nativescript-community / nativescript-community/https

Error: Trust anchor for certification path not found

Offen
#82 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Vorherrschende Sprache
Vue
Sterne
52
Forks
40
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

Hello,

Following the documentation I am trying to implement a simple call to test the plugin but I when I execute the call I get the following error: javax.net.ssl.SSLHandshakeException: java.security.cert.CertPathValidatorException: Trust anchor for certification path not found

I am testing it on an Android simulator, but I get the same error on a physical device as well.

Here is my code:

adding the cert to webpack

new CopyWebpackPlugin([
    { from: { glob: "fonts/**" } },
    { from: { glob: "**/*.jpg" } },
    { from: { glob: "**/*.png" } },
    { from: { glob: "certs/*.cer" } },
]

enable the pinning

const dir = knownFolders.currentApp().getFolder('certs');
const cert = dir.getFile('<cert_name>.cer').path;
https.enableSSLPinning({
        host: <domain>',
        certificate: cert
 });

then

https.request({
       url: '<url>',
       method: 'GET'
}).then((res) => {
       console.log(res.statusCode);
}).catch((err) => {
       console.error(err);
});

The code runs without an issue and the certificate is valid. I checked it using the openssl x509 -in <cert.cer> -text -noout command.

Am I missing something?
Thank you

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne mit der webpack-Konfiguration zum Kopieren des Zertifikats und dem Aufruf von https.enableSSLPinning; überprüfe, wie der .cer-Pfad auf Android paketiert wird, und vergleiche ihn mit den dokumentierten Zertifikatanforderungen des Plugins. Reproduziere den GET-Aufruf im Simulator und auf einem physischen Gerät und bestätige anschließend, dass die Anfrage ohne SSLHandshakeException erfolgreich ist.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
android, javascript
Bereich
api, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.