0

我们正在尝试在客户端和服务器之间进行安全的 http 通信。

服务器提供证书,我们获取它们,安装它们并开始运行,关键是在客户端和服务器之间同时交换确切数量的消息,让我们发疯的问题是请求之间,在SSLHANDSHAKE我们随机获取异常javax.net.ssl.SSLException: Received fatal alert: unexpected_message恰好在ServerHello握手阶段,我不知道它是如何或为什么会发生的,而它对 98% 的其他请求保持正常工作。

在此处输入图像描述

它在第 2 步崩溃。

Transporter.java:这是负责发送和接收数据的类。

        import java.io.BufferedReader;

        import java.io.File;
        import java.io.FileInputStream;
        import java.io.IOException;
        import java.io.InputStream;
        import java.io.InputStreamReader;
        import java.io.OutputStream;

        import java.net.MalformedURLException;
        import java.net.ProtocolException;
        import java.net.URL;
        import java.security.KeyStore;
        import java.util.ResourceBundle;
        import javax.net.ssl.HostnameVerifier;
        import javax.net.ssl.HttpsURLConnection;
        import javax.net.ssl.KeyManager;
        import javax.net.ssl.KeyManagerFactory;
        import javax.net.ssl.SSLContext;
        import javax.net.ssl.SSLSession;
        import javax.net.ssl.SSLSocketFactory;
        import javax.net.ssl.TrustManager;
        import javax.net.ssl.TrustManagerFactory;

        public class Transporter {

            private static ResourceBundle resource = ResourceBundle.getBundle("resourece_00");
            private static final String keystore = resource.getString("server_keystore");
            private static final String truststore = resource.getString("server_truststore");
            private static final String keypass = resource.getString("server_keystore_pwd");
            private static final String trustpass = resource.getString("server_truststore_pwd");

            // secure channel variables
            private static SSLSocketFactory sslSocketFactory = null;

            public Transporter() {
                // setupSocketFactory();
            }

            static {
                try {
                    String protocol = "TLS";
                    String type = "JKS";

                    String algorithm = KeyManagerFactory.getDefaultAlgorithm();
                    String trustAlgorithm = TrustManagerFactory.getDefaultAlgorithm();

                    // create and initialize an SSLContext object
                    SSLContext sslContext = SSLContext.getInstance(protocol);
                    sslContext.init(getKeyManagers(type, algorithm), getTrustManagers(type, trustAlgorithm), null);

                    // obtain the SSLSocketFactory from the SSLContext
                    sslSocketFactory = sslContext.getSocketFactory();

                } catch (Exception e) {
                    e.printStackTrace();
                }
            }

            private static KeyStore getStore(String type, String filename, String pwd) throws Exception {

                KeyStore ks = KeyStore.getInstance(type);
                InputStream istream = null;

                try {

                    File ksfile = new File(filename);
                    istream = new FileInputStream(ksfile);
                    ks.load(istream, pwd != null ? pwd.toCharArray() : null);
                } finally {
                    if (istream != null) {
                        istream.close();
                    }
                }

                return ks;
            }

            private static KeyManager[] getKeyManagers(String type, String algorithm) throws Exception {
                KeyStore ks = getStore(type, keystore, keypass);
                KeyManagerFactory kmf = KeyManagerFactory.getInstance(algorithm);
                kmf.init(ks, keypass.toCharArray());
                return kmf.getKeyManagers();
            }

            private static TrustManager[] getTrustManagers(String type, String algorithm) throws Exception {
                KeyStore ts = getStore(type, truststore, trustpass);
                TrustManagerFactory tmf = TrustManagerFactory.getInstance(algorithm);
                tmf.init(ts);
                return tmf.getTrustManagers();

            }

            public String sendToVD(String msg, String urll, Long timeOut) {

                byte[] bytes = msg.getBytes();
                HttpsURLConnection sconn = null;
                URL url = null;
                OutputStream out = null;
                BufferedReader read = null;
                String recu = null;

                try {

                    url = new URL(urll);
                    sconn = (HttpsURLConnection) url.openConnection();
                    sconn.setHostnameVerifier(new HostnameVerifier() {

                        public boolean verify(String hostname, SSLSession sslSession) {

                            return true;
                        }
                    });
                    sconn.setSSLSocketFactory(sslSocketFactory);
                    // sconn.setReadTimeout((timeOut.intValue()) * 1000);// set timeout
                    sconn.setRequestMethod("POST");
                    sconn.addRequestProperty("Content-Length", "" + bytes.length);
                    sconn.setRequestProperty("Content-Type", "application/xml; charset=utf-8");
                    sconn.setDoOutput(true);
                    sconn.setDoInput(true);
                    // send POST data
                    // This is the crash location
                    out = sconn.getOutputStream();
                    // OutputStreamWriter osw = new OutputStreamWriter(out, "UTF-8");
                    out.write(bytes);
                    out.flush();
                    // logger.info("flush!!!!!!!!!!!!!");
                    // out.close();
                    read = new BufferedReader(new InputStreamReader(sconn.getInputStream()));
                    String query = null;
                    recu = read.readLine();
                    while ((query = read.readLine()) != null) {
                        recu += query;
                    }
                } catch (MalformedURLException e) {
                    e.printStackTrace();
                } catch (ProtocolException e) {
                    e.printStackTrace();
                } catch (IOException e) {
                    e.printStackTrace();
                } finally {
                    try {
                        // close all connections here
                        if (out != null)
                            out.close();

                        if (read != null)
                            read.close();

                        if (sconn != null)
                            sconn.disconnect();
                    } catch (Exception ce) {

                    }
                }
                return recu;
            }
        }

函数sendToVD()完成客户端服务器之间交换的主要工作。

客户端:一个 Web 应用程序,JSF管理前端,spring 管理 bean 生命周期,与客户端的通信入口由Servlets保证。

客户端部署在RedHat Linux机器中,所有TLS_VERSIONS都已启用,JDK_8

服务器端:我无法发布有关安全措施的目标 URL 的详细信息,但它遵循以下模式https://ip:port/path,并且它支持TLS_v1.2

希望你能帮助我。

4

0 回答 0