You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Postman更新丢失集合后,如何在RestAssured中配置客户端证书?

解决RestAssured配置客户端证书的问题

你当前代码的核心问题是:keyStore()方法仅支持加载Java keystore格式文件(如.jks、.p12),但你提供的是单独的.crt证书文件和.key私钥文件,因此无法正确加载客户端证书。以下是两种可行的解决方案:

方案1:将证书和私钥转换为PKCS12格式(推荐)

这是最简便的方式,和Postman的客户端证书配置逻辑一致,步骤如下:

  1. 使用OpenSSL命令将.crt和.key合并为PKCS12格式的keystore文件:
openssl pkcs12 -export -in mycert.crt -inkey mycert.key -out mycert.p12

执行命令时会提示设置密码,记住该密码,后续代码需使用。

  1. 修改RestAssured代码,加载转换后的PKCS12文件:
import io.restassured.RestAssured;
import org.testng.annotations.BeforeClass;
import org.testng.annotations.Test;

public class ApiTest {

    @BeforeClass
    public static void setup() {
        RestAssured.baseURI = "https://mywebsitewhichneedcrt.com";
    }

    @Test
    public void testWithClientCertificate() {
        String p12Path = "C:\\Users\\user\\Desktop\\Web\\cert\\mycert.p12";
        String passphrase = "000000"; // 转换PKCS12时设置的密码

        RestAssured
                .given()
                // 加载PKCS12格式的keystore,指定类型为PKCS12
                .keyStore(p12Path, passphrase, "PKCS12")
                .when()
                .post("/endpoint")
                .then()
                .statusCode(201);
    }
}

方案2:直接加载单独的.crt和.key文件

如果不想转换证书格式,可以通过手动构建SSLContext的方式加载证书和私钥,需要依赖BouncyCastle库处理证书解析:

  1. 添加Maven依赖(若使用Maven):
<dependency>
    <groupId>org.bouncycastle</groupId>
    <artifactId>bcprov-jdk15on</artifactId>
    <version>1.70</version>
</dependency>
  1. 修改代码实现证书和私钥的加载:
import io.restassured.RestAssured;
import io.restassured.config.SSLConfig;
import org.testng.annotations.BeforeClass;
import org.testng.annotations.Test;

import java.io.FileInputStream;
import java.security.KeyFactory;
import java.security.KeyStore;
import java.security.PrivateKey;
import java.security.cert.Certificate;
import java.security.cert.CertificateFactory;
import java.security.spec.PKCS8EncodedKeySpec;
import java.util.Base64;

public class ApiTest {

    @BeforeClass
    public static void setup() {
        RestAssured.baseURI = "https://mywebsitewhichneedcrt.com";
    }

    @Test
    public void testWithClientCertificate() throws Exception {
        String certificatePath = "C:\\Users\\user\\Desktop\\Web\\cert\\mycert.crt";
        String keyPath = "C:\\Users\\user\\Desktop\\Web\\cert\\mycert.key";
        String passphrase = "000000";

        // 加载X.509证书
        CertificateFactory certFactory = CertificateFactory.getInstance("X.509");
        Certificate cert = certFactory.generateCertificate(new FileInputStream(certificatePath));

        // 加载并解析PKCS8格式私钥
        String keyContent = new String(java.nio.file.Files.readAllBytes(java.nio.file.Paths.get(keyPath)))
                .replace("-----BEGIN PRIVATE KEY-----", "")
                .replace("-----END PRIVATE KEY-----", "")
                .replaceAll("\\s", "");
        byte[] keyBytes = Base64.getDecoder().decode(keyContent);
        PKCS8EncodedKeySpec keySpec = new PKCS8EncodedKeySpec(keyBytes);
        KeyFactory keyFactory = KeyFactory.getInstance("RSA");
        PrivateKey privateKey = keyFactory.generatePrivate(keySpec);

        // 创建临时KeyStore并添加证书和私钥
        KeyStore keyStore = KeyStore.getInstance(KeyStore.getDefaultType());
        keyStore.load(null);
        keyStore.setKeyEntry("client-cert", privateKey, passphrase.toCharArray(), new Certificate[]{cert});

        // 配置RestAssured的SSL上下文
        SSLConfig sslConfig = new SSLConfig().keyStore(keyStore, passphrase);

        RestAssured
                .given()
                .config(RestAssured.config().sslConfig(sslConfig))
                .when()
                .post("/endpoint")
                .then()
                .statusCode(201);
    }
}

注意事项

  • 若服务器证书为可信证书,建议删除relaxedHTTPSValidation()方法以避免安全风险;若为自签名证书,可保留该方法跳过验证。
  • 确保证书和私钥文件路径正确,Windows系统需使用双反斜杠(\\)转义路径分隔符。

内容的提问来源于stack exchange,提问作者jhor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 22:23:18