powered by simpleCommunicator - 2.0.61     © 2026 Programmizd 02
Целевая тема:
Создать новую тему:
Автор:
Закрыть
Цитировать
Форумы / Java [игнор отключен] [закрыт для гостей] / Клиент веб сервиса и сертфикат.
25 сообщений из 44, страница 1 из 2
Клиент веб сервиса и сертфикат.
    #37885767
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Смысл такой есть вебсервис на .net с сертификатом. К нему создан клиент на яве. Не получается прицепить к нему сертификат из за чего он не дает коннект. Сертификат установлен вместе с крипто про в винде. Также есть сами файлы .cer. Как можно подцепить сертификаты к клиенту? Уже весь инет облазил и всё перепробовал пишет что неизвестный сертификат.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37885775
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Вот ошибка подробнее:

main, SEND TLSv1 ALERT: fatal, description = certificate_unknown
main, WRITE: TLSv1 Alert, length = 2
[Raw write]: length = 7
0000: 15 03 01 00 02 02 2E .......
main, called closeSocket()
main, handling exception: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
main, called close()
main, called closeInternal(true)
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37885776
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
импортировать сертификат в keystore?
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37885788
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Blazkowiczимпортировать сертификат в keystore?
Пример можно?
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37885802
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37885867
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Blazkowicz http://docs.oracle.com/javaee/1.4/tutorial/doc/Security6.html
Ну да keytool я использовал и таая ошибка вылазиет.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37885872
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
PeaceDeadsНу да keytool я использовал и таая ошибка вылазиет.
Как именно вы его использовали? Там ещё и сертификат самоподписаный небось.
Посмотрите вот здесь
https://blogs.oracle.com/gc/entry/unable_to_find_valid_certification
там вроде удобная утилита по импорту когда-то была.

Можно вообще отключить проверку сертификата. Тут по форуму поищите последние темы по SSL, там примеры были.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37886744
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
BlazkowiczPeaceDeadsНу да keytool я использовал и таая ошибка вылазиет.
Как именно вы его использовали? Там ещё и сертификат самоподписаный небось.
Посмотрите вот здесь
https://blogs.oracle.com/gc/entry/unable_to_find_valid_certification
там вроде удобная утилита по импорту когда-то была.

Можно вообще отключить проверку сертификата. Тут по форуму поищите последние темы по SSL, там примеры были.

Сервер не мой сертификат там отключить не могу и он там нужен для защиты данных. Возможно причина в том что сертификат является дочерним другого сертификата а его не получается в jks загрузить.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37886752
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
PeaceDeadsСервер не мой сертификат там отключить не могу и он там нужен для защиты данных.

Не нужно "там" отключать. Я про то чтобы отключать его валидацию на клиенте. Вы даже не искали. Ошибка у вас на клиенте.
Если сервер вас без сертификата не пускает, это уже другой разговор.

PeaceDeadsВозможно причина в том что сертификат является дочерним другого сертификата а его не получается в jks загрузить.
Возможно гадать о вымышленых причинах можно очень долго. Послушайте людей, которые с этим сталкивались не раз.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37886805
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
[quot Blazkowicz]PeaceDeadsСервер не мой сертификат там отключить не могу и он там нужен для защиты данных.

Не нужно "там" отключать. Я про то чтобы отключать его валидацию на клиенте. Вы даже не искали. Ошибка у вас на клиенте.
Если сервер вас без сертификата не пускает, это уже другой разговор.
В том то и дело сервер не пускает.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37886832
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
PeaceDeadsВ том то и дело сервер не пускает.
То что вы привели это ошибка на клиентской части. Я объяснил как её исправить.
Если у вас сейчас другая ошибка с сервера, то это другой разговор - показывайте ошибку сервера.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37886890
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Blazkowicz,

