private class MyHostnameVerifier implements HostnameVerifier {
@Override
public boolean verify(String hostname, SSLSession session) {
// TODO Auto-generated method stub
return true;
}
}
private class MyTrustManager implements X509TrustManager {
@Override
public void checkClientTrusted(X509Certificate[] chain, String authType)
throws CertificateException {
// TODO Auto-generated method stub
}
@Override
public void checkServerTrusted(X509Certificate[] chain, String authType)
throws CertificateException {
// TODO Auto-generated method stub
}
@Override
public X509Certificate[] getAcceptedIssuers() {
// TODO Auto-generated method stub
return null;
}
}
有些 https 请求,如果不是 android 系统自带信任的证书,我们需要去拿服务器对应的证书放到本地,发送请求时带上,,
也有一种方法,像上面的代码对证书验证的方法提供一个空实现,这样也可以访问,,这种做法会有怎样的安全风险,可以怎样被攻击