

源代码1 项目: buddycloud-android   文件: TLSSNISocketFactory.java
public Socket createSocket(Socket s, String host, int port, boolean autoClose) throws IOException {
    SSLSocket ssl = (SSLSocket)sslSocketFactory.createSocket(s, host, port, autoClose);

    // set SNI before the handshake
        Logger.info(TAG, "Setting SNI hostname");
        sslSocketFactory.setHostname(ssl, host);
    } else {
    	Logger.warn(TAG, "No SNI support below Android 4.2!");

    // now do the TLS handshake
    SSLSession session = ssl.getSession();
    if (session == null)
    throw new SSLException("Cannot verify SSL socket without session");

    // verify host name (important!)
    if (!HttpsURLConnection.getDefaultHostnameVerifier().verify(host, session))
    throw new SSLPeerUnverifiedException("Cannot verify hostname: " + host);
    return ssl;
源代码2 项目: wildfly-camel   文件: Application.java
public CxfRsEndpoint createCxfProducerEndpointRel() {
    CxfRsEndpoint cxfProducerEndpoint = this.camelContext.getEndpoint("cxfrs:" + CXF_ENDPOINT_REL_BASE_URI, CxfRsEndpoint.class);

    // Not for use in production
    HostnameVerifier hostnameVerifier = new HostnameVerifier() {
        public boolean verify(String hostname, SSLSession session) {
            return true;

    return cxfProducerEndpoint;
源代码3 项目: YCWebView   文件: WebViewCacheWrapper.java
 * 创建okhttp,主要是用它进行缓存
private void initHttpClient() {
    final Cache cache = new Cache(mCacheFile, mCacheSize);
    OkHttpClient.Builder builder = new OkHttpClient.Builder()
            .connectTimeout(mConnectTimeout, TimeUnit.SECONDS)
            .readTimeout(mReadTimeout, TimeUnit.SECONDS)
            .addNetworkInterceptor(new HttpCacheInterceptor());
    if (mTrustAllHostname) {
        builder.hostnameVerifier(new HostnameVerifier() {
            public boolean verify(String hostname, SSLSession session) {
                return true;
    if (mSSLSocketFactory != null && mX509TrustManager != null) {
        builder.sslSocketFactory(mSSLSocketFactory, mX509TrustManager);
    mHttpClient = builder.build();
源代码4 项目: AndroidHttpCapture   文件: SslUtil.java
 * Returns the X509Certificate for the server this session is connected to. The certificate may be null.
 * @param sslSession SSL session connected to upstream server
 * @return the X.509 certificate from the upstream server, or null if no certificate is available
public static X509Certificate getServerCertificate(SSLSession sslSession) {
    Certificate[] peerCertificates;
    try {
        peerCertificates = sslSession.getPeerCertificates();
    } catch (SSLPeerUnverifiedException e) {
        peerCertificates = null;

    if (peerCertificates != null && peerCertificates.length > 0) {
        Certificate peerCertificate = peerCertificates[0];
        if (peerCertificate != null && peerCertificate instanceof X509Certificate) {
            return (X509Certificate) peerCertificates[0];

    // no X.509 certificate was found for this server
    return null;
源代码5 项目: spring-analysis-note   文件: DefaultSslInfo.java
private static String initSessionId(SSLSession session) {
	byte [] bytes = session.getId();
	if (bytes == null) {
		return null;

	StringBuilder sb = new StringBuilder();
	for (byte b : bytes) {
		String digit = Integer.toHexString(b);
		if (digit.length() < 2) {
		if (digit.length() > 2) {
			digit = digit.substring(digit.length() - 2);
	return sb.toString();
源代码6 项目: java-technology-stack   文件: DefaultSslInfo.java
private static X509Certificate[] initCertificates(SSLSession session) {
	Certificate[] certificates;
	try {
		certificates = session.getPeerCertificates();
	catch (Throwable ex) {
		return null;