Я на C# создал клиента под этот же сервис там нет проблем с подключением сертификата. С Явой я слабо знаком, тока начинаю в ней разбираться. Создал классы через wsimport предварительно пришлось wsdl и xsd переправить чтоб обойти сертификат. Наверное сейчас криво сделал импорт в jks. Потому такая проблема. Я сейчас опишу как я устанавливал сертификат. Сначала установил крипто про потом в реестр добавил записи через крипто про установил сертификат postest.cer затем просто запустил другой сертификат root.cer. Таким получилась в пути сертификата получилась иерархия root->postest. Теперь вопрос мне в jks нужно оба сертификата импортнуть или нет? сертификат root.cer не импортируется.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37886915
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
PeaceDeadsЯ на C# создал клиента под этот же сервис там нет проблем с подключением сертификата. С Явой я слабо знаком, тока начинаю в ней разбираться. Создал классы через wsimport предварительно пришлось wsdl и xsd переправить чтоб обойти сертификат. Наверное сейчас криво сделал импорт в jks. Потому такая проблема. Я сейчас опишу как я устанавливал сертификат. Сначала установил крипто про потом в реестр добавил записи через крипто про установил сертификат postest.cer затем просто запустил другой сертификат root.cer. Таким получилась в пути сертификата получилась иерархия root->postest. Теперь вопрос мне в jks нужно оба сертификата импортнуть или нет? сертификат root.cer не импортируется.
Вы тупо игнорируете то что я пишу.
Вот статья, ссылку на которую я привел выше.
http://nodsw.com/blog/leeland/2006/12/06-no-more-unable-find-valid-certification-path-requested-target
В ней готовый класс, который скачает сертификат и поместит в jks. Вам нужно только заюзать это хранилище ключей как truststore в вашем приложении.
Зачем нужно инсталировать неизвесно где взятые сертификаты не извесно как, я не понял.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37887016
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
В обоих статьях битые ссылки. Сейчас попробую скомпилировать исходники. Спасибо.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37887023
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
PeaceDeadsВ обоих статьях битые ссылки. Сейчас попробую скомпилировать исходники. Спасибо.
У вас браузер битый, а не ссылки.

Andreas Sterbenz No more 'unable to find valid certification path to requested target'

Some of you may be familiar with the (not very user friendly) exception message
javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

when trying to open an SSL connection to a host using JSSE. What this usually means is that the server is using a test certificate (possibly generated using keytool) rather than a certificate from a well known commercial Certification Authority such as Verisign or GoDaddy. Web browsers display warning dialogs in this case, but since JSSE cannot assume an interactive user is present it just throws an exception by default.

Certificate validation is a very important part of SSL security, but I am not writing this entry to explain the details. If you are interested, you can start by reading the Wikipedia blurb. I am writing this entry to show a simple way to talk to that host with the test certificate, if you really want to.

Basically, you want to add the server's certificate to the KeyStore with your trusted certificates. There are any number of ways to achieve that, but a simple solution is to compile and run the attached program as java InstallCert hostname, for example:

% java InstallCert ecc.fedora.redhat.com
Loading KeyStore
/usr/jdk/instances/jdk1.5.0/jre/lib/security/cacerts...
Opening connection to ecc.fedora.redhat.com:443...
Starting SSL handshake...

javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException:
PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException:
unable to find valid certification path to requested target
at com.sun.net.ssl.internal.ssl.Alerts.getSSLException(Alerts.java:150)
at com.sun.net.ssl.internal.ssl.SSLSocketImpl.fatal(SSLSocketImpl.java:1476)
at com.sun.net.ssl.internal.ssl.Handshaker.fatalSE(Handshaker.java:174)
at com.sun.net.ssl.internal.ssl.Handshaker.fatalSE(Handshaker.java:168)
at com.sun.net.ssl.internal.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:846)
at com.sun.net.ssl.internal.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:106)
at com.sun.net.ssl.internal.ssl.Handshaker.processLoop(Handshaker.java:495)
at com.sun.net.ssl.internal.ssl.Handshaker.process_record(Handshaker.java:433)
at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:815)
at com.sun.net.ssl.internal.ssl.SSLSocketImpl.performInitialHandshake(SSLSocketImpl.java:1025)
at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1038)
at InstallCert.main(InstallCert.java:63)
Caused by: sun.security.validator.ValidatorException: PKIX path building failed:
sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid
certification path to requested target
at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:221)
at sun.security.validator.PKIXValidator.engineValidate(PKIXValidator.java:145)
at sun.security.validator.Validator.validate(Validator.java:203)
at com.sun.net.ssl.internal.ssl.X509TrustManagerImpl.checkServerTrusted(X509TrustManagerImpl.java:172)
at InstallCert$SavingTrustManager.checkServerTrusted(InstallCert.java:158)
at com.sun.net.ssl.internal.ssl.JsseX509TrustManager.checkServerTrusted(SSLContextImpl.java:320)
at com.sun.net.ssl.internal.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:839)
... 7 more
Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid
certification path to requested target
at sun.security.provider.certpath.SunCertPathBuilder.engineBuild(SunCertPathBuilder.java:236)
at java.security.cert.CertPathBuilder.build(CertPathBuilder.java:194)
at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:216)
... 13 more

