Android应用编程方式从签名JKS密钥库获取SHA256及别名
Alright, let's tackle your problem step by step—first fixing that frustrating NoSuchAlgorithmException, then writing code to pull aliases and SHA256 hashes from your JKS keystore programmatically.
Fixing the
NoSuchAlgorithmException: KeyStore jks implementation not found Error This error usually pops up when your JDK/JRE environment doesn't have the default JKS keystore implementation available, or it's not being loaded properly. Here are the most common fixes:
- Check your JDK/JRE distribution: Some stripped-down or custom OpenJDK builds (like those for embedded systems) might omit the JKS implementation. Stick to standard distributions like Oracle JDK, Eclipse Temurin (Adoptium), or OpenJDK from your OS package manager—these all include the JKS provider by default.
- Explicitly specify the KeyStore provider: If the default provider lookup is failing, force the use of the SUN provider (which includes JKS support) when initializing the KeyStore:
// Option 1: Specify provider by name KeyStore keyStore = KeyStore.getInstance("JKS", "SUN"); // Option 2: Instantiate the provider directly (for older JDK versions) Security.addProvider(new sun.security.provider.Sun()); KeyStore keyStore = KeyStore.getInstance("JKS"); - Verify modular dependencies (Java 9+): If you're using a modular project, ensure your
module-info.javaincludes a dependency onjava.base(where the JKS implementation lives):module your.module.name { requires java.base; }
Programmatically Fetching Aliases and SHA256 Hashes from JKS Keystore
Once you've fixed the exception, here's a complete code example to iterate over all aliases in your JKS keystore and compute the SHA256 hash for each associated certificate:
import java.io.FileInputStream; import java.security.KeyStore; import java.security.MessageDigest; import java.security.cert.Certificate; import java.util.Enumeration; public class JKSKeystoreReader { public static void main(String[] args) { // Replace these with your keystore path and password String keystorePath = "/path/to/your/keystore.jks"; String keystorePassword = "your_keystore_password"; try { // Initialize the KeyStore (use the fixed provider if needed) KeyStore keyStore = KeyStore.getInstance("JKS"); // Load the keystore file with the password keyStore.load(new FileInputStream(keystorePath), keystorePassword.toCharArray()); // Get all aliases in the keystore Enumeration<String> aliases = keyStore.aliases(); while (aliases.hasMoreElements()) { String alias = aliases.nextElement(); System.out.println("Alias Name: " + alias); // Retrieve the certificate linked to this alias Certificate certificate = keyStore.getCertificate(alias); if (certificate != null) { // Compute SHA256 hash of the certificate's encoded data MessageDigest sha256Digest = MessageDigest.getInstance("SHA-256"); byte[] hashBytes = sha256Digest.digest(certificate.getEncoded()); // Convert the raw byte hash to a readable hex string StringBuilder hexString = new StringBuilder(); for (byte b : hashBytes) { hexString.append(String.format("%02x", b)); } String sha256Hash = hexString.toString(); System.out.println("SHA256 Hash: " + sha256Hash); System.out.println("------------------------------"); } else { System.out.println("No certificate found for this alias"); System.out.println("------------------------------"); } } } catch (Exception e) { // Handle exceptions (e.g., wrong password, missing file, invalid keystore) e.printStackTrace(); } } }
Key Notes:
- File Permissions: Ensure your application has read access to the JKS keystore file.
- Password Handling: Never hardcode passwords in production—use environment variables, secure config files, or password prompts instead.
- Private Keys: If you're working with private key aliases, you'll need the key's password to access it, but for certificates (public key entries), the keystore password is sufficient.
内容的提问来源于stack exchange,提问作者Mustansar Saeed
相关产品推荐
相关产品推荐

