我想使用iOS中代码附带的自签名证书创建到我的服务器的SSL连接.这样我就不必担心更复杂的中间人攻击,其中有人可以访问高级“可信”的证书颁发机构.使用我认为是Apple的标准方式,我遇到了问题.
# Create root CA & private key openssl req -newkey rsa:4096 -sha512 -days 9999 -x509 -nodes -out root.pem.cer # Create a certificate signing request openssl req -newkey rsa:4096 -sha512 -nodes -out ssl.csr -keyout ssl.key # Create an OpenSSL Configuration file from http://svasey.org/projects/software-usage-notes/ssl_en.html vim openssl.conf # Create the indexes touch certindex echo 000a > certserial echo 000a > crlnumber # Generate SSL certificate openssl ca -batch -config openssl.conf -notext -in ssl.csr -out ssl.pem.cer # Create Certificate Revocation List openssl ca -config openssl.conf -gencrl -keyfile privkey.pem -cert root.pem.cer -out root.crl.pem openssl crl -inform PEM -in root.crl.pem -outform DER -out root.crl && rm root.crl.pem
和iOS代码:
- (void)connection:(NSURLConnection *)connection willSendRequestForAuthenticationChallenge:(NSURLAuthenticationChallenge *)challenge { NSURLProtectionSpace *protectionSpace = [challenge protectionSpace]; if ([protectionSpace authenticationMethod] == NSURLAuthenticationMethodServerTrust) { // Load anchor cert.. also tried this with both certs and it doesn't seem to matter NSString *path = [[NSBundle mainBundle] pathForResource:@"root.der" ofType:@"crt"]; NSData *data = [[NSData alloc] initWithContentsOfFile:path]; SecCertificateRef anchorCert = SecCertificateCreateWithData(kcfAllocatorDefault,(__bridge CFDataRef)data); CFMutableArrayRef anchorCerts = CFArrayCreateMutable(kcfAllocatorDefault,&kcfTypeArrayCallBacks); CFArrayAppendValue(anchorCerts,anchorCert); // Set anchor cert SecTrustRef trust = [protectionSpace serverTrust]; SecTrustSetAnchorCertificates(trust,anchorCerts); SecTrustSetAnchorCertificatesOnly(trust,YES); // only use that certificate CFRelease(anchorCert); CFRelease(anchorCerts); // Validate cert SecTrustResultType secresult = kSecTrustResultInvalid; if (SecTrustEvaluate(trust,&secresult) != errSecSuccess) { [challenge.sender cancelAuthenticationChallenge:challenge]; return; } switch (secresult) { case kSecTrustResultInvalid: case kSecTrustResultDeny: case kSecTrustResultFatalTrustFailure: case kSecTrustResultOtherError: case kSecTrustResultRecoverableTrustFailure: { // !!! It's always kSecTrustResultRecoverableTrustFailure,aka 5 NSLog(@"Failing due to result: %lu",secresult); [challenge.sender cancelAuthenticationChallenge:challenge]; return; } case kSecTrustResultUnspecified: // The OS trusts this certificate implicitly. case kSecTrustResultProceed: { // The user explicitly told the OS to trust it. NSURLCredential *credential = [NSURLCredential credentialForTrust:trust]; [challenge.sender useCredential:credential forAuthenticationChallenge:challenge]; return; } default: ; /* It's somebody else's key. Fall through. */ } /* The server sent a key other than the trusted key. */ [connection cancel]; // Perform other cleanup here,as needed. } else { NSLog(@"In weird space... not handling authentication method: %@",[protectionSpace authenticationMethod]); [connection cancel]; } }
我总是得到kSecTrustResultRecoverableTrustFailure作为结果.我不认为这是localhost问题,因为我已经尝试使用Apple的代码来改变它.该怎么办?
谢谢!
解决方法
如果信任结果是kSecTrustResultRecoverableTrustFailure,您可能能够从失败中恢复.
这是解决方法.