Server sent 2 certificate(s):

1 Subject CN=ecc.fedora.redhat.com, O=example.com, C=US
Issuer CN=Certificate Shack, O=example.com, C=US
sha1 2e 7f 76 9b 52 91 09 2e 5d 8f 6b 61 39 2d 5e 06 e4 d8 e9 c7
md5 dd d1 a8 03 d7 6c 4b 11 a7 3d 74 28 89 d0 67 54

2 Subject CN=Certificate Shack, O=example.com, C=US
Issuer CN=Certificate Shack, O=example.com, C=US
sha1 fb 58 a7 03 c4 4e 3b 0e e3 2c 40 2f 87 64 13 4d df e1 a1 a6
md5 72 a0 95 43 7e 41 88 18 ae 2f 6d 98 01 2c 89 68

Enter certificate to add to trusted keystore or 'q' to quit: [1]

What happened was that the program opened a connection to the specified host and started an SSL handshake. It printed the exception stack trace of the error that occured and shows you the certificates used by the server. Now it prompts you for the certificate you want to add to your trusted KeyStore. You should only do this if you are sure that this is the certificate of the trusted host you want to connect to. You may want to check the MD5 and SHA1 certificate fingerprints against a fingerprint generated on the server (e.g. using keytool) to make sure it is the correct certificate.

If you've changed your mind, enter 'q'. If you really want to add the certificate, enter '1'. (You could also add a CA certificate by entering a different certificate, but you usually don't want to do that'). Once you have made your choice, the program will print the following:


[
[
Version: V3
Subject: CN=ecc.fedora.redhat.com, O=example.com, C=US
Signature Algorithm: MD5withRSA, OID = 1.2.840.113549.1.1.4

Key: SunPKCS11-Solaris RSA public key, 1024 bits
(id 5158256, session object)
modulus: 1402933022884660852748661816869706021655226675890
635441166580364941191074987345500771612454338502131694873337
233737712894815966313948609351561047977102880577818156814678
041303637255354084762814638611185951230474669455913908815827
173696651397340074281578017567044868711049821409365743953199
69584127568303024757
public exponent: 65537
Validity: [From: Wed Jan 18 13:16:12 PST 2006,
To: Wed Apr 18 14:16:12 PDT 2007]
Issuer: CN=Certificate Shack, O=example.com, C=US
SerialNumber: [ 0f]

Certificate Extensions: 2
[1]: ObjectId: 2.16.840.1.113730.1.1 Criticality=false
NetscapeCertType [
SSL server
]

[2]: ObjectId: 2.5.29.15 Criticality=false
KeyUsage [
Key_Encipherment
]

]
Algorithm: [MD5withRSA]
Signature:
0000: 6D F4 2A 63 76 2A 05 70 A2 21 0E 1E 4A 31 BE 6B m.*cv*.p.!..J1.k
0010: 15 64 D8 BB 35 36 82 B0 0D 2A 96 FA 7A 9F A1 59 .d..56...*..z..Y
0020: CA 90 C3 28 C5 A6 9B 59 05 3B EB B2 8D C9 5E 38 ...(...Y.;....^8
0030: 62 ED 1A D7 93 DF 2A A5 D6 54 94 23 15 A2 0C E5 b.....*..T.#....
0040: 13 40 2C 3E 59 E4 2A EB 51 AC 9E 28 44 23 87 B1 .@,>Y.*.Q..(D#..
0050: 34 0B AC F3 E0 39 CA B8 35 B4 78 07 BF 28 4C C4 4....9..5.x..(L.
0060: 9A 2B A3 E9 04 26 78 19 F0 62 EA 0A B5 BB DC 0B .+...&x..b......
0070: 90 59 E7 77 90 F8 BC 8A 1B 74 4B 4D C1 F8 3B 6C .Y.w.....tKM..;l

]

Added certificate to keystore 'jssecacerts' using alias
'ecc.fedora.redhat.com-1'

It displayed the complete certificate and then added it to a Java KeyStore 'jssecacerts' in the current directory. To use it in your program, either configure JSSE to use it as its trust store (as explained in the documentation) or copy it into your $JAVA_HOME/jre/lib/security directory. If you want all Java applications to recognize the certificate as trusted and not just JSSE, you could also overwrite the cacerts file in that directory.

After all that, JSSE will be able to complete a handshake with the host, which you can verify by running the program again:

% java InstallCert ecc.fedora.redhat.com
Loading KeyStore jssecacerts...
Opening connection to ecc.fedora.redhat.com:443...
Starting SSL handshake...

No errors, certificate is already trusted

Server sent 2 certificate(s):

1 Subject CN=ecc.fedora.redhat.com, O=example.com, C=US
Issuer CN=Certificate Shack, O=example.com, C=US
sha1 2e 7f 76 9b 52 91 09 2e 5d 8f 6b 61 39 2d 5e 06 e4 d8 e9 c7
md5 dd d1 a8 03 d7 6c 4b 11 a7 3d 74 28 89 d0 67 54

2 Subject CN=Certificate Shack, O=example.com, C=US
Issuer CN=Certificate Shack, O=example.com, C=US
sha1 fb 58 a7 03 c4 4e 3b 0e e3 2c 40 2f 87 64 13 4d df e1 a1 a6
md5 72 a0 95 43 7e 41 88 18 ae 2f 6d 98 01 2c 89 68

Enter certificate to add to trusted keystore or
'q' to quit: [1]
q
KeyStore not changed

I hope that helps. For more information about the InstallCert program, have a look at the (**2011-10-11 edit the link now has a 404 (gone from the web) so I posted the source below) source code. I am sure you can figure out how it works.

Код: java
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154.
155.
156.
157.
158.
159.
160.
161.
162.
163.
164.
165.
166.
167.
168.
169.
170.
171.
172.
173.
174.
175.
176.
177.
178.
179.
180.
181.
182.
183.
184.
185.
186.
187.
188.
189.
190.
191.
192.
193.
194.
195.
196.
/*
 * Copyright 2006 Sun Microsystems, Inc.  All Rights Reserved.
 *
 * Redistribution and use in source and binary forms, with or without
 * modification, are permitted provided that the following conditions
 * are met:
 *
 *   - Redistributions of source code must retain the above copyright
 *     notice, this list of conditions and the following disclaimer.
 *
 *   - Redistributions in binary form must reproduce the above copyright
 *     notice, this list of conditions and the following disclaimer in the
 *     documentation and/or other materials provided with the distribution.
 *
 *   - Neither the name of Sun Microsystems nor the names of its
 *     contributors may be used to endorse or promote products derived
 *     from this software without specific prior written permission.
 *
 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS
 * IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
 * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
 * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE COPYRIGHT OWNER OR
 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
 * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
 * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
 * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
 * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
 */
/**
 * Originally from:
 * http://blogs.sun.com/andreas/resource/InstallCert.java
 * Use:
 * java InstallCert hostname
 * Example:
 *% java InstallCert ecc.fedora.redhat.com
 */

import javax.net.ssl.*;
import java.io.*;
import java.security.KeyStore;
import java.security.MessageDigest;
import java.security.cert.CertificateException;
import java.security.cert.X509Certificate;

/**
 * Class used to add the server's certificate to the KeyStore
 * with your trusted certificates.
 */
public class InstallCert {

    public static void main(String[] args) throws Exception {
        String host;
        int port;
        char[] passphrase;
        if ((args.length == 1) || (args.length == 2)) {
            String[] c = args[0].split(":");
            host = c[0];
            port = (c.length == 1) ? 443 : Integer.parseInt(c[1]);
            String p = (args.length == 1) ? "changeit" : args[1];
            passphrase = p.toCharArray();
        } else {
            System.out.println("Usage: java InstallCert [:port] [passphrase]");
            return;
        }

        File file = new File("jssecacerts");
        if (file.isFile() == false) {
            char SEP = File.separatorChar;
            File dir = new File(System.getProperty("java.home") + SEP
                    + "lib" + SEP + "security");
            file = new File(dir, "jssecacerts");
            if (file.isFile() == false) {
                file = new File(dir, "cacerts");
            }
        }
        System.out.println("Loading KeyStore " + file + "...");
        InputStream in = new FileInputStream(file);
        KeyStore ks = KeyStore.getInstance(KeyStore.getDefaultType());
        ks.load(in, passphrase);
        in.close();

