证书指纹 (Certificate Fingerprint)
🔒 证书的唯一标识,Pinning 常用它匹配。
是什么
证书指纹 = 证书内容的 SHA-1/SHA-256 哈希,是证书的"身份证号"。
| 类型 | 算法 | 长度 | 用途 |
|---|---|---|---|
| SHA-1 fingerprint | SHA-1 | 40 hex | 旧 Pinning |
| SHA-256 fingerprint | SHA-256 | 64 hex | 新 Pinning |
怎么算
对 DER 编码的证书整体做哈希:
SHA256(DER编码的证书字节) = 指纹r0capture 的关联
r0capture 抓不到"指纹比对"这个动作本身(Pinning 校验常在 Java 层或 native 层做),但能:
- 导出证书:
storecert把服务端证书写到/sdcard/Download/,可本地算指纹 - 抓 Pinning 报错:Pinning 失败常抛
SSLPeerUnverifiedException,r0capture 抓到SSL_read失败前的握手明文
本地算指纹
bash
# 从导出的证书
openssl x509 -in server.crt -noout -fingerprint -sha256
# 从 p12
keytool -list -v -keystore client.p12 -storepass r0ysuePinning 比对方式
| 方式 | 比对对象 |
|---|---|
| 公钥 hash (SPKI) | SubjectPublicKeyInfo 的 hash |
| 证书 hash | 整张证书的 hash |
| CN/Subject | 证书的 Common Name |
SPKI hash 最常见(OkHttp CertificatePinner 默认),因为换证书但公钥不变时 Pinning 仍通过。