views:

117

answers:

1

I am trying to connect an Android application with a secured HTTPS remote service that is hosted in Google App Engine for Java (https://applicationname.appspot.com), using the HTTPClient 4 implementation that comes with Android. The certificate is signed and valid form *.appspot.com.

I am using Android 2.1 in a real device (HTC Hero), and I get the following error: SSL23_GET_SERVER_HELLO:unknown protocol.

This is part of my code:

HttpParams params = new BasicHttpParams();        
...

SchemeRegistry schemeRegistry = new SchemeRegistry();
schemeRegistry.register(
        new Scheme("http", PlainSocketFactory.getSocketFactory(), 80));
schemeRegistry.register(
        new Scheme("https", SSLSocketFactory.getSocketFactory(), 443));
..
ClientConnectionManager cm = 
        new ThreadSafeClientConnManager(params, schemeRegistry);
DefaultHttpClient result = new DefaultHttpClient(cm, params);

Any idea about what could be happening and any solution or workaround?

This is the complete stack trace:

09-25 18:19:05.452: ERROR/OpenSSLSocketImpl(1195): Unknown error 1 during connect
09-25 18:19:05.460: ERROR/ServerProxy(1195): HTTPHelp : IOException : java.io.IOException: SSL handshake failure: Failure in SSL library, usually a protocol error
09-25 18:19:05.460: ERROR/ServerProxy(1195): error:140770FC:SSL routines:SSL23_GET_SERVER_HELLO:unknown protocol (external/openssl/ssl/s23_clnt.c:585 0xaf586674:0x00000000)
09-25 18:19:05.460: ERROR/ServerProxy(1195): java.io.IOException: SSL handshake failure: Failure in SSL library, usually a protocol error
09-25 18:19:05.460: ERROR/ServerProxy(1195): error:140770FC:SSL routines:SSL23_GET_SERVER_HELLO:unknown protocol (external/openssl/ssl/s23_clnt.c:585 0xaf586674:0x00000000)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.harmony.xnet.provider.jsse.OpenSSLSocketImpl.nativeconnect(Native Method)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.harmony.xnet.provider.jsse.OpenSSLSocketImpl.startHandshake(OpenSSLSocketImpl.java:305)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.harmony.xnet.provider.jsse.OpenSSLSocketImpl$SSLInputStream.<init>(OpenSSLSocketImpl.java:502)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.harmony.xnet.provider.jsse.OpenSSLSocketImpl.getInputStream(OpenSSLSocketImpl.java:443)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.io.SocketInputBuffer.<init>(SocketInputBuffer.java:93)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.SocketHttpClientConnection.createSessionInputBuffer(SocketHttpClientConnection.java:83)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.conn.DefaultClientConnection.createSessionInputBuffer(DefaultClientConnection.java:170)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.SocketHttpClientConnection.bind(SocketHttpClientConnection.java:106)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.conn.DefaultClientConnection.openCompleted(DefaultClientConnection.java:129)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.conn.DefaultClientConnectionOperator.openConnection(DefaultClientConnectionOperator.java:136)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.conn.AbstractPoolEntry.open(AbstractPoolEntry.java:164)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.conn.AbstractPooledConnAdapter.open(AbstractPooledConnAdapter.java:119)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.client.DefaultRequestDirector.execute(DefaultRequestDirector.java:348)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.client.AbstractHttpClient.execute(AbstractHttpClient.java:555)
09-25 18:19:05.460: ERROR/ServerProxy(1195):     at org.apache.http.impl.client.AbstractHttpClient.execute(AbstractHttpClient.java:487)

Thank you very much.

A: 

I don't use Java, but as for GAE -- are you using a "secure" parameter in your app.yaml? http://code.google.com/appengine/kb/general.html#https

Kai
Yas, in fact I can browse the site using a regular desktop browser, and the certificate is valid. The problem only appears when httpclient tries to connect the server.
Guido
@Guido ah okay, then I am uncertain. Have you tried looking up SSL error definitions for clues?
Kai