为 Java JDK 11 中可用的 TLS 1.3 实现会话恢复

如何解决为 Java JDK 11 中可用的 TLS 1.3 实现会话恢复

尝试实施 TLS 1.2 与 TLS 1.3 握手测量,重点是会话恢复。

TLS 1.2 运行良好,ID 和票证恢复,但更改为 TLS 1.3 时却没有。

不幸的是,wireshark 数据已加密,但 java 声明如下:

javax.net.ssl|DEBUG|17|Thread-3|2021-01-09 20:36:54.491 CET|PreSharedKeyExtension.java:634|No session to resume.
javax.net.ssl|DEBUG|17|Thread-3|2021-01-09 20:36:54.491 CET|SSLExtensions.java:260|Ignore,context unavailable extension: pre_shared_key

我们不是要实现 0RTT 恢复,而是要使用 SessionTickets。客户端不会向服务器发送 PresharedKey。

javax.net.ssl|DEBUG|16|Thread-2|2021-01-09 20:36:54.564 CET|PreSharedKeyExtension.java:807|Handling pre_shared_key absence.

代码(客户端):

public class Client implements Runnable {
    private String version;
    private int count;
    private final int PORT = 8084;
    private String[] cipher_suites;
    private boolean sessionResumption;

    private SSLServerSocket serverSocket;

    public Client(String tlsVersion,int count,boolean resumeSession) {
        this.version = tlsVersion;
        this.count = count;
        this.sessionResumption = resumeSession;
    }


    private SSLContext getContext() {
        SSLContext context = null;
        try {
            InputStream stream = this.getClass().getResourceAsStream("/sslclienttrust");
            KeyStore trustStore = KeyStore.getInstance(KeyStore.getDefaultType());
            char[] trustStorePassword = "]3!z2Tb?@EHu%d}Q".toCharArray();
            trustStore.load(stream,trustStorePassword);
            context = SSLContext.getInstance(version);

            TrustManagerFactory factory = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());
            factory.init(trustStore);
            TrustManager[] managers = factory.getTrustManagers();
            context.init(null,managers,null);
        } catch (KeyStoreException | IOException | NoSuchAlgorithmException | CertificateException | KeyManagementException e) {
            e.printStackTrace();

        }
        return context;
    }

    public void startHandshake(SSLSocketFactory sf) throws IOException {
        long startTime = -1;
        try (SSLSocket socket = createSocket(sf)) {
            //InputStream is = new BufferedInputStream(socket.getInputStream());
            startTime = System.currentTimeMillis();
            socket.startHandshake();
        }
        long endTime = System.currentTimeMillis();
        long timeElapsed = endTime - startTime;
        System.out.println("Time Handshake " + timeElapsed );

    }

    private SSLSocket createSocket(SSLSocketFactory sf) throws IOException {
        SSLSocket s = (SSLSocket) sf.createSocket("localhost",PORT);
        s.setEnabledProtocols(new String[]{version});
        //s.setEnabledCipherSuites(new String[]{"TLS_RSA_WITH_AES_128_CBC_SHA256"});
        return s;
    }

    @Override
    public void run() {
        startTime = System.currentTimeMillis();
        SSLSocketFactory s = null;
        if(sessionResumption){
            s = getContext().getSocketFactory();
        }
        while(count>0){

            try {
                if(!sessionResumption){
                    s = getContext().getSocketFactory();
                }
                startHandshake(s);
                count--;
                Thread.sleep(1);
            } catch (IOException | InterruptedException e) {
                e.printStackTrace();
                count = 0;
            }

        }

    }

服务器:

public class Server implements Runnable {
    private String version;
    private boolean keepAlive;
    private final int PORT = 8084;
    private String[] cipher_suites;

    private SSLServerSocket serverSocket;

    public Server(String tlsVersion,boolean keepAlive) {
        this.version = tlsVersion;
        this.keepAlive = keepAlive;
    }

    private SSLContext getContext() {
        SSLContext context = null;
        try {



            InputStream stream = this.getClass().getResourceAsStream("/sslserverkeys");
            KeyStore keyStore = KeyStore.getInstance(KeyStore.getDefaultType());
            keyStore.load(stream,"7x*;^C(HU~5}@P?h".toCharArray());

            KeyManagerFactory keyManagerFactory = KeyManagerFactory.getInstance(KeyManagerFactory.getDefaultAlgorithm());
            keyManagerFactory.init(keyStore,"7x*;^C(HU~5}@P?h".toCharArray());
            KeyManager[] km = keyManagerFactory.getKeyManagers();

            TrustManagerFactory trustManagerFactory = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());
            trustManagerFactory.init(keyStore);
            TrustManager[] tm = trustManagerFactory.getTrustManagers();

            context = SSLContext.getInstance(version);
            context.init(km,tm,null);
        } catch (KeyStoreException | IOException | NoSuchAlgorithmException | CertificateException | KeyManagementException | UnrecoverableKeyException e) {
            e.printStackTrace();

