【问题标题】:How to force to use TLS 1.1 only in android app如何仅在 android 应用程序中强制使用 TLS 1.1
【发布时间】:2019-11-01 18:17:49
【问题描述】:

这是我的简单应用代码:

MainActivity.java:

import android.support.v7.app.AppCompatActivity;
import android.os.Bundle;
import android.widget.ImageView;
import android.widget.TextView;
import com.bumptech.glide.Glide;
import com.bumptech.glide.load.resource.drawable.GlideDrawable;
import com.bumptech.glide.request.RequestListener;
import okhttp3.MediaType;

public class MainActivity extends AppCompatActivity {

    TextView error_txt;
    ImageView avatar;

    @Override
    protected void onCreate(Bundle savedInstanceState) {
        super.onCreate(savedInstanceState);
        setContentView(R.layout.activity_main);

        avatar = (ImageView) findViewById(R.id.avatar);
        error_txt =  (TextView) findViewById(R.id.error_log);    


        Glide.with(this).load("https://media.didestan.com/v1/image/w256h144/5bfbada9d833cs6ruNVbEtu78AOIycqb2.jpg")
            .listener(new RequestListener<String, GlideDrawable>() {
                @Override
                public boolean onException(Exception e, String model, com.bumptech.glide.request.target.Target<GlideDrawable> target, boolean isFirstResource) {
                    error_txt.setText(e.getMessage());
                    return false;
                }

                @Override
                public boolean onResourceReady(GlideDrawable resource, String model, com.bumptech.glide.request.target.Target<GlideDrawable> target, boolean isFromMemoryCache, boolean isFirstResource) {
                    return false;
                }

            }).into(avatar);

    }
}

activity_main.xml:

<?xml version="1.0" encoding="utf-8"?>
<RelativeLayout xmlns:android="http://schemas.android.com/apk/res/android"
xmlns:tools="http://schemas.android.com/tools"
android:id="@+id/activity_main"
android:layout_width="match_parent"
android:layout_height="match_parent"
android:paddingBottom="@dimen/activity_vertical_margin"
android:paddingLeft="@dimen/activity_horizontal_margin"
android:paddingRight="@dimen/activity_horizontal_margin"
android:paddingTop="@dimen/activity_vertical_margin"
tools:context="com.journaldev.okhttp.MainActivity">


<ImageView
    android:id="@+id/avatar"
    android:layout_width="368dp"
    android:layout_height="225dp"
    android:layout_alignParentStart="true"
    android:layout_alignParentLeft="true"
    android:layout_alignParentTop="true"
    android:layout_alignParentEnd="true"
    android:layout_alignParentRight="true"
    android:layout_marginStart="0dp"
    android:layout_marginLeft="0dp"
    android:layout_marginEnd="0dp"
    android:layout_marginRight="0dp"
    android:background="@drawable/ic_launcher_background" />

<TextView
    android:id="@+id/error_log"
    android:layout_width="368dp"
    android:layout_height="120dp"
    android:layout_alignParentBottom="true"
    android:layout_marginTop="181dp"
    android:layout_marginBottom="10dp"
    android:text="TextView" />
</RelativeLayout>

它在 android 版本 >5 中工作正常,但在 android 版本 4.1 - 4.4 中我有一个错误并且图像未加载:

java.security.cert.CertPathValidatorException: Trust anchor for certification path not found

1- 我该如何解决这个错误?

2- 我认为如果我将 tls 更改为 1.1,它将正常工作。现在我该如何强制它使用 tls 1.1(重要)?

这是下沉或游泳的问题:),请帮助我

编辑:

compileSdkVersion 28      
minSdkVersion 16 // It is important to be 16. I want to support android 4
targetSdkVersion 28

【问题讨论】:

  • 你能提供你得到CertPathValidatorException的链接吗?
  • 同时分享您的最低 Android SDK 版本。
  • @Abbas 该链接存在于代码中。它是一个从服务器读取它的源代码的 imageView
  • 所以?您仍然可以共享该链接,除非它是专有的。
  • 您调用的链接已损坏证书链,请在digicert.com 中添加media.didestan.com。您可以看到中间证书链已损坏。如果服务器是你的,你应该专注于更正证书链。

标签: android ssl


【解决方案1】:

可能是重复的问题,您将不得不克服它。 检查这篇文章。

How to enable TLS 1.2 support in an Android application (running on Android 4.1 JB)

【讨论】:

  • 这将为所有请求启用 TLSV1.1。
【解决方案2】:

如果您可以控制服务器

OP 提供的图片链接有一个损坏的证书链,应该专注于修复它。


如果您无法控制服务器

如果您正在为 Android 5 编写代码,您可以执行以下操作以强制使用 TLSV1.1 进行连接。我假设您使用的是 GlideV4.0.0.0 或更高版本,在您的AppGlideModule.java:

@GlideModule
private class CustomGlideModule extends AppGlideModule {

    @Override
    public void registerComponents(Context context, Glide glide, Registry registry) {
    ConnectionSpec spec = new ConnectionSpec.Builder(ConnectionSpec.MODERN_TLS)
        .tlsVersions(TlsVersion.TLS_1_1)
        .cipherSuites(
              CipherSuite.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
              CipherSuite.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
              CipherSuite.TLS_DHE_RSA_WITH_AES_128_GCM_SHA256)
        .build();

    OkHttpClient client = new OkHttpClient.Builder()
        .connectionSpecs(Collections.singletonList(spec))
        .build();

    OkHttpUrlLoader.Factory factory = new OkHttpUrlLoader.Factory(client);

    glide.getRegistry().replace(GlideUrl.class, InputStream.class, factory);
}

注意:我没有在任何设备上测试过上面的代码,它可能无法正常工作。

这将为 Glide 发出的所有请求启用 TLS V1.1,但可能仅适用于 Android 5+,我还没有为 Kitkat 测试过。

如果您仍然坚持使用 Kitkat,您可以创建一个 CustomSocketFactory(按照 @Alfeardo 的链接)启用 TLSV1.1 并在您的 Application 或 Activity 中设置套接字工厂

SSLContext sslcontext = SSLContext.getInstance("TLSv1.1");
sslcontext.init(null, null, null);
SSLSocketFactory customSocketFactory = new SecureTLSSocketFactory(sslcontext.getSocketFactory());

HttpsURLConnection.setDefaultSSLSocketFactory(customSocketFactory);

但是,这将为您的应用程序发出的所有请求启用 TLSV1.1,您将失去使用最新 TLS 版本的任何优势。

注意:

您可能还想看看Glide Docs: Certificate Pinning and Customizing Trusted Certificates。我从未使用过它,几乎不知道它们是如何工作的。

【讨论】:

  • 实现 'com.github.bumptech.glide:glide:3.8.0' annotationProcessor 'com.github.bumptech.glide:compiler:4.9.0'
猜你喜欢
  • 1970-01-01
  • 2015-09-20
  • 1970-01-01
  • 1970-01-01
  • 2018-11-21
  • 2019-10-06
  • 2019-06-04
  • 2018-03-08
  • 1970-01-01
相关资源
最近更新 更多