	List<X509Certificate> result = new ArrayList<>(certificates.length);
	for (Certificate certificate : certificates) {
		if (certificate instanceof X509Certificate) {
			result.add((X509Certificate) certificate);
	return (!result.isEmpty() ? result.toArray(new X509Certificate[0]) : null);
public SSLEngine clientSslEngineFor(HttpRequest httpRequest, SSLSession serverSslSession) {
    try {
        X509Certificate upstreamCert = getCertificateFromSession(serverSslSession);
        // TODO store the upstream cert by commonName to review it later

        // A reasons to not use the common name and the alternative names
        // from upstream certificate from serverSslSession to create the
        // dynamic certificate:
        // It's not necessary. The host name is accepted by the browser.
        String commonName = getCommonName(upstreamCert);

        SubjectAlternativeNameHolder san = new SubjectAlternativeNameHolder();


        LOG.debug("Subject Alternative Names: {}", san);
        return sslEngineSource.createCertForHost(commonName, san);

    } catch (Exception e) {
        throw new FakeCertificateException(
                "Creation dynamic certificate failed", e);
源代码8 项目: pgadba   文件: ClientTlsChannel.java
private ClientTlsChannel(
    ByteChannel underlying,
    SSLEngine engine,
    Consumer<SSLSession> sessionInitCallback,
    boolean runTasks,
    BufferAllocator plainBufAllocator,
    BufferAllocator encryptedBufAllocator,
    boolean releaseBuffers,
    boolean waitForCloseNotifyOnClose) {
  if (!engine.getUseClientMode()) {
    throw new IllegalArgumentException("SSLEngine must be in client mode");
  this.underlying = underlying;
  TrackingAllocator trackingPlainBufAllocator = new TrackingAllocator(plainBufAllocator);
  TrackingAllocator trackingEncryptedAllocator = new TrackingAllocator(encryptedBufAllocator);
  impl = new TlsChannelImpl(underlying, underlying, engine, Optional.empty(), sessionInitCallback, runTasks,
      trackingPlainBufAllocator, trackingEncryptedAllocator, releaseBuffers, waitForCloseNotifyOnClose);
源代码9 项目: CapturePacket   文件: SslUtil.java
 * Returns the X509Certificate for the server this session is connected to. The certificate may be null.
 * @param sslSession SSL session connected to upstream server
 * @return the X.509 certificate from the upstream server, or null if no certificate is available
public static X509Certificate getServerCertificate(SSLSession sslSession) {
    Certificate[] peerCertificates;
    try {
        peerCertificates = sslSession.getPeerCertificates();
    } catch (SSLPeerUnverifiedException e) {
        peerCertificates = null;

    if (peerCertificates != null && peerCertificates.length > 0) {
        Certificate peerCertificate = peerCertificates[0];
        if (peerCertificate != null && peerCertificate instanceof X509Certificate) {
            return (X509Certificate) peerCertificates[0];

    // no X.509 certificate was found for this server
    return null;
源代码10 项目: athenz   文件: ProviderHostnameVerifierTest.java
public void testHostnameVerifier() throws IOException {
    SSLSession session = Mockito.mock(SSLSession.class);
    Path path = Paths.get("src/test/resources/athenz.instanceid.pem");
    String pem = new String(Files.readAllBytes(path));
    X509Certificate cert = Crypto.loadX509Certificate(pem);
    Certificate[] certs = new Certificate[1];
    certs[0] = cert;
    ProviderHostnameVerifier verifier1 = new ProviderHostnameVerifier("athenz.production");
    assertTrue(verifier1.verify("athenz", session));
    ProviderHostnameVerifier verifier2 = new ProviderHostnameVerifier("athenz.production2");
    assertFalse(verifier2.verify("athenz", session));
private String initSessionId(SSLSession session) {
    byte [] bytes = session.getId();
    if (bytes == null) {
        return null;

