1、我们先将.cer 和.jks文件导出然后发给服务端进行证书认证才好进行接下来的开发
1.1、至于如何导出:
命令1.keytool -genkeypair -dname "cn=clientAuth_PhevBattery, ou=IS, o=SGM, c=CN" -alias clientAuthCert -keypass Pass1234 -keystore d:\clientAuth_PhevBattery.jks -storepass Pass1234 -validity 3600 -keyalg RSA -keysize 2048 -sigalg SHA256WithRSA
命令2:keytool -export -file d:\clientAuth_PhevBattery.cer -keystore d:\clientAuth_PhevBattery.jks -storepass Pass1234 -alias clientAuthCert
PS:.cer是我们的证书保存了公钥,.jks保存的公钥和秘钥的算法 个人理解,如果错了希望大家可以提供改正,谢谢
2、开发过程中遇到两个问题
1.1、没搞明白JDK的security/cacerts库的是什么意思
经查询资料显示cacerts是一个秘钥库,我们在执行SSL认证的时候会使用到
1.2、客户没有将我们导出的.cer证书成功的加入到秘钥库进行受信任,所以在测试的过程中程序报错
javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: No trusted certificate found
import java.io.BufferedReader;
import java.io.File;
import java.io.FileInputStream;
import java.io.FileNotFoundException;
import java.io.IOException;
import java.io.InputStreamReader;
import java.io.OutputStream;
import java.io.PrintWriter;
import java.net.URL;
import java.security.KeyManagementException;
import java.security.KeyStore;
import java.security.KeyStoreException;
import java.security.NoSuchAlgorithmException;
import java.security.SecureRandom;
import java.security.UnrecoverableKeyException;
import java.security.cert.CertificateException;
import java.util.List;
import java.util.Map;
import javax.net.ssl.HostnameVerifier;
import javax.net.ssl.HttpsURLConnection;
import javax.net.ssl.KeyManager;
import javax.net.ssl.KeyManagerFactory;
import javax.net.ssl.SSLContext;
import javax.net.ssl.SSLSession;
import javax.net.ssl.TrustManager;
import javax.net.ssl.TrustManagerFactory;
public class ClientCertAuthSample {
// JKS文件
public static String KEY_STORE_FILE = "/Users/lkj/Desktop/clientAuth_PhevBattery.jks";
// JKS文件密码
public static String KEY_STORE_PASS = "Pass1234";
// jre安全库文件
// 一般默认位置 jdk1.8.0_161.jdk/jre/lib/security/cacerts
public static String TRUST_STORE_FILE = "/Users/lkj/Desktop/cacerts";
// 密匙库默认密码
public static String TRUST_STORE_PASS = "changeit";
final static String param
Java SSL HTTPS进行双重认证开发实践
最新推荐文章于 2025-06-19 04:21:41 发布