← Back to Advanced Java Course | Chapter 11: Advanced & Security | Lesson 13 of 19

Java SSL और HTTPS

SSL और TLS messages को उलझाकर internet connections को private बनाते हैं, जैसे lock की हुई box में चिट्ठियां भेजना। HTTPS वह protection उपयोग करने वाला web है।

SSL/TLS Overview

SSL (Secure Sockets Layer) और इसका आधुनिक successor TLS (Transport Layer Security) किसी client और server के बीच network communication को encrypt करते हैं, network पार करते समय transit में data को eavesdropping या tampering से बचाते हुए।

उदाहरण: SSL/TLS Overview

java
import javax.net.ssl.SSLContext;
public class Main {
	public static void main(String[] args) throws Exception {
		SSLContext context = SSLContext.getInstance("TLSv1.3"); // encrypts data in transit
		System.out.println(context.getProtocol());
	}
}

Creating HttpsURLConnection

HttpsURLConnection आपको specifically HTTPS पर requests भेजने देता है, यह सुनिश्चित करते हुए कि किसी domain (उदाहरण के लिए cookiescursor.com) के साथ exchanged data end-to-end encrypted है बजाय इसके कि एक plain HttpURLConnection HTTP पर इसे plaintext के रूप में भेजे।

उदाहरण: Creating HttpsURLConnection

java
import java.net.URL;
import javax.net.ssl.HttpsURLConnection;
public class Main {
	public static void main(String[] args) throws Exception {
		URL url = new URL("https://cookiescursor.com");
		HttpsURLConnection conn = (HttpsURLConnection) url.openConnection(); // encrypted, not plaintext HTTP
		System.out.println(conn.getURL());
	}
}

Custom TrustManagers

एक TrustManager TLS handshake के दौरान यह तय करने के लिए ज़िम्मेदार है कि किसी server के SSL certificate पर भरोसा किया जाए या नहीं। Custom TrustManagers कभी-कभी test environments में self-signed certificates को accept करने के लिए उपयोग होते हैं, लेकिन production में कभी सभी certificates पर अंधाधुंध भरोसा करने के लिए उपयोग नहीं होने चाहिए।

उदाहरण: Custom TrustManagers

java
import javax.net.ssl.*;
import java.security.cert.X509Certificate;
public class Main {
	public static void main(String[] args) throws Exception {
		TrustManager trustManager = new X509TrustManager() {
			public void checkClientTrusted(X509Certificate[] chain, String authType) {}
			public void checkServerTrusted(X509Certificate[] chain, String authType) {} // only for test environments
			public X509Certificate[] getAcceptedIssuers() { return new X509Certificate[0]; }
		};
		System.out.println("Custom TrustManager created (never blindly trust all certs in production)");
	}
}

SSLSocket

SSLSocket आपको किसी client और server के बीच सीधे एक सुरक्षित, encrypted raw TCP connection खोलने का एक lower-level तरीका देता है, तब उपयोगी जब आपको किसी higher-level HTTP client के बजाय socket level पर TLS चाहिए।

उदाहरण: SSLSocket

java
// Import javax.net.ssl.* so it can be used by its short name
import javax.net.ssl.*;
// Define the class Main
public class Main {
	// Program entry point: the JVM starts running here
	public static void main(String[] args) throws Exception {
		SSLSocketFactory factory = (SSLSocketFactory) SSLSocketFactory.getDefault();
		// Print a line to the console
		System.out.println(factory.getClass().getSimpleName() + " creates raw encrypted sockets");
	}
}

Enforcing Secure TLS Versions

हमेशा अपने SSLContext को TLSv1.3 जैसे modern, secure TLS versions enforce करने और पुराने, vulnerable protocol versions (जैसे SSLv3 या TLS 1.0) को reject करने के लिए configure करें, क्योंकि किसी पुराने protocol में वापस आने वाले connections TLS के देने वाले security guarantees खो देते हैं।

उदाहरण: Enforcing Secure TLS Versions

java
import javax.net.ssl.SSLContext;
public class Main {
	public static void main(String[] args) throws Exception {
		SSLContext context = SSLContext.getInstance("TLSv1.3"); // rejects outdated protocols like SSLv3
		context.init(null, null, null);
		System.out.println("Enforcing " + context.getProtocol());
	}
}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. कोई error हटाने के लिए हर certificate को accept करने वाला TrustManager लिखना, जो HTTPS की दी protection हटा देता है।
  2. SSLv3 या TLS 1.0 जैसे पुराने protocols को enable करना, जबकि सिर्फ TLSv1.2 और TLSv1.3 जैसे modern versions की अनुमति होनी चाहिए।
  3. http:// URL से खोले गए connection को HttpsURLConnection में cast करना, जो ClassCastException फेंकता है।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.