Paul T.
Paul T.

Reputation: 5038

AFNetworking 3 issue

In AFNetworking 3 for invalid SSL certificate I used validatesCertificateChain = false , but now it seems that this field was removed and I can't make requests to my server.

Here is class for requests:

import UIKit
import AFNetworking

class ClientHTML: AFHTTPSessionManager {
    private static var __once: () = { () -> Void in

        let securityPolicy = AFSecurityPolicy(pinningMode: AFSSLPinningMode.certificate)
        securityPolicy.validatesDomainName = false
        securityPolicy.allowInvalidCertificates = true
        sharedInstanceTemp.securityPolicy = securityPolicy


        sharedInstanceTemp.requestSerializer = AFHTTPRequestSerializer()
        sharedInstanceTemp.responseSerializer = AFHTTPResponseSerializer()


    }()

    fileprivate static let sharedInstanceTemp = ClientHTML(baseURL: URL(string: kServer_urlBilderlings))

    static var sharedInstance:ClientHTML {
        get {
            _ = ClientHTML.__once

            return sharedInstanceTemp
        }
    }
}

I do requests by:

ClientHTML.sharedInstance.post("https://acs-web-test.firstdata.lv", parameters: nil, progress: { (progress) in
            print("progress = ", progress)
        }, success: { (task, response) in
            let data = response as! Data
            let html = String(data: data, encoding: .utf8)
            print("success responce = ", html)
        }, failure: { (task, error) in
            print("error = ", error)
        })

And according to this post I have to use validatesCertificateChain property. Can anybody help?

Upvotes: 2

Views: 1147

Answers (3)

Sunil Targe
Sunil Targe

Reputation: 7459

Objective-C

static NSString* const kSecurityCertificate = @"xxxxx";

yourManager.securityPolicy = [self customSecurityPolicy];

- (AFSecurityPolicy*)customSecurityPolicy {
   AFSecurityPolicy *securityPolicy = [AFSecurityPolicy policyWithPinningMode:AFSSLPinningModeNone];
   NSString *cerPath = [[NSBundle mainBundle] pathForResource:kSecurityCertificate ofType:@"der"];
   NSData *certData = [NSData dataWithContentsOfFile:cerPath];
   [securityPolicy setValidatesDomainName:NO];
   [securityPolicy setAllowInvalidCertificates:YES];
   [securityPolicy setPinnedCertificates:[NSSet setWithObjects:certData, nil]];
   return securityPolicy;
}

Upvotes: 0

Dody Rachmat Wicaksono
Dody Rachmat Wicaksono

Reputation: 1014

For objective-c user setAllowInvalidCertificates:YES without SSL Pinning:

AFSecurityPolicy *sec = [AFSecurityPolicy policyWithPinningMode:AFSSLPinningModeNone];
[sec setAllowInvalidCertificates:YES];
[sec setValidatesDomainName:NO];
manager.securityPolicy = sec;

Upvotes: 2

Paul T.
Paul T.

Reputation: 5038

I solved it by changing let securityPolicy = AFSecurityPolicy(pinningMode: AFSSLPinningMode.certificate) to let securityPolicy = AFSecurityPolicy(pinningMode: AFSSLPinningMode.none)

Upvotes: 2

Related Questions