📄 configurablex509trustmanager.html
字号:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head><meta http-equiv="content-type" content="text/html; charset=UTF-8" /><title>ConfigurableX509TrustManager xref</title><link type="text/css" rel="stylesheet" href="../../../stylesheet.css" /></head><body><div id="overview"><a href="../../../../apidocs/org/archive/httpclient/ConfigurableX509TrustManager.html">View Javadoc</a></div><pre><a name="1" href="#1">1</a> <em class="comment">/*<em class="comment"> ConfigurableX509TrustManager</em></em><a name="2" href="#2">2</a> <em class="comment"> *</em><a name="3" href="#3">3</a> <em class="comment"> * Created on Feb 18, 2004</em><a name="4" href="#4">4</a> <em class="comment"> *</em><a name="5" href="#5">5</a> <em class="comment"> * Copyright (C) 2004 Internet Archive.</em><a name="6" href="#6">6</a> <em class="comment"> *</em><a name="7" href="#7">7</a> <em class="comment"> * This file is part of the Heritrix web crawler (crawler.archive.org).</em><a name="8" href="#8">8</a> <em class="comment"> *</em><a name="9" href="#9">9</a> <em class="comment"> * Heritrix is free software; you can redistribute it and/or modify</em><a name="10" href="#10">10</a> <em class="comment"> * it under the terms of the GNU Lesser Public License as published by</em><a name="11" href="#11">11</a> <em class="comment"> * the Free Software Foundation; either version 2.1 of the License, or</em><a name="12" href="#12">12</a> <em class="comment"> * any later version.</em><a name="13" href="#13">13</a> <em class="comment"> *</em><a name="14" href="#14">14</a> <em class="comment"> * Heritrix is distributed in the hope that it will be useful,</em><a name="15" href="#15">15</a> <em class="comment"> * but WITHOUT ANY WARRANTY; without even the implied warranty of</em><a name="16" href="#16">16</a> <em class="comment"> * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the</em><a name="17" href="#17">17</a> <em class="comment"> * GNU Lesser Public License for more details.</em><a name="18" href="#18">18</a> <em class="comment"> *</em><a name="19" href="#19">19</a> <em class="comment"> * You should have received a copy of the GNU Lesser Public License</em><a name="20" href="#20">20</a> <em class="comment"> * along with Heritrix; if not, write to the Free Software</em><a name="21" href="#21">21</a> <em class="comment"> * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA</em><a name="22" href="#22">22</a> <em class="comment"> */</em><a name="23" href="#23">23</a> <strong>package</strong> <a href="../../../org/archive/httpclient/package-summary.html">org.archive.httpclient</a>;<a name="24" href="#24">24</a> <a name="25" href="#25">25</a> <strong>import</strong> java.security.KeyStore;<a name="26" href="#26">26</a> <strong>import</strong> java.security.KeyStoreException;<a name="27" href="#27">27</a> <strong>import</strong> java.security.NoSuchAlgorithmException;<a name="28" href="#28">28</a> <strong>import</strong> java.security.cert.CertificateException;<a name="29" href="#29">29</a> <strong>import</strong> java.security.cert.X509Certificate;<a name="30" href="#30">30</a> <strong>import</strong> java.util.Arrays;<a name="31" href="#31">31</a> <strong>import</strong> java.util.List;<a name="32" href="#32">32</a> <strong>import</strong> java.util.logging.Logger;<a name="33" href="#33">33</a> <a name="34" href="#34">34</a> <strong>import</strong> javax.net.ssl.TrustManager;<a name="35" href="#35">35</a> <strong>import</strong> javax.net.ssl.TrustManagerFactory;<a name="36" href="#36">36</a> <strong>import</strong> javax.net.ssl.X509TrustManager;<a name="37" href="#37">37</a> <a name="38" href="#38">38</a> <em>/**<em>*</em></em><a name="39" href="#39">39</a> <em> * A configurable trust manager built on X509TrustManager.</em><a name="40" href="#40">40</a> <em> *</em><a name="41" href="#41">41</a> <em> * If set to 'open' trust, the default, will get us into sites for whom we do</em><a name="42" href="#42">42</a> <em> * not have the CA or any of intermediary CAs that go to make up the cert chain</em><a name="43" href="#43">43</a> <em> * of trust. Will also get us past selfsigned and expired certs. 'loose'</em><a name="44" href="#44">44</a> <em> * trust will get us into sites w/ valid certs even if they are just</em><a name="45" href="#45">45</a> <em> * selfsigned. 'normal' is any valid cert not including selfsigned. 