        SSLContext context = SSLContext.getInstance("TLS");
        TrustManagerFactory tmf =
                TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());
        tmf.init(ks);
        X509TrustManager defaultTrustManager = (X509TrustManager) tmf.getTrustManagers()[0];
        SavingTrustManager tm = new SavingTrustManager(defaultTrustManager);
        context.init(null, new TrustManager[]{tm}, null);
        SSLSocketFactory factory = context.getSocketFactory();

        System.out.println("Opening connection to " + host + ":" + port + "...");
        SSLSocket socket = (SSLSocket) factory.createSocket(host, port);
        socket.setSoTimeout(10000);
        try {
            System.out.println("Starting SSL handshake...");
            socket.startHandshake();
            socket.close();
            System.out.println();
            System.out.println("No errors, certificate is already trusted");
        } catch (SSLException e) {
            System.out.println();
            e.printStackTrace(System.out);
        }

        X509Certificate[] chain = tm.chain;
        if (chain == null) {
            System.out.println("Could not obtain server certificate chain");
            return;
        }

        BufferedReader reader =
                new BufferedReader(new InputStreamReader(System.in));

        System.out.println();
        System.out.println("Server sent " + chain.length + " certificate(s):");
        System.out.println();
        MessageDigest sha1 = MessageDigest.getInstance("SHA1");
        MessageDigest md5 = MessageDigest.getInstance("MD5");
        for (int i = 0; i < chain.length; i++) {
            X509Certificate cert = chain[i];
            System.out.println
                    (" " + (i + 1) + " Subject " + cert.getSubjectDN());
            System.out.println("   Issuer  " + cert.getIssuerDN());
            sha1.update(cert.getEncoded());
            System.out.println("   sha1    " + toHexString(sha1.digest()));
            md5.update(cert.getEncoded());
            System.out.println("   md5     " + toHexString(md5.digest()));
            System.out.println();
        }

        System.out.println("Enter certificate to add to trusted keystore or 'q' to quit: [1]");
        String line = reader.readLine().trim();
        int k;
        try {
            k = (line.length() == 0) ? 0 : Integer.parseInt(line) - 1;
        } catch (NumberFormatException e) {
            System.out.println("KeyStore not changed");
            return;
        }

        X509Certificate cert = chain[k];
        String alias = host + "-" + (k + 1);
        ks.setCertificateEntry(alias, cert);

        OutputStream out = new FileOutputStream("jssecacerts");
        ks.store(out, passphrase);
        out.close();

        System.out.println();
        System.out.println(cert);
        System.out.println();
        System.out.println
                ("Added certificate to keystore 'jssecacerts' using alias '"
                        + alias + "'");
    }

    private static final char[] HEXDIGITS = "0123456789abcdef".toCharArray();

    private static String toHexString(byte[] bytes) {
        StringBuilder sb = new StringBuilder(bytes.length * 3);
        for (int b : bytes) {
            b &= 0xff;
            sb.append(HEXDIGITS[b >> 4]);
            sb.append(HEXDIGITS[b & 15]);
            sb.append(' ');
        }
        return sb.toString();
    }

    private static class SavingTrustManager implements X509TrustManager {

        private final X509TrustManager tm;
        private X509Certificate[] chain;

        SavingTrustManager(X509TrustManager tm) {
            this.tm = tm;
        }

        public X509Certificate[] getAcceptedIssuers() {
            throw new UnsupportedOperationException();
        }

        public void checkClientTrusted(X509Certificate[] chain, String authType)
                throws CertificateException {
            throw new UnsupportedOperationException();
        }

        public void checkServerTrusted(X509Certificate[] chain, String authType)
                throws CertificateException {
            this.chain = chain;
            tm.checkServerTrusted(chain, authType);
        }
    }
}
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37887036
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Blazkowicz,

Спасибо. Вы две разных ссылки дали они не битые, но внутри них ссылки на InstallCert.java битые. Во второй ссылке исходники, я и написал что сейчас скомпилирую и попробую. :)
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37887188
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Blazkowicz,

