參考文章:
http://www.ruanyifeng.com/blog/2014/02/ssl_tls.html
http://www.ruanyifeng.com/blog/2014/09/illustration-ssl.html
http://www.reibang.com/p/20d5fb4cd76d
雙向驗(yàn)證:
http://blog.csdn.net/codingfire/article/details/53419521
http://m.ithao123.cn/content-10472230.html
OpenSSL:
https://www.openssl.org/docs/man1.0.2/
http://shjia.blog.51cto.com/2476475/1427138
通篇看完覺得一張圖解釋Https很??肃叶。
注意:
- 證書和服務(wù)器需要滿足Requirements for Connecting Using ATS的條件牍帚。
- 保證1滿足。
NSURLConnection-兩種方式實(shí)現(xiàn) - 客戶端驗(yàn)證服務(wù)器
其他的如NSURLSession 調(diào)用方式和位置不同,原理一樣
- (void)connection:(NSURLConnection *)connection willSendRequestForAuthenticationChallenge:(NSURLAuthenticationChallenge *)challenge {
NSLog(@"authenticatemethod:%@",challenge.protectionSpace.authenticationMethod);
BOOL userJustCheckCertificateSame = NO;
{
if ([challenge.protectionSpace.authenticationMethod isEqualToString:NSURLAuthenticationMethodServerTrust]) {
NSMutableArray *certificates = [NSMutableArray array];
NSData*caCert =[NSData dataWithContentsOfFile:[[NSBundle mainBundle] pathForResource:@"new_cacert" ofType:@"cer"]];
NSData*serverCert =[NSData dataWithContentsOfFile:[[NSBundle mainBundle] pathForResource:@"new_server" ofType:@"cer"]];
if (userJustCheckCertificateSame) {
[certificates addObject:caCert];
[certificates addObject:serverCert];
[self serverTrustjustCheckCertificateSame:challenge pinCertificates:certificates];
}else{
SecCertificateRef caCertRef = SecCertificateCreateWithData(NULL, (__bridge CFDataRef)caCert);
SecCertificateRef serverCertRef = SecCertificateCreateWithData(NULL, (__bridge CFDataRef)serverCert);
[certificates addObject:(__bridge_transfer id)caCertRef];
[certificates addObject:(__bridge_transfer id)serverCertRef];
[self serverTrustSystemMethod:challenge pinCertificates:certificates];
}
}else if ([challenge.protectionSpace.authenticationMethod isEqualToString:NSURLAuthenticationMethodClientCertificate]) {
//暫時不做client 驗(yàn)證
[challenge.sender continueWithoutCredentialForAuthenticationChallenge:challenge];
// NSData*certData =[NSData dataWithContentsOfFile:[[NSBundle mainBundle] pathForResource:@"old_client" ofType:@"cer"]];
// [self addCertToKeychain:certData];
// NSURLCredential *credential = [self getClientCertFromKeychain];
// [[challenge sender] useCredential:credential forAuthenticationChallenge:challenge];
}else{
[challenge.sender continueWithoutCredentialForAuthenticationChallenge:challenge];
}
}
}
// 如果server 返回的證書鏈 里面有一個在local 證書集合里面恋脚,即可認(rèn)為合法
- (void)serverTrustjustCheckCertificateSame:(NSURLAuthenticationChallenge *)challenge pinCertificates:(NSMutableArray *)pinCertificates{
SecTrustRef serverTrust = challenge.protectionSpace.serverTrust;
if ([self localCaInServerChainList:serverTrust pinCertificates:pinCertificates]) {
NSURLCredential *cred = [NSURLCredential credentialForTrust:serverTrust];
[challenge.sender useCredential:cred forAuthenticationChallenge:challenge];
}else{
[challenge.sender cancelAuthenticationChallenge:challenge];
}
}
- (BOOL)localCaInServerChainList:(SecTrustRef)serverTrust pinCertificates:(NSMutableArray *)pinCertificates{
CFIndex certificateCount = SecTrustGetCertificateCount(serverTrust);
for (CFIndex i = 0; i < certificateCount; i++) {
SecCertificateRef certificate = SecTrustGetCertificateAtIndex(serverTrust, i);
NSData *trustChainCertificate = (__bridge_transfer NSData *)SecCertificateCopyData(certificate);
