5

我正在尝试NSURLCredential使用该+credentialWithIdentity:certificates:persistence:方法创建一个。但是它返回零。

我已经完成了以下步骤。首先,我创建了一个私钥和公钥,然后生成了一个证书并将其添加到我的钥匙串中。第一个问题,当我这样做时:

static const uint8_t certificateIdentifier[] = "test.certificate";    
NSData * certificateTag = [NSData dataWithBytes:certificateIdentifier length:sizeof(certificateIdentifier)];
SecCertificateRef cert = SecCertificateCreateWithData(NULL, (__bridge CFDataRef) certificadoData);
NSMutableDictionary *dictionary = [[NSMutableDictionary alloc] init];
[dictionary setObject:(__bridge id)kSecClassCertificate forKey:(__bridge id)kSecClass];
[dictionary setObject:certificateTag forKey:(__bridge id)kSecAttrApplicationTag];
[dictionary setObject:(__bridge id)(cert) forKey:(__bridge id<NSCopying>)(kSecValueRef)];
OSStatus status = SecItemAdd((__bridge CFDictionaryRef)dictionary, NULL);

状态告诉我 mycertificateTag是一个无效参数。如果我不放这个标签,我可以把证书放在我的钥匙串上,然后在方法里面

(void)connection:(NSURLConnection *)connection didReceiveAuthenticationChallenge:(NSURLAuthenticationChallenge *)challenge

我放

SecIdentityRef myIdentity;
SecCertificateRef myCertificate;

NSMutableDictionary * queryCertificate = [[NSMutableDictionary alloc] init];
[queryCertificate setObject:(__bridge id)kSecClassIdentity forKey:(__bridge id)kSecClass];
[queryCertificate setObject:[NSNumber numberWithBool:YES] forKey:(__bridge id)kSecReturnRef];

OSStatus status = SecItemCopyMatching((__bridge CFDictionaryRef)queryCertificate, (CFTypeRef *)&myIdentity);

status = SecIdentityCopyCertificate(myIdentity, &myCertificate);

const void *certs[] = { myCertificate };
CFArrayRef certsArray = CFArrayCreate(NULL, certs, 1, NULL);
NSURLCredential *credential = [NSURLCredential credentialWithIdentity:myIdentity certificates:(__bridge NSArray*)certsArray persistence:NSURLCredentialPersistencePermanent];

[[challenge sender] useCredential:credential forAuthenticationChallenge:challenge];

我得到了正确的身份和证书,但凭证一直没有返回任何内容,不是错误,只是空值。知道为什么吗?

4

1 回答 1

1

在我的问题的第一部分,我试图在 kSecClassCertificate 中添加一个 kSecAttrApplicationTag,但 kSecAttrApplicationTag 只在 kSecClassKey 中被接受。

在第二部分中,凭证(<NSURLCredential: 0x1e20d140>: (null))的结果是正确的,这个“空”并不意味着该值实际上是空的。保持这种方式我的代码工作正常。

于 2013-10-31T16:50:54.190 回答