【问题标题】:Xamarin WKWebView Accepting Self-Signed CertificatesXamarin WKWebView 接受自签名证书
【发布时间】:2017-11-20 20:22:18
【问题描述】:

我在网上看到各种示例说明如何接受它们,但我总是得到发生 SSL 错误,无法与服务器建立安全连接。

我会注意到,肯定会调用该方法(在 iOS 8.4 模拟器和 iOS 11 实际设备上运行),所以这里没有调用该方法。

到目前为止我所尝试的(显然我只在开发中使用此代码,而不是在生产中,等等等等):

1:

public override void DidReceiveAuthenticationChallenge(WKWebView webView, NSUrlAuthenticationChallenge challenge, Action<NSUrlSessionAuthChallengeDisposition, NSUrlCredential> completionHandler) {
 completionHandler(NSUrlSessionAuthChallengeDisposition.UseCredential, new NSUrlCredential(serverTrust));
}

2:

public override void DidReceiveAuthenticationChallenge(WKWebView webView, NSUrlAuthenticationChallenge challenge, Action<NSUrlSessionAuthChallengeDisposition, NSUrlCredential> completionHandler) {
 completionHandler(NSUrlSessionAuthChallengeDisposition.UseCredential, NSUrlCredential.FromTrust(serverTrust));
}

3:

    public override void DidReceiveAuthenticationChallenge(WKWebView webView, NSUrlAuthenticationChallenge challenge, Action<NSUrlSessionAuthChallengeDisposition, NSUrlCredential> completionHandler) {
        SecTrust serverTrust = challenge.ProtectionSpace.ServerSecTrust;
        NSData exceptions = serverTrust.GetExceptions();
        serverTrust.SetExceptions(exceptions);
        exceptions.Dispose();
        completionHandler(NSUrlSessionAuthChallengeDisposition.UseCredential, NSUrlCredential.FromTrust(serverTrust));
    }

4:

    public override void DidReceiveAuthenticationChallenge(WKWebView webView, NSUrlAuthenticationChallenge challenge, Action<NSUrlSessionAuthChallengeDisposition, NSUrlCredential> completionHandler) {
        SecTrust serverTrust = challenge.ProtectionSpace.ServerSecTrust;    //TODO: Get the following working (currently we still receive SSL errors)
        NSData exceptions = serverTrust.GetExceptions();
        serverTrust.SetExceptions(exceptions);
        exceptions.Dispose();

        challenge.Sender.UseCredential(NSUrlCredential.FromTrust(serverTrust), challenge);
        completionHandler(NSUrlSessionAuthChallengeDisposition.UseCredential, NSUrlCredential.FromTrust(serverTrust));
    }

我做错了什么?谢谢。

【问题讨论】:

    标签: xamarin webview xamarin.ios wkwebview


    【解决方案1】:

    为了支持自签名证书,您有 两件事要做:

    1. 在您的自签名域上允许 NSExceptionAllowsInsecureHTTPLoads
      • 即使您使用的是https,您的应用也会被标记为存在信任问题
    2. 绕过证书安全检查

    关于 2 的安全说明:为任何生产应用程序获取 CA 颁发的证书,因为这会完全禁用您的域上的证书验证,从而允许 MITM 攻击、应用程序的 DNS 重定向欺骗等。 . 您可以通过在主捆绑包中包含公共 cer 并将其与收到的证书进行检查来固定证书,但这仅意味着需要在 MITM 或 DNS 欺骗攻击中生成假证书(以及已经存在的工具)在各种漏洞利用工具包中)

    使用https://badssl.com 站点的示例:

    WKNavigationDelegate:

    public class NavigationDelegate : WKNavigationDelegate
    {
        const string host = "self-signed.badssl.com";
        public override void DidReceiveAuthenticationChallenge(WKWebView webView, NSUrlAuthenticationChallenge challenge, Action<NSUrlSessionAuthChallengeDisposition, NSUrlCredential> completionHandler)
        {
            switch (challenge.ProtectionSpace.Host)
            {
                case host:
                    using (var cred = NSUrlCredential.FromTrust(challenge.ProtectionSpace.ServerSecTrust))
                    {
                        completionHandler.Invoke(NSUrlSessionAuthChallengeDisposition.UseCredential, cred);
                    }
                    break;
                default:
                    completionHandler.Invoke(NSUrlSessionAuthChallengeDisposition.PerformDefaultHandling, null);
                    break;
            }
        }
    }
    

    注意:将此类的实例分配给 WKWebView 实例的 NavigationDelegate 或 WeakNavigationDelegate。

    Info.plist NSAppTransportSecurity:

    <key>NSAppTransportSecurity</key>
    <dict>
        <key>NSExceptionDomains</key>
        <dict>
            <key>self-signed.badssl.com</key>
            <dict>
                <key>NSExceptionAllowsInsecureHTTPLoads</key>
                <true/>
            </dict>
        </dict>
    </dict>
    

    【讨论】:

    • 谢谢!我在 info.plist 中添加了您的代码以及 NSExceptionAllowsInsecureHTTPLoads,卸载了应用程序,重新构建和部署,现在看到,在从原始站点重定向到登录站点(也带有自签名证书)之后, DidFailProvisionalNavigation 中的导航失败并出现以下错误:此服务器的证书无效。您可能正在连接到伪装成“login.somesite.dev”的服务器,这可能会使您的机密信息面临风险。
    • @hvaughan3 您有多个自签名站点/域?或者它们是一个自签名域的子域?通配符自签名?等等……
    • .dev 环境中的所有站点都在使用丑陋的自签名证书。因此,当我点击 site1.somesite.dev 并且未登录时,它会重定向到 login.sometime.dev 以强制我登录。两个站点都使用自签名证书,不确定它们是否是相同的自签名证书。实际上,它可以在我的 iOS 11.1.2 设备上运行,但不能在我的 iOS 8.4 模拟器上运行,所以看起来有一个已修复的错误。再次非常感谢您!想要完成这项工作已经很久了。
    • @hvaughan3 我知道证书绕过代码适用于 iOS 9/10/11+(即设备和 sim),但 iOS 8(.4)?我认为有 Apple radr 指出 ATS、自签名证书和 UIWebView/MKWebView 存在问题,但我一时想不起来。
    猜你喜欢
    • 1970-01-01
    • 2015-12-25
    • 2017-04-18
    • 2021-05-21
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多