    StringBuilder sb = new StringBuilder();
    for (byte b : bytes) {
        String digit = Integer.toHexString(b);
        if (digit.length() < 2) {
        if (digit.length() > 2) {
            digit = digit.substring(digit.length() - 2);
    return sb.toString();
private HostnameVerifier getFriendlyToAllHostnameVerifier() {
    final HostnameVerifier hv = new HostnameVerifier() {
        public boolean verify(final String hostname, final SSLSession session) { return true; }
    return hv;
源代码13 项目: TencentKona-8   文件: X509TrustManagerImpl.java
static void checkIdentity(SSLSession session,
        X509Certificate [] trustedChain,
        String algorithm,
        boolean checkClientTrusted) throws CertificateException {

    boolean identifiable = false;
    String peerHost = session.getPeerHost();
    if (!checkClientTrusted) {
        List<SNIServerName> sniNames = getRequestedServerNames(session);
        String sniHostName = getHostNameInSNI(sniNames);
        if (sniHostName != null) {
            try {
                        trustedChain[0], algorithm);
                identifiable = true;
            } catch (CertificateException ce) {
                if (sniHostName.equalsIgnoreCase(peerHost)) {
                    throw ce;

                // otherwisw, failover to check peer host

    if (!identifiable) {
                trustedChain[0], algorithm);
private static Principal getPeerPrincipal(SSLSession session)
        throws SSLPeerUnverifiedException {
    Principal principal;
    try {
        principal = session.getPeerPrincipal();
    } catch (AbstractMethodError e) {
        // if the JSSE provider does not support it, return null, since
        // we need it only for Kerberos.
        principal = null;
    return principal;
源代码15 项目: nomulus   文件: SslInitializerTestUtils.java
 * Verifies tha the SSL channel is established as expected, and also sends a message to the server
 * and verifies if it is echoed back correctly.
 * @param certs The certificate that the server should provide.
 * @return The SSL session in current channel, can be used for further validation.
static SSLSession setUpSslChannel(Channel channel, X509Certificate... certs) throws Exception {
  SslHandler sslHandler = channel.pipeline().get(SslHandler.class);
  // Wait till the handshake is complete.

  // Returns the SSL session for further assertion.
  return sslHandler.engine().getSession();
源代码16 项目: AndServer   文件: ProxyHandler.java
private Socket createSocket(HttpHost host) throws IOException {
    Socket socket = new Socket();
    socket.setSoTimeout(60 * 1000);
    socket.setSoLinger(true, 0);

    String scheme = host.getSchemeName();
    String hostName = host.getHostName();
    int port = host.getPort();

    InetSocketAddress address = resolveAddress(scheme, hostName, port);
    socket.connect(address, 10 * 1000);

    if ("https".equalsIgnoreCase(scheme)) {
        SSLSocket sslSocket = (SSLSocket) mSocketFactory.createSocket(socket, hostName, port, true);
        try {
            final SSLSession session = sslSocket.getSession();
            if (session == null) {
                throw new SSLHandshakeException("SSL session not available.");
        } catch (final IOException ex) {
            throw ex;
        return sslSocket;
    return socket;
public void handle(Client client, HttpServerRequest request, Handler<AsyncResult<Client>> handler) {
    // We ensure that the authentication is done over TLS thanks to the canHandle method which checks for an SSL
    // session
    SSLSession sslSession = request.sslSession();

    try {
        Certificate[] peerCertificates = sslSession.getPeerCertificates();
        X509Certificate peerCertificate = (X509Certificate) peerCertificates[0];
        String thumbprint = getThumbprint(peerCertificate, "SHA-1");
        String thumbprint256 = getThumbprint(peerCertificate, "SHA-256");
                        jwkSet -> {
                            boolean match = jwkSet.getKeys()
                                    .anyMatch(jwk -> thumbprint256.equals(jwk.getX5tS256()) || thumbprint.equals(jwk.getX5t()));
                            if (match) {
                            } else {
                                handler.handle(Future.failedFuture(new InvalidClientException("Invalid client: invalid self-signed certificate")));
                        throwable -> handler.handle(Future.failedFuture(new InvalidClientException("Invalid client: invalid self-signed certificate"))),
                        () -> handler.handle(Future.failedFuture(new InvalidClientException("Invalid client: missing or unsupported JWK Set"))));
    } catch (Exception ex) {
        handler.handle(Future.failedFuture(new InvalidClientException("Invalid client: missing or unsupported self-signed certificate")));
protected SslInfo initSslInfo() {
	SSLSession session = this.exchange.getConnection().getSslSession();
	if (session != null) {
		return new DefaultSslInfo(session);
	return null;
源代码19 项目: jdk8u_jdk   文件: CookieHttpsClientTest.java
void doClientSide() throws Exception {
    // Wait for server to get started.
    while (!serverReady) {

    HttpsURLConnection.setDefaultHostnameVerifier(new HostnameVerifier() {
        public boolean verify(String hostname, SSLSession session) {
            return true;

    URL url = new URL("https://localhost:" + serverPort +"/");

    // Run without a CookieHandler first
    InputStream in = url.openConnection().getInputStream();
    while (in.read() != -1);  // read response body so connection can be reused

    // Set a CookeHandler and retest using the HttpClient from the KAC
    CookieManager manager = new CookieManager(null, CookiePolicy.ACCEPT_ALL);

    in = url.openConnection().getInputStream();
    while (in.read() != -1);

    if (manager.getCookieStore().getCookies().isEmpty()) {
        throw new RuntimeException("Failed: No cookies in the cookie Handler.");
源代码20 项目: Dream-Catcher   文件: ImpersonatingMitmManager.java
 * Creates an SSLContext that will present an impersonated certificate for the specified hostname to the client.
 * This is a convenience method for {@link #createImpersonatingSslContext(CertificateInfo)} that generates the
 * {@link CertificateInfo} from the specified hostname using the {@link #certificateInfoGenerator}.
 * @param sslSession sslSession between the proxy and the upstream server
 * @param hostnameToImpersonate hostname (supplied by the client's HTTP CONNECT) that will be impersonated
 * @return an SSLContext presenting a certificate matching the hostnameToImpersonate
private SslContext createImpersonatingSslContext(SSLSession sslSession, String hostnameToImpersonate) {
    // get the upstream server's certificate so the certificateInfoGenerator can (optionally) use it to construct a forged certificate
    X509Certificate originalCertificate = SslUtil.getServerCertificate(sslSession);

    // get the CertificateInfo that will be used to populate the impersonated X509Certificate
    CertificateInfo certificateInfo = certificateInfoGenerator.generate(Collections.singletonList(hostnameToImpersonate), originalCertificate);

    SslContext sslContext = createImpersonatingSslContext(certificateInfo);

    return sslContext;
源代码21 项目: jdk8u-dev-jdk   文件: X509TrustManagerImpl.java
static List<SNIServerName> getRequestedServerNames(SSLEngine engine) {
    if (engine != null) {
        SSLSession session = engine.getHandshakeSession();

        if (session != null && (session instanceof ExtendedSSLSession)) {
            ExtendedSSLSession extSession = (ExtendedSSLSession)session;
            return extSession.getRequestedServerNames();

    return Collections.<SNIServerName>emptyList();
 * Gets a {@link TenantObjectWithAuthId} from the X509 certificate of the given {@link SSLSession}.
 * @param sslSession The SSL session.
 * @param spanContext The OpenTracing context to use for tracking the operation (may be {@code null}).
 * @return A future indicating the outcome of the operation.
 * @throws NullPointerException if sslSession is {@code null}.
protected final Future<TenantObjectWithAuthId> getFromClientCertificate(final SSLSession sslSession,
        final SpanContext spanContext) {
    final X509Certificate deviceCert = getX509Cert(sslSession);
    if (deviceCert == null) {
        return Future.failedFuture("no cert found");
    return getFromClientCertificate(deviceCert, spanContext);
protected HttpActivityExecutor createHttpActivityExecutor() {
    HttpClientConfig config = CommandContextUtil.getCmmnEngineConfiguration().getHttpClientConfig();
    HttpClientBuilder httpClientBuilder = HttpClientBuilder.create();

    // https settings
    if (config.isDisableCertVerify()) {
        try {
            SSLContextBuilder builder = new SSLContextBuilder();
            builder.loadTrustMaterial(null, new TrustSelfSignedStrategy());
                    new SSLConnectionSocketFactory(builder.build(), new HostnameVerifier() {
                        public boolean verify(String s, SSLSession sslSession) {
                            return true;

        } catch (Exception e) {
            LOGGER.error("Could not configure HTTP client SSL self signed strategy", e);

    // request retry settings
    int retryCount = 0;
    if (config.getRequestRetryLimit() > 0) {
        retryCount = config.getRequestRetryLimit();
    httpClientBuilder.setRetryHandler(new DefaultHttpRequestRetryHandler(retryCount, false));

    // client builder settings
    if (config.isUseSystemProperties()) {

    return new HttpActivityExecutor(httpClientBuilder, new NopErrorPropagator(),
源代码24 项目: jdk8u60   文件: StartTlsResponseImpl.java
private static Principal getPeerPrincipal(SSLSession session)
        throws SSLPeerUnverifiedException {
    Principal principal;
    try {
        principal = session.getPeerPrincipal();
    } catch (AbstractMethodError e) {
        // if the JSSE provider does not support it, return null, since
        // we need it only for Kerberos.
        principal = null;
    return principal;
private X509Certificate getCertificateFromSession(SSLSession sslSession)
        throws SSLPeerUnverifiedException {
    Certificate[] peerCerts = sslSession.getPeerCertificates();
    Certificate peerCert = peerCerts[0];
    if (peerCert instanceof X509Certificate) {
        return (X509Certificate) peerCert;
    throw new IllegalStateException(
            "Required java.security.cert.X509Certificate, found: "
                    + peerCert);
源代码26 项目: ignite   文件: GridCommonAbstractTest.java
/** {@inheritDoc} */
@Override protected void beforeTest() throws Exception {
    // Disable SSL hostname verifier.
    HttpsURLConnection.setDefaultHostnameVerifier(new HostnameVerifier() {
        @Override public boolean verify(String s, SSLSession sslSes) {
            return true;

源代码27 项目: tls-channel   文件: ClientTlsChannel.java
private ClientTlsChannel(
    ByteChannel underlying,
    SSLEngine engine,
    Consumer<SSLSession> sessionInitCallback,
    boolean runTasks,
    BufferAllocator plainBufAllocator,
    BufferAllocator encryptedBufAllocator,
    boolean releaseBuffers,
    boolean waitForCloseNotifyOnClose) {
  if (!engine.getUseClientMode())
    throw new IllegalArgumentException("SSLEngine must be in client mode");
  this.underlying = underlying;
  TrackingAllocator trackingPlainBufAllocator = new TrackingAllocator(plainBufAllocator);
  TrackingAllocator trackingEncryptedAllocator = new TrackingAllocator(encryptedBufAllocator);
  impl =
      new TlsChannelImpl(
源代码28 项目: keycloak   文件: VertxClientCertificateLookup.java
public X509Certificate[] getCertificateChain(HttpRequest httpRequest) {
    Instance<RoutingContext> instances = CDI.current().select(RoutingContext.class);

    if (instances.isResolvable()) {
        RoutingContext context = instances.get();

        try {
            SSLSession sslSession = context.request().sslSession();
            if (sslSession == null) {
                return null;
            X509Certificate[] certificates = (X509Certificate[]) sslSession.getPeerCertificates();

            if (logger.isTraceEnabled() && certificates != null) {
                for (X509Certificate cert : certificates) {
                    logger.tracef("Certificate's SubjectDN => \"%s\"", cert.getSubjectDN().getName());

            return certificates;
        } catch (SSLPeerUnverifiedException ignore) {
            // client not authenticated

    return null;
源代码29 项目: hottub   文件: SSLSessionContextImpl.java
boolean isTimedout(SSLSession sess) {
    if (timeout == 0) {
        return false;

    if ((sess != null) && ((sess.getCreationTime() + timeout * 1000L)
                                    <= (System.currentTimeMillis()))) {
        return true;

    return false;
源代码30 项目: openjdk-8-source   文件: X509TrustManagerImpl.java
static List<SNIServerName> getRequestedServerNames(SSLEngine engine) {
    if (engine != null) {
        SSLSession session = engine.getHandshakeSession();

        if (session != null && (session instanceof ExtendedSSLSession)) {
            ExtendedSSLSession extSession = (ExtendedSSLSession)session;
            return extSession.getRequestedServerNames();

    return Collections.<SNIServerName>emptyList();