if ([pinCertificates containsObject:trustChainCertificate]) {
return YES;
}
}
return NO;
}
// 調(diào)用系統(tǒng)方法
- (void)serverTrustSystemMethod:(NSURLAuthenticationChallenge *)challenge pinCertificates:(NSMutableArray *)pinCertificates{
//1)獲取trust object
SecTrustRef trust = challenge.protectionSpace.serverTrust;
SecTrustResultType result;
NSMutableArray *policies = [NSMutableArray array];
// BasicX509 不驗(yàn)證域名是否相同(我們用的IP)
SecPolicyRef policy = SecPolicyCreateBasicX509();
[policies addObject:(__bridge_transfer id)policy];
SecTrustSetPolicies(trust, (__bridge CFArrayRef)policies);
//注意:添加自己的證書作為可信列表
SecTrustSetAnchorCertificates(trust, (__bridge CFArrayRef)pinCertificates);
//禁用系統(tǒng)可信列表
//SecTrustSetAnchorCertificatesOnly(trust, false);
//2)SecTrustEvaluate會查找前面SecTrustSetAnchorCertificates設(shè)置的證書或者系統(tǒng)默認(rèn)提供的證書,對trust進(jìn)行驗(yàn)證
OSStatus status = SecTrustEvaluate(trust, &result);
if (status == errSecSuccess &&
(result == kSecTrustResultProceed ||
result == kSecTrustResultUnspecified))
{
//3)驗(yàn)證成功,生成NSURLCredential憑證cred,告知challenge的sender使用這個憑證來繼續(xù)連接
NSURLCredential *cred = [NSURLCredential credentialForTrust:trust];
[challenge.sender useCredential:cred forAuthenticationChallenge:challenge];
} else {
//5)驗(yàn)證失敗婴噩,取消這次驗(yàn)證流程
[challenge.sender cancelAuthenticationChallenge:challenge];
}
}
NSURLConnection -服務(wù)器驗(yàn)證客戶端
所有參考鏈接:
http://www.cnblogs.com/qiyer/p/4871421.html
http://m.ithao123.cn/content-10472230.html
http://oncenote.com/2014/10/21/Security-1-HTTPS/
http://oncenote.com/2015/09/16/Security-2-HTTPS2/#verify_safely
http://www.cnblogs.com/interdrp/p/4881116.html
http://www.cnblogs.com/pixy/p/4722381.html
http://www.cnblogs.com/JeffreySun/archive/2010/06/24/1627247.html
http://www.reibang.com/p/2927ca2b3719
http://www.ruanyifeng.com/blog/2014/09/illustration-ssl.html
http://www.ruanyifeng.com/blog/2014/02/ssl_tls.html
https://zh.wikipedia.org/wiki/%E8%BF%AA%E8%8F%B2-%E8%B5%AB%E7%88%BE%E6%9B%BC%E5%AF%86%E9%91%B0%E4%BA%A4%E6%8F%9B
http://www.cnblogs.com/oc-bowen/p/5896041.html
http://www.cnblogs.com/jukan/p/5527922.html
http://www.cnblogs.com/guogangj/p/4118605.html
http://blog.csdn.net/linda1000/article/details/8676330
http://blog.sina.com.cn/s/blog_a9303fd90101jmtx.html
https://tools.ietf.org/html/rfc5246#section-7.3
https://developer.apple.com/library/prerelease/content/documentation/Security/Conceptual/CertKeyTrustProgGuide/revisionHistory.html#//apple_ref/doc/uid/TP40001358-CH206-TPXREF101
https://developer.apple.com/library/prerelease/content/technotes/tn2326/_index.html
https://developer.apple.com/library/content/documentation/General/Reference/InfoPlistKeyReference/Articles/CocoaKeys.html#//apple_ref/doc/uid/TP40009251-SW57
https://developer.apple.com/library/content/documentation/Security/Conceptual/CertKeyTrustProgGuide/revisionHistory/revisionHistory.html#//apple_ref/doc/uid/TP40001358-CH206-TPXREF101
https://developer.apple.com/library/content/technotes/tn2232/_index.html#//apple_ref/doc/uid/DTS40012884-CH1-SECBASICTRUSTCUSTOMIZATION
http://www.reibang.com/p/2542c95fb023
http://www.cnblogs.com/longshiyVip/p/5080917.html
http://www.reibang.com/p/e767a4e9252e
http://www.cnblogs.com/hyddd/archive/2009/01/07/1371292.html
https://developer.apple.com/library/content/qa/qa1727/_index.html
https://developer.apple.com/reference/security