物理Android设备上Ionic应用用自签名证书连接CouchDB失败
Ionic Android应用连接自签名证书CouchDB失败问题
我开发了一款从CouchDB服务器请求文档的应用,在电脑上用Node.js运行相同代码完全正常,但在物理手机的Ionic Android应用中运行时,出现数据获取失败的问题。
服务器基础配置
已启用CORS
CouchDB使用自签名证书运行,已通过以下命令启用CORS:
pnpm install -g add-cors-to-couchdb add-cors-to-couchdb http://192.168.1.27:5984 -u admin -p xxxx
PouchDB初始化代码
this.rdb = new PouchDB('https://192.168.1.2:6984/employees', { auth: { username: "xxxx", password: "xxxx", }, });
应用错误信息
Android应用请求时抛出以下异常:
java.security.cert.CertPathValidatorException: Trust anchor for certification path not found.
注:用手机浏览器直接访问https://192.168.1.2:6984可正常打开
Android应用配置详情
AndroidManifest.xml
<manifest xmlns:android="http://schemas.android.com/apk/res/android" xmlns:tools="http://schemas.android.com/tools" android:networkSecurityConfig="@xml/network_security_config" > <application android:usesCleartextTraffic="true" tools:ignore="GoogleAppIndexingWarning"> <uses-library android:name="org.apache.http.legacy" android:required="false" /> ... </application> <uses-permission android:name="android.permission.INTERNET" /> <uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" /> </manifest>
network_security_config.xml
<?xml version="1.0" encoding="utf-8"?> <network-security-config> <domain-config cleartextTrafficPermitted="true"> <domain includeSubdomains="true">localhost</domain> <domain includeSubdomains="true">192.168.1.27</domain> </domain-config> <base-config cleartextTrafficPermitted="true"> <trust-anchors> <certificates src="system" /> <certificates src="user" /> </trust-anchors> </base-config> <debug-overrides> <trust-anchors> <certificates src="@raw/couchdb"/> </trust-anchors> </debug-overrides> </network-security-config>
已将证书重命名为couchdb.crt,并复制到以下两个路径:
android/app/src/main/res/raw/couchdb.crtandroid/app/src/main/assets/couchdb.crt
capacitor.config.ts
... server: { androidScheme: 'https', allowNavigation: ['https://192.168.1.27:6984/employees'] } ...
CouchDB服务器完整设置
local.ini配置
[ssl] enable = true cert_file = /etc/couchdb/cert/couchdb.pem key_file = /etc/couchdb/cert/privkey.pem
自签名证书生成命令
openssl req -newkey rsa:2048 -nodes -x509 -keyout privkey.pem -out couchdb.pem -days 1095 -addext "subjectAltName = IP.1:192.168.1.27"
内容的提问来源于stack exchange,提问作者danilo
相关产品推荐
相关产品推荐

