【发布时间】:2017-03-30 09:25:20
【问题描述】:
我指的是这个问题的第二个答案:
Web Service Client (JAX-WS) in Weblogic(10.3) with 2 way SSL cannot complete the handshake
我有一个使用单向 SSL 连接到另一台服务器 A 的客户端程序。为了关闭证书链验证,我使用了上述问题的第二个答案中的解决方案来安装全信任信任管理器。它工作正常。
但是,当客户端程序使用双向 SSL 连接到另一个服务器 B 时,会抛出以下异常。
java.net.SocketException: Software caused connection abort: recv failed
at java.net.SocketInputStream.socketRead0(Native Method)
at java.net.SocketInputStream.socketRead(SocketInputStream.java:116)
at java.net.SocketInputStream.read(SocketInputStream.java:171)
at java.net.SocketInputStream.read(SocketInputStream.java:141)
at sun.security.ssl.InputRecord.readFully(InputRecord.java:465)
at sun.security.ssl.InputRecord.read(InputRecord.java:503)
at sun.security.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:973)
at sun.security.ssl.SSLSocketImpl.waitForClose(SSLSocketImpl.java:1769)
at sun.security.ssl.HandshakeOutStream.flush(HandshakeOutStream.java:124
)
at sun.security.ssl.Handshaker.sendChangeCipherSpec(Handshaker.java:1130
)
at sun.security.ssl.ClientHandshaker.sendChangeCipherAndFinish(ClientHan
dshaker.java:1216)
at sun.security.ssl.ClientHandshaker.serverHelloDone(ClientHandshaker.ja
va:1128)
at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.jav
a:348)
at sun.security.ssl.Handshaker.processLoop(Handshaker.java:1026)
at sun.security.ssl.Handshaker.process_record(Handshaker.java:961)
at sun.security.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:1062)
at sun.security.ssl.SSLSocketImpl.performInitialHandshake(SSLSocketImpl.
java:1375)
at sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1403
)
at sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1387
)
at sun.net.www.protocol.https.HttpsClient.afterConnect(HttpsClient.java:
559)
at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect
(AbstractDelegateHttpsURLConnection.java:185)
at sun.net.www.protocol.http.HttpURLConnection.getOutputStream0(HttpURLC
onnection.java:1316)
at sun.net.www.protocol.http.HttpURLConnection.getOutputStream(HttpURLCo
nnection.java:1291)
at sun.net.www.protocol.https.HttpsURLConnectionImpl.getOutputStream(Htt
psURLConnectionImpl.java:250)
如果我不安装全信任信任管理器,我仍然可以使与两台服务器的连接正常工作(无论是单向还是双向 SSL),前提是我指定了身份存储和信任存储:
System.setProperty("javax.net.ssl.keyStore", "path/to/your/key");
System.setProperty("javax.net.ssl.keyStorePassword", "your-keystore-password");
System.setProperty("javax.net.ssl.keyStoreType", "JKS");
System.setProperty("javax.net.ssl.trustStore", "path/to/your/trust/keystore");
System.setProperty("javax.net.ssl.trustStorePassword", "your-truststore-password");
但是,我仍然想在双向 SSL 中关闭证书链验证。安装全信任信任管理器似乎不起作用。为什么?
提前致谢。
【问题讨论】:
-
如果您不希望它安全,为什么要使用双向身份验证?你为什么要使用 SSL?
-
服务器实际上是公司内部的。它为许多其他客户提供服务。作为客户端,我并不关心服务器的身份是否在我的信任库中。因为它是一个内部服务器,所以安全性不是那么重要。
-
这并不能回答我的任何一个问题。
-
首先,我说过我不希望它安全吗?我正在使用 SSL,所以它当然是安全的。我想要的只是禁用服务器的验证。它是我们可以信任的内部服务器。
标签: java ssl https handshake truststore