请求https错误: unable to find valid certification path to requested target

来源:互联网 发布:王士营养配餐软件 编辑:程序博客网 时间:2024/05/16 15:51

错误及原因

当Java客户端请求实现https协议的服务时,出现异常:’unable to find valid certification path to requested target’

是因为服务期端的证书没有被认证,需要做的是把服务端证书导入到Java keystore。

解决方法

使用下面的类安装证书

package com.shanhy.caogen;/* * Copyright 2006 Sun Microsystems, Inc.  All Rights Reserved. * * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions * are met: * *   - Redistributions of source code must retain the above copyright *     notice, this list of conditions and the following disclaimer. * *   - Redistributions in binary form must reproduce the above copyright *     notice, this list of conditions and the following disclaimer in the *     documentation and/or other materials provided with the distribution. * *   - Neither the name of Sun Microsystems nor the names of its *     contributors may be used to endorse or promote products derived *     from this software without specific prior written permission. * * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE COPYRIGHT OWNER OR * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. */import java.io.*;import java.net.URL;import java.security.*;import java.security.cert.*;import javax.net.ssl.*;/** * 安装证书 * * @author   单红宇(365384722) * @myblog  http://blog.csdn.net/catoop/ * @create    2016年4月14日 */public class InstallCert {    // 我们要访问的HTTPS服务,如访问 https://www.shanhy.com    public static final String hostName = "www.shanhy.com";    public static void main(String[] args) throws Exception {        args = new String[]{hostName};        String host;        int port;        char[] passphrase;        if ((args.length == 1) || (args.length == 2)) {            String[] c = args[0].split(":");            host = c[0];            port = (c.length == 1) ? 443 : Integer.parseInt(c[1]);            String p = (args.length == 1) ? "changeit" : args[1];            passphrase = p.toCharArray();        } else {            System.out.println("Usage: java InstallCert <host>[:port] [passphrase]");            return;        }        File file = new File("jssecacerts");        if (file.isFile() == false) {            char SEP = File.separatorChar;            File dir = new File(System.getProperty("java.home") + SEP + "lib" + SEP + "security");            file = new File(dir, "jssecacerts");            if (file.isFile() == false) {                file = new File(dir, "cacerts");            }        }        System.out.println("Loading KeyStore " + file + "...");        InputStream in = new FileInputStream(file);        KeyStore ks = KeyStore.getInstance(KeyStore.getDefaultType());        ks.load(in, passphrase);        in.close();        SSLContext context = SSLContext.getInstance("TLS");        TrustManagerFactory tmf = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());        tmf.init(ks);        X509TrustManager defaultTrustManager = (X509TrustManager) tmf.getTrustManagers()[0];        SavingTrustManager tm = new SavingTrustManager(defaultTrustManager);        context.init(null, new TrustManager[] { tm }, null);        SSLSocketFactory factory = context.getSocketFactory();        System.out.println("Opening connection to " + host + ":" + port + "...");        SSLSocket socket = (SSLSocket) factory.createSocket(host, port);        socket.setSoTimeout(10000);        try {            System.out.println("Starting SSL handshake...");            socket.startHandshake();            socket.close();            System.out.println();            System.out.println("No errors, certificate is already trusted");        } catch (SSLException e) {            System.out.println();            e.printStackTrace(System.out);        }        X509Certificate[] chain = tm.chain;        if (chain == null) {            System.out.println("Could not obtain server certificate chain");            return;        }        BufferedReader reader = new BufferedReader(new InputStreamReader(System.in));        System.out.println();        System.out.println("Server sent " + chain.length + " certificate(s):");        System.out.println();        MessageDigest sha1 = MessageDigest.getInstance("SHA1");        MessageDigest md5 = MessageDigest.getInstance("MD5");        for (int i = 0; i < chain.length; i++) {            X509Certificate cert = chain[i];            System.out.println(" " + (i + 1) + " Subject " + cert.getSubjectDN());            System.out.println("   Issuer  " + cert.getIssuerDN());            sha1.update(cert.getEncoded());            System.out.println("   sha1    " + toHexString(sha1.digest()));            md5.update(cert.getEncoded());            System.out.println("   md5     " + toHexString(md5.digest()));            System.out.println();        }        System.out.println("Enter certificate to add to trusted keystore or 'q' to quit: [1]");        String line = reader.readLine().trim();        int k;        try {            k = (line.length() == 0) ? 0 : Integer.parseInt(line) - 1;        } catch (NumberFormatException e) {            System.out.println("KeyStore not changed");            return;        }        X509Certificate cert = chain[k];        String alias = host + "-" + (k + 1);        ks.setCertificateEntry(alias, cert);        OutputStream out = new FileOutputStream("jssecacerts");        ks.store(out, passphrase);        out.close();        System.out.println();        System.out.println(cert);        System.out.println();        System.out.println("Added certificate to keystore 'jssecacerts' using alias '" + alias + "'");    }    private static final char[] HEXDIGITS = "0123456789abcdef".toCharArray();    private static String toHexString(byte[] bytes) {        StringBuilder sb = new StringBuilder(bytes.length * 3);        for (int b : bytes) {            b &= 0xff;            sb.append(HEXDIGITS[b >> 4]);            sb.append(HEXDIGITS[b & 15]);            sb.append(' ');        }        return sb.toString();    }    private static class SavingTrustManager implements X509TrustManager {        private final X509TrustManager tm;        private X509Certificate[] chain;        SavingTrustManager(X509TrustManager tm) {            this.tm = tm;        }        public X509Certificate[] getAcceptedIssuers() {            throw new UnsupportedOperationException();        }        public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException {            throw new UnsupportedOperationException();        }        public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException {            this.chain = chain;            tm.checkServerTrusted(chain, authType);        }    }}
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191

该类为包含main方法的入口类,直接运行即可。 
在出现提示后,输入1后回车完成(如果你要放弃并退出输入q即可)。

执行完毕后,在执行该类的当然目录中找到生成的 jssecacerts 文件,然后拷贝该文件到JDK中,如我的是放到:……\jdk1.8.0_60\jre\lib\security 中。

最后再使用之前的Java代码请求HTTPS接口,就不会出现错误了。

阅读全文
0 0