'strict'</em><a name="46" href="#46">46</a> <em> * means cert must be valid and the cert DN must match server name.</em><a name="47" href="#47">47</a> <em> *</em><a name="48" href="#48">48</a> <em> * <p>Based on pointers in</em><a name="49" href="#49">49</a> <em> * <a href="<a href="http://jakarta.apache.org/commons/httpclient/sslguide.html" target="alexandria_uri">http://jakarta.apache.org/commons/httpclient/sslguide.html</a>">SSL</em><a name="50" href="#50">50</a> <em> * Guide</a>,</em><a name="51" href="#51">51</a> <em> * and readings done in <a</em><a name="52" href="#52">52</a> <em> * href="<a href="http://java.sun.com/j2se/1.4.2/docs/guide/security/jsse/JSSERefGuide.html" target="alexandria_uri">http://java.sun.com/j2se/1.4.2/docs/guide/security/jsse/JSSERefGuide.html</a>#Introduction">JSSE</em><a name="53" href="#53">53</a> <em> * Guide</a>.</em><a name="54" href="#54">54</a> <em> *</em><a name="55" href="#55">55</a> <em> * <p>TODO: Move to an ssl subpackage when we have other classes other than</em><a name="56" href="#56">56</a> <em> * just this one.</em><a name="57" href="#57">57</a> <em> *</em><a name="58" href="#58">58</a> <em> * @author stack</em><a name="59" href="#59">59</a> <em> * @version $Id: ConfigurableX509TrustManager.java,v 1.6 2006/05/15 21:52:30 stack-sf Exp $</em><a name="60" href="#60">60</a> <em> */</em><a name="61" href="#61">61</a> <strong>public</strong> <strong>class</strong> ConfigurableX509TrustManager implements X509TrustManager<a name="62" href="#62">62</a> {<a name="63" href="#63">63</a> <em>/**<em>*</em></em><a name="64" href="#64">64</a> <em> * Logging instance.</em><a name="65" href="#65">65</a> <em> */</em><a name="66" href="#66">66</a> <strong>protected</strong> <strong>static</strong> Logger logger = Logger.getLogger(<a name="67" href="#67">67</a> <span class="string">"org.archive.httpclient.ConfigurableX509TrustManager"</span>);<a name="68" href="#68">68</a> <a name="69" href="#69">69</a> <em>/**<em>*</em></em><a name="70" href="#70">70</a> <em> * Trust anything given us.</em><a name="71" href="#71">71</a> <em> *</em><a name="72" href="#72">72</a> <em> * Default setting.</em><a name="73" href="#73">73</a> <em> *</em><a name="74" href="#74">74</a> <em> * <p>See <a href="<a href="http://javaalmanac.com/egs/javax.net.ssl/TrustAll.html" target="alexandria_uri">http://javaalmanac.com/egs/javax.net.ssl/TrustAll.html</a>"></em><a name="75" href="#75">75</a> <em> * e502. Disabling Certificate Validation in an HTTPS Connection</a> from</em><a name="76" href="#76">76</a> <em> * the java almanac for how to trust all.</em><a name="77" href="#77">77</a> <em> */</em><a name="78" href="#78">78</a> <strong>public</strong> <strong>final</strong> <strong>static</strong> String OPEN = <span class="string">"open"</span>;<a name="79" href="#79">79</a> <a name="80" href="#80">80</a> <em>/**<em>*</em></em><a name="81" href="#81">81</a> <em> * Trust any valid cert including self-signed certificates.</em><a name="82" href="#82">82</a> <em> */</em><a name="83" href="#83">83</a> <strong>public</strong> <strong>final</strong> <strong>static</strong> String LOOSE = <span class="string">"loose"</span>;<a name="84" href="#84">84</a> <a name="85" href="#85">85</a> <em>/**<em>*</em></em><a name="86" href="#86">86</a> <em> * Normal jsse behavior.</em><a name="87" href="#87">87</a> <em> *</em><a name="88" href="#88">88</a> <em> * Seemingly any certificate that supplies valid chain of trust.</em><a name="89" href="#89">89</a> <em> */</em><a name="90" href="#90">90</a> <strong>public</strong> <strong>final</strong> <strong>static</strong> String NORMAL = <span class="string">"normal"</span>;<a name="91" href="#91">91</a> <a name="92" href="#92">92</a> <em>/**<em>*</em></em><a name="93" href="#93">93</a> <em> * Strict trust.</em><a name="94" href="#94">94</a> <em> *</em><a name="95" href="#95">95</a> <em> * Ensure server has same name as cert DN.</em><a name="96" href="#96">96</a> <em> */</em><a name="97" href="#97">97</a> <strong>public</strong> <strong>final</strong> <strong>static</strong> String STRICT = <span class="string">"strict"</span>;<a name="98" href="#98">98</a> <a name="99" href="#99">99</a> <em>/**<em>*</em></em><a name="100" href="#100">100</a> <em> * All the levels of trust as an array from babe-in-the-wood to strict.</em>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -