫代替她去往敵國(guó)和親刑巧。 傳聞我的和親對(duì)象是個(gè)殘疾皇子,可洞房花燭夜當(dāng)晚...
    茶點(diǎn)故事閱讀 44,654評(píng)論 2 354

推薦閱讀更多精彩內(nèi)容