Спасибо! С сертификатом разобрался всё находит проверку прошел. Но теперь выводит ошибку:
main, handling exception: javax.net.ssl.SSLProtocolException: Server did not send a DH Server Key Exchange message
main, SEND TLSv1 ALERT: fatal, description = unexpected_message
main, WRITE: TLSv1 Alert, length = 2
[Raw write]: length = 7
0000: 15 03 01 00 02 02 0A .......
main, called closeSocket()
main, called close()
main, called closeInternal(true)
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37887236
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
-Djavax.net.debug=ssl не пробовали?
ещё советуют установаить JCE
http://www.oracle.com/technetwork/java/javase/downloads/index.html
Два последних в списке -
Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37888866
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Blazkowicz,
Возможно я что-то не так использую? ошибка :

main, handling exception: javax.net.ssl.SSLProtocolException: Server did not send a DH Server Key Exchange message
main, SEND TLSv1 ALERT: fatal, description = unexpected_message

Вот код запускаю его в eclipse

Код: java
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
                 WEBService service = new WEBService ();
		 IWEBService iService = service.getBasicHttpBindingIWEBService();
		 
		 BindingProvider bp = (BindingProvider)iService;
		 System.setProperty("javax.net.ssl.keyStoreType", "JKS");
		 System.setProperty("javax.net.ssl.trustStore", "E:/WEBclient_java/wsdl/jssecacerts");
		 System.setProperty("javax.net.ssl.trustStorePassword", "changeit");
		 System.setProperty("java.security.debug", "all");
		 
		 System.setProperty("java.protocol.handler.pkgs","javax.net.ssl");
		 System.setProperty("sun.security.ssl.allowUnsafeRenegotiation", "true");
		 System.setProperty("javax.net.debug", "all");

WEBResultOfArrayOfstringuHEDJ7Dj sss = iService.getBankOffices();
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37888869
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy установлен в JRE?
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37888877
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Blazkowicz,

Да
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37888886
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
Надо смотреть всё что в консоль теперь пишеться. Порядок сообщений например, с сервера и клиента.
Какая версия JDK?
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37888888
Фотография Blazkowicz
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Участник
И покажите stacktrace, пожалуйста. Это очень важная часть исключения её всегда стоит логировать.
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37888891
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Blazkowicz,

1.6.0.33
jce 6
...
Рейтинг: 0 / 0
Клиент веб сервиса и сертфикат.
    #37888902
PeaceDeads
Скрыть профиль Поместить в игнор-лист Сообщения автора в теме
Гость
Blazkowicz,

Некоторые хэши заменил ... чтоб проще читалось

Код: java
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154.
155.
156.
157.
158.
159.
160.
161.
162.
163.
164.
165.
166.
167.
168.
169.
170.
171.
172.
173.
174.
175.
176.
177.
178.
179.
180.
181.
182.
183.
184.
185.
186.
187.
188.
189.
190.
191.
192.
193.
194.
195.
196.
197.
198.
199.
200.
201.
202.
203.
204.
keyStore is : 
keyStore type is : JKS
keyStore provider is : 
init keystore
init keymanager of type SunX509
trustStore is: E:\credit_broker_java\wsdl\jssecacerts
trustStore type is : jks
trustStore provider is : 
init truststore
adding as trusted cert:
Добавляет кучу сертификатов


