java - 连接到需要证书的 Web 服务时出错

标签 java web-services ssl webclient keystore

我正在尝试连接到一家公司的 Web 服务,该公司为我提供了 4 个 .cert 格式的证书,我已将这些证书放入 keystore 中,并在我的客户端代码上建立了 Https 连接

    System.setProperty("javax.net.ssl.trustStore",ERPGetProperty.erpGetProperty("pathToKeyStore"));
    System.setProperty("javax.net.ssl.trustStorePassword", "changeit");
    System.setProperty("javax.net.ssl.trustStoreType", "JKS");
    System.setProperty("javax.net.ssl.keyStore", ERPGetProperty.erpGetProperty("pathToKeyStore"));
    System.setProperty("javax.net.ssl.keyStorePassword", "changeit");
    System.setProperty("javax.net.ssl.keyStoreType", "JKS"); 
    System.setProperty("https.protocols", "TLSv1.2");

    SSLSocketFactory sslSocketFactory  = (SSLSocketFactory) SSLSocketFactory.getDefault();

    URL url = new URL(address);
    HttpsURLConnection con  = (HttpsURLConnection) url.openConnection();

    con.setSSLSocketFactory(sslSocketFactory);  
    con.setRequestMethod("POST");
    con.setUseCaches(true);
    con.setRequestProperty("Content-type", "text/xml");
    con.setRequestProperty("Content-Length", Integer.toString(xml.length()));
    con.setRequestProperty("SOAPAction", address);
    con.setDoOutput(true);
    con.setDoInput(true);

    userPass = username + ":" + password;
    byte[] encodeBytes = Base64.encodeBase64(userPass.getBytes());
    String encode = new String(encodeBytes);
    con.setRequestProperty("Authorization", "Basic " + encode);

    out = con.getOutputStream();

    out.write(b);

我总是遇到这个异常

 10:21:15,591 ERROR [stderr] (DefaultQuartzScheduler_Worker-2) java.net.ConnectException:  Operation timed out

10:21:15,591 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at     java.net.PlainSocketImpl.socketConnect(Native Method)
10:21:15,591 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at java.net.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.java:339)
10:21:15,592 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at java.net.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketImpl.java:200)
10:21:15,592 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:182)
10:21:15,593 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:392)
10:21:15,593 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at java.net.Socket.connect(Socket.java:579)
10:21:15,593 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.security.ssl.SSLSocketImpl.connect(SSLSocketImpl.java:618)
10:21:15,594 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.security.ssl.BaseSSLSocketImpl.connect(BaseSSLSocketImpl.java:160)
10:21:15,594 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.net.NetworkClient.doConnect(NetworkClient.java:180)
10:21:15,594 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.net.www.http.HttpClient.openServer(HttpClient.java:432)
10:21:15,595 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.net.www.http.HttpClient.openServer(HttpClient.java:527)
10:21:15,595 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.net.www.protocol.https.HttpsClient.<init>(HttpsClient.java:275)
10:21:15,595 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.net.www.protocol.https.HttpsClient.New(HttpsClient.java:371)
10:21:15,596 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.getNewHttpClient(AbstractDelegateHttpsURLConnection.java:191)
10:21:15,596 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:932)
10:21:15,596 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:177)
10:21:15,597 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.net.www.protocol.http.HttpURLConnection.getOutputStream(HttpURLConnection.java:1091)
10:21:15,597 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at sun.net.www.protocol.https.HttpsURLConnectionImpl.getOutputStream(HttpsURLConnectionImpl.java:250)
10:21:15,598 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at hot.com.mhd.erp.action.client.PushStatusClient.pushXML(PushStatusClient.java:492)
10:21:15,598 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at main.com.mhd.erp.sched.StatusPushJob.execute(StatusPushJob.java:73)
10:21:15,598 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at org.quartz.core.JobRunShell.run(JobRunShell.java:202)
10:21:15,599 ERROR [stderr] (DefaultQuartzScheduler_Worker-2)   at org.quartz.simpl.SimpleThreadPool$WorkerThread.run(SimpleThreadPool.java:525)

这是我在抛出异常之前从 Debug模式中得到的一些结果

10:21:00,034 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unavailable cipher suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
10:21:00,034 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unavailable cipher suite: TLS_DHE_RSA_WITH_AES_256_CBC_SHA
10:21:00,035 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unavailable cipher suite: TLS_ECDH_RSA_WITH_AES_256_CBC_SHA
10:21:00,035 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_DHE_DSS_WITH_AES_128_CBC_SHA256
10:21:00,036 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_DHE_DSS_WITH_AES_256_CBC_SHA256
10:21:00,036 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
10:21:00,036 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256
10:21:00,036 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
10:21:00,037 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
10:21:00,037 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384
10:21:00,037 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_RSA_WITH_AES_256_CBC_SHA256
10:21:00,037 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unavailable cipher suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
10:21:00,038 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
10:21:00,038 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384
10:21:00,038 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unavailable cipher suite: TLS_DHE_DSS_WITH_AES_256_CBC_SHA
10:21:00,038 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384
10:21:00,039 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256
10:21:00,039 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256
10:21:00,039 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unavailable cipher suite: TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA
10:21:00,039 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unavailable cipher suite: TLS_RSA_WITH_AES_256_CBC_SHA
10:21:00,040 INFO  [stdout] (DefaultQuartzScheduler_Worker-4) Ignoring unsupported cipher suite: TLS_RSA_WITH_AES_128_CBC_SHA256

请帮帮我!我没时间解决这个问题了!谢谢!

最佳答案

  10:21:15,591 ERROR [stderr] (DefaultQuartzScheduler_Worker-2) java.net.ConnectException:  Operation timed out
  10:21:15,591 ERROR [stderr] (DefaultQuartzScheduler_Worker-2) at java.net.PlainSocketImpl.socketConnect(Native Method)

您已经在普通套接字级别获得连接超时。请确保服务器已启动并为来自外部的连接打开,并且您的应用程序和服务器之间没有防火墙阻止访问。尝试使用另一个客户端连接到服务器,以确保问题出在您的应用程序上。

关于java - 连接到需要证书的 Web 服务时出错,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/26634458/

相关文章:

java - 自定义 spring-data 存储库后端

web-services - 通过Yahoo Finance按行业获取股票

xml - 输入/输出元素的名称必须是唯一的(WSDL 规范)

ruby-on-rails - EOFError:文件结尾已到达 Net::HTTP 问题

java - 将 Scala 条件转换为 Java 谓词

java - 我想使用 PHP 开发一个 Android 聊天应用程序。我该怎么做?不使用 Google Firebase Cloud Messeging 和 AWS

java - SSLSocket如何像Socket.sendUrgentData()一样发心连接

iPhone SSL 网站证书警告

ssl - 使用 2 路 SSL 的 Weblogic(10.3) 中的 Web 服务客户端 (JAX-WS) 无法完成握手

java - 无法将我的 DefaultListModel 分配给 Java NetBeans 中的 JList