【问题标题】:Setting trust store programatically in ActiveMQSslConnectionFactory seems to fail在 ActiveMQSslConnectionFactory 中以编程方式设置信任库似乎失败
【发布时间】:2013-05-20 19:38:28
【问题描述】:

我一直在开发一个 java activemq 客户端软件来连接到一个支持 ssl 的代理,但是通过以下方式以编程方式设置信任库:

// Configure the secure connection factory.
ActiveMQSslConnectionFactory connectionFactory = new ActiveMQSslConnectionFactory(url);
connectionFactory.setTrustStore("/conf/client.ts"); // truststore which includes the certificate of the broaker
connectionFactory.setTrustStorePassword("password");

如here 所示。但是,那抛出一个

javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException:PKIX 路径构建失败 错误

根据 QA Resolving javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed Error? 的回复,通过将代理证书添加到我的 java 安装的受信任证书中,我能够成功地将客户端连接到代理。

但是,在这种情况下,我不希望每个使用应用程序的用户都在他们的 java 发行版上导入证书,而是希望客户端应用程序已经携带了代理证书。我怎样才能最好地使用 ActiveMQSslConnectionFactory 类?

【问题讨论】:

    标签: java ssl jms ssl-certificate activemq


    【解决方案1】:

    据我了解,您需要信任所有传入的自签名证书。

    您可以尝试这种方式(创建一个不验证的信任管理器然后注册它:

    TrustManager[] trustAllCerts = new TrustManager[] { 
        new X509TrustManager() {     
            public java.security.cert.X509Certificate[] getAcceptedIssuers() { 
                return null;
            } 
            public void checkClientTrusted( 
                java.security.cert.X509Certificate[] certificates, String authType) {
                } 
            public void checkServerTrusted( 
                java.security.cert.X509Certificate[] certificates, String authType) {
            }
        } 
    }; 
    
    try {
        SSLContext sslContext = SSLContext.getInstance("SSL"); 
        sslContext.init(null, trustAllCerts, new java.security.SecureRandom()); 
        HttpsURLConnection.setDefaultSSLSocketFactory(sslContext.getSocketFactory());
    } catch (GeneralSecurityException e) {
    } 
    
    //then do the ssl conversation.
    

    【讨论】:

    • 虽然这会起作用,但我想知道一个解决方案,我可以将特定的自签名证书设置为被接受。有什么想法吗?
    • 在这种情况下,您必须根据您的要求实施TrustManager。
    • 没有办法以编程方式调用默认的 TrustManager 并导入证书吗?我认为这就是 connectionFactory.setTrustStore 行会做的事情,尽管它不起作用。
    • 应该是在那条线上,但是和ActiveMQConnection一起,最好是ActiveMQSslConnectionFactory。您提出的使用接受所有证书的 TrustManager 的解决方案在没有异常并且不需要在客户端计算机上运行 keytool 的意义上工作。我尝试编辑您的解决方案以将其从 HttpsURLConnection 移植到 ActiveMQSslConnectionFactory 但它被拒绝了=(我希望你不介意我添加了一个新的解决方案 Activemq 连接细节
    【解决方案2】:

    我仍然没有设法使用来自ActiveMQSslConnectionFactory 的setTrustStore 方法以编程方式设置信任库

    但根据@Chris 的响应,可以将接受所有证书的新信任管理器附加到ActiveMQSslConnectionFactory。

    为此,我创建了与他相同的 TrustManager,但使用不同的方法将其链接到 ActiveMQSslConnectionFactory

    TrustManager[] trustAllCerts = new TrustManager[] { 
        new X509TrustManager() {     
            public java.security.cert.X509Certificate[] getAcceptedIssuers() { 
                return null;
            } 
            public void checkClientTrusted( 
                java.security.cert.X509Certificate[] certificates, String authType) {
                } 
            public void checkServerTrusted( 
                java.security.cert.X509Certificate[] certificates, String authType) {
            }
        } 
    }; 
    
    try {
        String connectionString = "ssl://ipaddress:port"
        ActiveMQSslConnectionFactory factory = new  ActiveMQSslConnectionFactory(connectionString);
    factory.setKeyAndTrustManagers(null, trustAllCerts, new SecureRandom());
        Connection connection = factory.createConnection(user,password);
        connection.start(); 
    
    } catch (Exception e) {
    } 
    

    【讨论】:

      猜你喜欢
      • 2019-06-19
      • 2011-12-23
      • 2011-10-23
      • 1970-01-01
      • 1970-01-01
      • 2010-12-08
      • 2016-09-28
      • 2011-07-22
      • 2010-10-15
      相关资源
      最近更新 更多