trigger seeding of SecureRandom
done seeding SecureRandom
Allow unsafe renegotiation: true
Allow legacy hello messages: true
Is initial handshake: true
Is secure renegotiation: false
%% No cached client session
*** ClientHello, TLSv1
RandomCookie:  GMT: 1342963338 bytes = { 220, 205, 211, 143, 233, 222, 27, 127, 97, 186, 52, 210, 96, 108, 0, 3, 255, 233, 160, 217, 231, 45, 150, 179, 70, 184, 216, 37 }
Session ID:  {}
Cipher Suites: [SSL_RSA_WITH_RC4_128_MD5, SSL_RSA_WITH_RC4_128_SHA, TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_DHE_RSA_WITH_AES_128_CBC_SHA, TLS_DHE_RSA_WITH_AES_256_CBC_SHA, TLS_DHE_DSS_WITH_AES_128_CBC_SHA, TLS_DHE_DSS_WITH_AES_256_CBC_SHA, SSL_RSA_WITH_3DES_EDE_CBC_SHA, SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA, SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA, SSL_RSA_WITH_DES_CBC_SHA, SSL_DHE_RSA_WITH_DES_CBC_SHA, SSL_DHE_DSS_WITH_DES_CBC_SHA, SSL_RSA_EXPORT_WITH_RC4_40_MD5, SSL_RSA_EXPORT_WITH_DES40_CBC_SHA, SSL_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA, SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA, TLS_EMPTY_RENEGOTIATION_INFO_SCSV]
Compression Methods:  { 0 }
***
[write] MD5 and SHA1 hashes:  len = 81
...
main, WRITE: TLSv1 Handshake, length = 81
[write] MD5 and SHA1 hashes:  len = 110
...
main, WRITE: SSLv2 client hello message, length = 110
[Raw write]: length = 112
...
[Raw read]: length = 5
0000: 16 03 01 03 44                                     ....D
[Raw read]: length = 836
...
main, READ: TLSv1 Handshake, length = 836
*** ServerHello, TLSv1
RandomCookie:  GMT: 1342963338 bytes = { 122, 57, 131, 89, 124, 92, 25, 20, 131, 85, 95, 203, 200, 241, 163, 192, 19, 54, 225, 74, 232, 21, 164, 211, 0, 0, 0, 0 }
Session ID:  {207, 191, 170, 74, 140, 244, 16, 128, 249, 187, 114, 236, 243, 105, 195, 34, 220, 29, 125, 151, 120, 240, 179, 100, 43, 222, 36, 199, 250, 128, 6, 176}
Cipher Suite: TLS_DHE_DSS_WITH_AES_128_CBC_SHA
Compression Method: 0
***
Warning: No renegotiation indication extension in ServerHello
%% Created:  [Session-1, TLS_DHE_DSS_WITH_AES_128_CBC_SHA]
** TLS_DHE_DSS_WITH_AES_128_CBC_SHA
[read] MD5 and SHA1 hashes:  len = 74
...
*** Certificate chain
chain [0] = [
[
  Version: V3
  Subject: CN=webpos.mcb.ru, C=RU
  Signature Algorithm: 1.2.643.2.2.3, OID = 1.2.643.2.2.3

  Key:  algorithm = 1.2.643.2.2.19, params unparsed, unparsed keybits = 
...
  Validity: [From: Thu May 03 12:33:41 MSK 2012,
               To: Fri Apr 19 17:35:28 MSK 2013]
  Issuer: CN=mcb-GOST-CA, DC=mcb, DC=ru
  SerialNumber: [    4282dbae 00000000 07eb]

Certificate Extensions: 6
[1]: ObjectId: 1.3.6.1.5.5.7.1.1 Criticality=false
AuthorityInfoAccess [
  [
   accessMethod: 1.3.6.1.5.5.7.48.2
   accessLocation: URIName: http://cronoss.mcb.ru/CertEnroll/Cronoss.mcb.ru_mcb-GOST-CA.crt, 
   accessMethod: 1.3.6.1.5.5.7.48.2
   accessLocation: URIName: file://Cronoss.mcb.ru/CertEnroll/Cronoss.mcb.ru_mcb-GOST-CA.crt]
]

[2]: ObjectId: 2.5.29.35 Criticality=false
AuthorityKeyIdentifier [
KeyIdentifier [
0000: CB 2C AD 32 05 A5 01 31   18 DA 15 F7 7A 24 F0 A3  .,.2...1....z$..
0010: 8F A4 35 7C                                        ..5.
]

]

[3]: ObjectId: 2.5.29.31 Criticality=false
CRLDistributionPoints [
  [DistributionPoint:
     [URIName: http://cronoss.mcb.ru/CertEnroll/mcb-GOST-CA.crl, URIName: file://Cronoss.mcb.ru/CertEnroll/mcb-GOST-CA.crl]
]]

[4]: ObjectId: 2.5.29.37 Criticality=false
ExtendedKeyUsages [
  serverAuth
]

[5]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Non_repudiation
  Key_Encipherment
  Data_Encipherment
]

[6]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: C1 76 D6 F3 58 97 74 37   BF 2A 12 42 4B 25 FA A7  .v..X.t7.*.BK%..
0010: 2F 85 75 15                                        /.u.
]
]

]
  Algorithm: [1.2.643.2.2.3]
  Signature:
0000: DC A7 7C B2 74 29 23 C4   4E EF A8 53 EE EB 1B 96  ....t)#.N..S....
0010: 8D E7 9A 23 E8 60 06 29   D4 D7 9F 79 4B EE B3 5C  ...#.`.)...yK..\
0020: 2C D9 FC 68 4E 5E 08 93   43 75 94 F9 82 11 61 34  ,..hN^..Cu....a4
0030: 14 8D 8F BA 4C 34 AA 53   58 2E 5B 71 72 E8 66 7D  ....L4.SX.[qr.f.

