异常大致信息:
javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192)
at sun.security.ssl.SSLSocketImpl.fatal(SSLSocketImpl.java:1959)
主因:百度一下
哈哈
后面有再补上,太忙啦啦啦啦啦!
解决方式:OkHttpCliten在获取时使用工具类
具体工具方法:
public static OkHttpClient getUnsafeOkHttpClient() {
try
{
final TrustManager[] trustAllCerts = new TrustManager[]{
new X509TrustManager() {
@Override
public void checkClientTrusted(java.security.cert.X509Certificate[] chain, String authType) {
}
@Override
public void checkServerTrusted(java.security.cert.X509Certificate[] chain, String authType) {
}
@Override
public java.security.cert.X509Certificate[] getAcceptedIssuers() {
return new java.security.cert.X509Certificate[]{};
}
}
};
final SSLContext sslContext = SSLContext.getInstance("SSL");
sslContext.init(null, trustAllCerts, new java.security.SecureRandom());
final javax.net.ssl.SSLSocketFactory sslSocketFactory = sslContext.getSocketFactory();
OkHttpClient.Builder builder = new OkHttpClient.Builder();
builder.sslSocketFactory(sslSocketFactory);
builder.hostnameVerifier(new HostnameVerifier() {
@Override
public boolean verify(String hostname, SSLSession session) {
return true;
}
});
return builder.build();
} catch (Exception e)
{
throw new RuntimeException(e);
}
}
使用时:
private static final OkHttpClient cliten = HttpClientUtil.getUnsafeOkHttpClient();
依赖:
<!-- OKHTTP3 --> <dependency> <groupId>com.squareup.okhttp3</groupId> <artifactId>okhttp</artifactId> <version>3.14.0</version> </dependency>
完美!!!
这只是一次痛心的调试而已,使用springboot 的Restemplate 报:
javax.net.ssl.SSLPeerUnverifiedException: Certificate for <ip> doesn't match any of the subject alternative names
搞了一天,硬是没处理好,下班之际我更换OkHttp3 进行第三方访问。。。。。。。才顺利 下班,记录记录!
拜拜!