Get the App
SLTechnology News&Howtos  ›  Network Security  › 

The method of using server-side certificate (self-signed certificate) when connecting to https using httpClient

Shulou Source: shulou.com Published: 2022-06-01 02:50:01 10月02日 Update

Travel, winter warm standing outdoor socks, quick dry socks, thickened socks.

Poke Ledu station http://zhoupa1188.taobao.com to snap up men's and women's thickened outdoor socks, coolmax, cotton, warm, sweat absorption, quick drying, mountaineering, hiking socks. Free delivery of 10 or more

It is common to introduce a certificate on the client side when using httpClient to connect to https. There are three ways to introduce:

1. Import a certificate in jdk

2. Set the certificate path to the environment variable:

System.setProperty ("javax.net.ssl.trustStore", keyStore_path)

System.setProperty ("javax.net.ssl.trustStorePassword", keyStore_password)

3. Add the certificate path to the startup parameters when starting the java process.

Sometimes you don't need a certificate to visit a https website. Sometimes the use of client certificates may not be successful, throwing a variety of certificate-related errors. At this point, you can use a server-side certificate (self-signed certificate). The method is simple, as long as you log out of the default Socket Factory before the httpClient call and use the custom Socket Factory:

Org.apache.commons.httpclient.protocol.Protocol.unregisterProtocol ("https"); org.apache.commons.httpclient.protocol.Protocol.registerProtocol ("https", new Protocol ("https", (ProtocolSocketFactory) new org.apache.commons.httpclient.contrib.ssl.EasySSLProtocolSocketFactory (), 13087); org.apache.commons.httpclient.protocol.Protocol.unregisterProtocol ("https") Org.apache.commons.httpclient.protocol.Protocol.registerProtocol ("https", new Protocol ("https", (ProtocolSocketFactory) new org.apache.commons.httpclient.contrib.ssl.EasySSLProtocolSocketFactory (), 13087))

It depends on the not-yet-commons-ssl-0.3.9.jar package:

Org.apache.commons

Not-yet-commons-ssl

0.3.9

The exception I encountered was:

Org.apache.axis2.AxisFault: sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors

At org.apache.axis2.AxisFault.makeFault (AxisFault.java:430)

At org.apache.axis2.transport.http.SOAPMessageFormatter.writeTo (SOAPMessageFormatter.java:83)

...

Caused by: com.ctc.wstx.exc.WstxIOException: sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors

At com.ctc.wstx.sw.BaseStreamWriter.flush (BaseStreamWriter.java:313)

At org.apache.axiom.om.impl.MTOMXMLStreamWriter.flush (MTOMXMLStreamWriter.java:146)

...

Caused by: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors

At com.sun.net.ssl.internal.ssl.Alerts.getSSLException (Alerts.java:150)

...

Caused by: sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors

At sun.security.validator.PKIXValidator.doValidate (PKIXValidator.java:187)

...

Caused by: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors

At sun.security.provider.certpath.PKIXCertPathValidator.engineValidate (PKIXCertPathValidator.java:195)

At java.security.cert.CertPathValidator.validate (CertPathValidator.java:206)

At sun.security.validator.PKIXValidator.doValidate (PKIXValidator.java:182)

... 49 more

Tags: Certificates socks methods warmth customers clients paths services success cotton parameters variables just need various brands environments men and women websites processes errors Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Linux Shulou Information Shulou Tech Info vpn Shulou Technology