]
***
Found trusted certificate:
[
[
  Version: V3
  Subject: CN=webpos.mcb.ru, C=RU
  Signature Algorithm: 1.2.643.2.2.3, OID = 1.2.643.2.2.3

  Key:  algorithm = 1.2.643.2.2.19, params unparsed, unparsed keybits = 
0000: 04 40 F0 FB AA BB B5 74   7B AC CF 2F 5F 79 B4 2F  .@.....t.../_y./
0010: 42 04 5D 49 CE E8 44 1F   A0 A5 AD 3D 9E 07 2D 53  B.]I..D....=..-S
0020: 59 F2 68 C0 5A 96 00 6E   CE 53 2D 85 58 9B D5 8C  Y.h.Z..n.S-.X...
0030: 1D 2D C5 A8 E0 FD 7A B5   CE EF 2F 71 FE 49 CB 15  .-....z.../q.I..
0040: E1 BD                                              ..

  Validity: [From: Thu May 03 12:33:41 MSK 2012,
               To: Fri Apr 19 17:35:28 MSK 2013]
  Issuer: CN=mcb-GOST-CA, DC=mcb, DC=ru
  SerialNumber: [    4282dbae 00000000 07eb]

Certificate Extensions: 6
[1]: ObjectId: 1.3.6.1.5.5.7.1.1 Criticality=false
AuthorityInfoAccess [
  [
   accessMethod: 1.3.6.1.5.5.7.48.2
   accessLocation: URIName: http://cronoss.mcb.ru/CertEnroll/Cronoss.mcb.ru_mcb-GOST-CA.crt, 
   accessMethod: 1.3.6.1.5.5.7.48.2
   accessLocation: URIName: file://Cronoss.mcb.ru/CertEnroll/Cronoss.mcb.ru_mcb-GOST-CA.crt]
]

[2]: ObjectId: 2.5.29.35 Criticality=false
AuthorityKeyIdentifier [
KeyIdentifier [
0000: CB 2C AD 32 05 A5 01 31   18 DA 15 F7 7A 24 F0 A3  .,.2...1....z$..
0010: 8F A4 35 7C                                        ..5.
]

]

[3]: ObjectId: 2.5.29.31 Criticality=false
CRLDistributionPoints [
  [DistributionPoint:
     [URIName: http://cronoss.mcb.ru/CertEnroll/mcb-GOST-CA.crl, URIName: file://Cronoss.mcb.ru/CertEnroll/mcb-GOST-CA.crl]
]]

[4]: ObjectId: 2.5.29.37 Criticality=false
ExtendedKeyUsages [
  serverAuth
]

[5]: ObjectId: 2.5.29.15 Criticality=true
KeyUsage [
  DigitalSignature
  Non_repudiation
  Key_Encipherment
  Data_Encipherment
]

[6]: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: C1 76 D6 F3 58 97 74 37   BF 2A 12 42 4B 25 FA A7  .v..X.t7.*.BK%..
0010: 2F 85 75 15                                        /.u.
]
]

]
  Algorithm: [1.2.643.2.2.3]
  Signature:
...

]
[read] MD5 and SHA1 hashes:  len = 758
...
*** ServerHelloDone
[read] MD5 and SHA1 hashes:  len = 4
0000: 0E 00 00 00                                        ....
main, handling exception: javax.net.ssl.SSLProtocolException: Server did not send a DH Server Key Exchange message
main, SEND TLSv1 ALERT:  fatal, description = unexpected_message
main, WRITE: TLSv1 Alert, length = 2
[Raw write]: length = 7
0000: 15 03 01 00 02 02 0A                               .......
main, called closeSocket()
main, called close()
main, called closeInternal(true)
...
Рейтинг: 0 / 0
25 сообщений из 44, страница 1 из 2
Форумы / Java [игнор отключен] [закрыт для гостей] / Клиент веб сервиса и сертфикат.
Найденые пользователи ...
Разблокировать пользователей ...
Читали форум (0):
Пользователи онлайн (0):
x
x
Закрыть


Просмотр
0 / 0
Close
Debug Console [Select Text]