Необходимо сделать клиента, который общается через https, в наличие имею Certificate.p7b и Personal.pfx Импортирую Personal.pfx в my.keystore | Код | C:\>keytool -importkeystore -srcstoretype pkcs12 -srckeystore c:\keystore\Personal.pfx -destkeystore c:\keystore\my.keystore -srcalias mykey -destalias goodkey -srckeypass 123 -destkeypass tomcat |
все проходит без ошибок, затем пытаюсь просмотреть my.keystore | Код | C:\keytool" -v -list -keystore c:\keystore\my.keystore
|
в этом сертификате в Extensions: проскакивает Exception несколько раз : | Код | #4: ObjectId: 1.3.6.1.5.5.7.1.1 Criticality=false Unparseable AuthorityInfoAccess extension due to java.io.IOException: invalid URI name:file://\\dca01\CertEnroll\dca01_хххххххх хххххххх(6).crt
|
Критично ли это? Подскажите Затем импортирую Certificate.p7b в браузер и отуда экспортирую Certificate.cer Добавляю в my.truststore При просмотре опять проскакивает тот же Exception | Код | Unparseable AuthorityInfoAccess extension due to java.io.IOException: invalid URI name:file://
|
Для соединения использую httpclient-4.0 | Код | DefaultHttpClient httpClient=new DefaultHttpClient(); KeyStore keysStore = KeyStore.getInstance(KeyStore.getDefaultType()); KeyStore trustStore = KeyStore.getInstance(KeyStore.getDefaultType()); FileInputStream instream = new FileInputStream(new File("c:\\keystore\\my.keystore")); FileInputStream instream2 = new FileInputStream(new File("c:\\keystore\\my.truststore")); try { keysStore.load(instream, "tomcat".toCharArray()); trustStore.load(instream2, "tomcat".toCharArray()); } catch (IOException ex) { Logger.getLogger(TestConnection.class.getName()).log(Level.SEVERE, null, ex); } catch (NoSuchAlgorithmException ex) { Logger.getLogger(TestConnection.class.getName()).log(Level.SEVERE, null, ex); } catch (CertificateException ex) { Logger.getLogger(TestConnection.class.getName()).log(Level.SEVERE, null, ex); }finally{
instream.close(); } SSLSocketFactory socketFactory = new SSLSocketFactory(keysStore, "tomcat", trustStore); Scheme sch = new Scheme("https", socketFactory, 444); httpClient.getConnectionManager().getSchemeRegistry().register(sch);
HttpGet httpget = new HttpGet("https://192.168.11.11:444/Serv/test.html?data1=xxxx&data2=xxxx");
System.out.println("executing request" + httpget.getRequestLine());
HttpResponse response = httpClient.execute(httpget); HttpEntity entity = response.getEntity();
System.out.println("----------------------------------------"); System.out.println(response.getStatusLine()); if (entity != null) { System.out.println("Response content length: " + entity.getContentLength()); } if (entity != null) { entity.consumeContent(); }
httpClient.getConnectionManager().shutdown();
|
Ну и на последок получаю | Код | Exception in thread "main" javax.net.ssl.SSLPeerUnverifiedException: peer not authenticated at com.sun.net.ssl.internal.ssl.SSLSessionImpl.getPeerCertificates(SSLSessionImpl.java:352) |
Подскажите или натолкните, где копать. Гугл потихоньку начинает меня игнорировать
|