Skip to content

证书指纹 (Certificate Fingerprint) ​

🔒 证书的唯一标识,Pinning 常用它匹配。

是什么 ​

证书指纹 = 证书内容的 SHA-1/SHA-256 哈希,是证书的"身份证号"。

类型算法长度用途
SHA-1 fingerprintSHA-140 hex旧 Pinning
SHA-256 fingerprintSHA-25664 hex新 Pinning

怎么算 ​

对 DER 编码的证书整体做哈希:

SHA256(DER编码的证书字节) = 指纹

r0capture 的关联 ​

r0capture 抓不到"指纹比对"这个动作本身(Pinning 校验常在 Java 层或 native 层做),但能:

  1. 导出证书:storecert 把服务端证书写到 /sdcard/Download/,可本地算指纹
  2. 抓 Pinning 报错:Pinning 失败常抛 SSLPeerUnverifiedException,r0capture 抓到 SSL_read 失败前的握手明文

本地算指纹 ​

bash
# 从导出的证书
openssl x509 -in server.crt -noout -fingerprint -sha256

# 从 p12
keytool -list -v -keystore client.p12 -storepass r0ysue

Pinning 比对方式 ​

方式比对对象
公钥 hash (SPKI)SubjectPublicKeyInfo 的 hash
证书 hash整张证书的 hash
CN/Subject证书的 Common Name

SPKI hash 最常见(OkHttp CertificatePinner 默认),因为换证书但公钥不变时 Pinning 仍通过。

相关文档 ​

基于 VitePress 构建 · 教学用途