        }
        return context;
    }

    public void acceptHandshake() throws IOException {
        //verbindung
        try (SSLSocket socket = (SSLSocket) serverSocket.accept()) {
            socket.setEnabledProtocols(new String[]{version});
            socket.startHandshake();


        }

    }
    public void configure(){
        SSLServerSocketFactory factory = getContext().getServerSocketFactory();
        try {
            serverSocket = ((SSLServerSocket) factory.createServerSocket(this.PORT));
            //config
            serverSocket.setEnabledProtocols(new String[]{version});
            serverSocket.setEnabledCipherSuites(serverSocket.getSupportedCipherSuites());

        } catch (IOException e) {
            e.printStackTrace();
        }
    }

    @Override
    public void run() {
        configure();
            try {
                while(keepAlive){
                    acceptHandshake();
                }
            } catch (IOException e) {
                e.printStackTrace();
            }
    }
}

提前致谢:)

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。

相关推荐


使用本地python环境可以成功执行 import pandas as pd import matplotlib.pyplot as plt # 设置字体 plt.rcParams['font.sans-serif'] = ['SimHei'] # 能正确显示负号 p
错误1:Request method ‘DELETE‘ not supported 错误还原:controller层有一个接口,访问该接口时报错:Request method ‘DELETE‘ not supported 错误原因:没有接收到前端传入的参数,修改为如下 参考 错误2:cannot r
错误1:启动docker镜像时报错:Error response from daemon: driver failed programming external connectivity on endpoint quirky_allen 解决方法:重启docker -> systemctl r
错误1:private field ‘xxx‘ is never assigned 按Altʾnter快捷键,选择第2项 参考:https://blog.csdn.net/shi_hong_fei_hei/article/details/88814070 错误2:启动时报错,不能找到主启动类 #
报错如下,通过源不能下载,最后警告pip需升级版本 Requirement already satisfied: pip in c:\users\ychen\appdata\local\programs\python\python310\lib\site-packages (22.0.4) Coll
错误1:maven打包报错 错误还原:使用maven打包项目时报错如下 [ERROR] Failed to execute goal org.apache.maven.plugins:maven-resources-plugin:3.2.0:resources (default-resources)
错误1:服务调用时报错 服务消费者模块assess通过openFeign调用服务提供者模块hires 如下为服务提供者模块hires的控制层接口 @RestController @RequestMapping("/hires") public class FeignControl
错误1:运行项目后报如下错误 解决方案 报错2:Failed to execute goal org.apache.maven.plugins:maven-compiler-plugin:3.8.1:compile (default-compile) on project sb 解决方案:在pom.
参考 错误原因 过滤器或拦截器在生效时,redisTemplate还没有注入 解决方案:在注入容器时就生效 @Component //项目运行时就注入Spring容器 public class RedisBean { @Resource private RedisTemplate<String
使用vite构建项目报错 C:\Users\ychen\work>npm init @vitejs/app @vitejs/create-app is deprecated, use npm init vite instead C:\Users\ychen\AppData\Local\npm-
参考1 参考2 解决方案 # 点击安装源 协议选择 http:// 路径填写 mirrors.aliyun.com/centos/8.3.2011/BaseOS/x86_64/os URL类型 软件库URL 其他路径 # 版本 7 mirrors.aliyun.com/centos/7/os/x86
报错1 [root@slave1 data_mocker]# kafka-console-consumer.sh --bootstrap-server slave1:9092 --topic topic_db [2023-12-19 18:31:12,770] WARN [Consumer clie
错误1 # 重写数据 hive (edu)> insert overwrite table dwd_trade_cart_add_inc > select data.id, > data.user_id, > data.course_id, > date_format(
错误1 hive (edu)> insert into huanhuan values(1,'haoge'); Query ID = root_20240110071417_fe1517ad-3607-41f4-bdcf-d00b98ac443e Total jobs = 1
报错1:执行到如下就不执行了,没有显示Successfully registered new MBean. [root@slave1 bin]# /usr/local/software/flume-1.9.0/bin/flume-ng agent -n a1 -c /usr/local/softwa
虚拟及没有启动任何服务器查看jps会显示jps,如果没有显示任何东西 [root@slave2 ~]# jps 9647 Jps 解决方案 # 进入/tmp查看 [root@slave1 dfs]# cd /tmp [root@slave1 tmp]# ll 总用量 48 drwxr-xr-x. 2
报错1 hive> show databases; OK Failed with exception java.io.IOException:java.lang.RuntimeException: Error in configuring object Time taken: 0.474 se
报错1 [root@localhost ~]# vim -bash: vim: 未找到命令 安装vim yum -y install vim* # 查看是否安装成功 [root@hadoop01 hadoop]# rpm -qa |grep vim vim-X11-7.4.629-8.el7_9.x
修改hadoop配置 vi /usr/local/software/hadoop-2.9.2/etc/hadoop/yarn-site.xml # 添加如下 <configuration> <property> <name>yarn.nodemanager.res