<p>When connecting to a server which has setup their SSL encryption with a self-signed certificate through a Java or an android app, you’ll get an SSLException since their certificate isn’t signed by a Certificate Authorities (CA) which is a 3rd party who is trusted by everyone.</p> <pre class="giallo" style="color: #657B83; background-color: #FDF6E3;" ><code data-lang="plain"><span class="giallo-l"><span>javax.net.ssl.SSLException: Not trusted server certificate exception</span></span></code></pre> <p>If you have access to the server or know the site admin, get them to buy a CA signed SSL certificate.</p> <p>But in case that is not possible or feasible we can one thing we can do is configure our HTTP client library to just not verify the site hostname with the certificate. But then again that is not a good solution and defeats the whole purpose of encryption.</p> <span id="continue-reading"></span> <p>A more elegant solution is to tell the client library to explicitly trust a certificate. We’ll have to manually get a copy of the site’s self-signed certificate that we can use to tell our client to trust.</p> <p>Java has a couple of HTTP clients, mainly:</p> <ul> <li>Apache HTTP client</li> <li>HttpUrlConnection</li> </ul> <p>You’ll find that when using Apache Http client we’ll have to create a custom SSLSocketFactory to implement the above functionality. And for HttpUrlConnection set a custom SSLSocket to the connection as described at <a rel="noopener nofollow noreferrer external" target="_blank" href="https://developer.android.com/training/articles/security-ssl.html">developer.android.com</a>.</p> <p>Here is a reference implementation that does just that.</p> <div ><script src="https://gist.github.com/shalzz/8125772.js"></script></div> <h4 id="for-httpurlconnection"><a class="zola-anchor" href="#for-httpurlconnection" aria-label="Anchor link for: for-httpurlconnection">🔗</a> For HttpURLConnection</h4> <pre class="giallo" style="color: #657B83; background-color: #FDF6E3;" ><code data-lang="java"><span class="giallo-l"><span style="color: #586E75;font-weight: bold;">MySSLSocketFactory</span><span style="color: #268BD2;"> sslf</span><span style="color: #859900;"> =</span><span style="color: #B58900;"> null</span><span>;</span></span> <span class="giallo-l"><span style="color: #859900;">try</span><span> {</span></span> <span class="giallo-l"><span style="color: #586E75;font-weight: bold;"> KeyStore</span><span style="color: #268BD2;"> ks</span><span style="color: #859900;"> =</span><span style="color: #268BD2;"> MySSLSocketFactory</span><span>.</span><span style="color: #268BD2;">getKeystoreOfCA</span><span>(</span><span style="color: #268BD2;">getResources</span><span>().</span><span style="color: #268BD2;">openRawResource</span><span>(</span><span style="color: #268BD2;">R</span><span>.</span><span style="color: #268BD2;">raw</span><span>.</span><span style="color: #268BD2;">myCert</span><span>));</span></span> <span class="giallo-l"><span> sslf </span><span style="color: #859900;">= new</span><span style="color: #268BD2;"> MySSLSocketFactory</span><span>(ks);</span></span> <span class="giallo-l"><span>}</span><span style="color: #859900;"> catch</span><span> (</span><span style="color: #586E75;font-weight: bold;">Exception</span><span> e) {</span></span> <span class="giallo-l"><span style="color: #268BD2;"> e</span><span>.</span><span style="color: #268BD2;">printStackTrace</span><span>();</span></span> <span class="giallo-l"><span>}</span><span style="color: #859900;"> finally</span><span> {</span></span> <span class="giallo-l"><span style="color: #268BD2;"> sslf</span><span>.</span><span style="color: #268BD2;">fixHttpsURLConnection</span><span>();</span></span> <span class="giallo-l"><span>}</span></span></code></pre> <p>Here we create a <code>Keystore</code> containing our certificate, in this case <code>myCert</code>. Which we then use to get an instance of <code>MySSLSocketFactory</code> and then call its non static <code>fixHttpsURLConnection()</code> method. This sets the SSLSocketFactory created as the default SSLSocketFactory for HttpURLConnection.</p> <h4 id="for-apache-http-client"><a class="zola-anchor" href="#for-apache-http-client" aria-label="Anchor link for: for-apache-http-client">🔗</a> For Apache Http Client</h4> <pre class="giallo" style="color: #657B83; background-color: #FDF6E3;" ><code data-lang="java"><span class="giallo-l"><span style="color: #586E75;font-weight: bold;">MySSLSocketFactory</span><span style="color: #268BD2;"> sslf</span><span style="color: #859900;"> =</span><span style="color: #B58900;"> null</span><span>;</span></span> <span class="giallo-l"><span style="color: #586E75;font-weight: bold;">DefaultHttpClient</span><span style="color: #268BD2;"> client</span><span style="color: #859900;"> =</span><span style="color: #B58900;"> null</span><span> ;</span></span> <span class="giallo-l"><span style="color: #859900;">try</span><span> {</span></span> <span class="giallo-l"><span style="color: #586E75;font-weight: bold;"> KeyStore</span><span style="color: #268BD2;"> ks</span><span style="color: #859900;"> =</span><span style="color: #268BD2;"> MySSLSocketFactory</span><span>.</span><span style="color: #268BD2;">getKeystoreOfCA</span><span>(</span><span style="color: #268BD2;">this</span><span>.</span><span style="color: #268BD2;">getResources</span><span>().</span><span style="color: #268BD2;">openRawResource</span><span>(</span><span style="color: #268BD2;">R</span><span>.</span><span style="color: #268BD2;">raw</span><span>.</span><span style="color: #268BD2;">myCert</span><span>));</span></span> <span class="giallo-l"><span> client </span><span style="color: #859900;">=</span><span style="color: #268BD2;"> MySSLSocketFactory</span><span>.</span><span style="color: #268BD2;">getNewHttpClient</span><span>(ks);</span></span> <span class="giallo-l"><span>}</span><span style="color: #859900;"> catch</span><span> (</span><span style="color: #586E75;font-weight: bold;">Exception</span><span> e) {</span></span> <span class="giallo-l"><span style="color: #268BD2;"> e</span><span>.</span><span style="color: #268BD2;">printStackTrace</span><span>();</span></span> <span class="giallo-l"><span>}</span></span></code></pre> <p>In this case we get a <code>DefaultHttpClient</code> created with the <code>KeyStore</code> containing our Certificates.</p> <blockquote> <p>Originally posted at <a rel="noopener nofollow noreferrer external" target="_blank" href="https://coding-euphoria.blogspot.in/2013/12/custom-sslsocketfactory-that-trusts.html">coding-euphoria.blogspot.in</a><br /> Edited and updated on 20/07/2017</p> </blockquote>Liked this article? Share this with others
Got any questions or comments? Drop me a message on Twitter @shalzzj
Sign up for my newsletter to be the first to know about a new post