Varun Narisetty
Varun Narisetty

Reputation: 155

Android SSLSocket#getInputstream() throws HandshakeException on earlier versions of Android 6.0

In my application, I need to work on the SSLSocket. I have this code which is working on Android6.0 and above and When I run the same code on Android version 5.+ I am getting HandshakeException

private void openSSLSocket(String mHost, int mPort){
    try {
        SocketFactory sf = SSLSocketFactory.getDefault();
        mSocket = (SSLSocket) sf.createSocket(mHost, mPort);
        mSocket.setEnabledProtocols(new String[]{"TLSv1"});
        mInputStream = mSocket.getInputStream();
        mOutputStream = mSocket.getOutputStream();


    }catch (Exception e){

I have read this article on android developer site and implemented the below code I got the .crt file for the server admin

private void openSSLSocketWithCA(String mHost, int mPort) {

        // Load CAs from an InputStream
        // (could be from a resource or ByteArrayInputStream or ...)
        CertificateFactory cf = CertificateFactory.getInstance("X.509");
        // From

        InputStream caInput ="star_******_chained.crt");

        Certificate ca;
        try {
            ca = cf.generateCertificate(caInput);
            System.out.println("ca=" + ((X509Certificate) ca).getSubjectDN());
        } finally {

        // Create a KeyStore containing our trusted CAs
        String keyStoreType = KeyStore.getDefaultType();
        KeyStore keyStore = KeyStore.getInstance(keyStoreType);
        keyStore.load(null, null);
        keyStore.setCertificateEntry("ca", ca);

        // Create a TrustManager that trusts the CAs in our KeyStore
        String tmfAlgorithm = TrustManagerFactory.getDefaultAlgorithm();
        TrustManagerFactory tmf = TrustManagerFactory.getInstance(tmfAlgorithm);

        // Create an SSLContext that uses our TrustManager
        SSLContext context = SSLContext.getInstance("TLS");
        context.init(null, tmf.getTrustManagers(), null);

        SSLSocketFactory sf = context.getSocketFactory();
        mSocket = (SSLSocket) sf.createSocket(mHost, mPort);
        mSocket.setEnabledProtocols(new String[]{"TLSv1"});
        mInputStream = mSocket.getInputStream();
        mOutputStream = mSocket.getOutputStream();

    }catch (Exception e){

even then I am getting HandshakeException when calling mSocket.getInputStream(); method

here is the log

W/System.err: Handshake failed
W/System.err:     at
W/System.err:     at
W/System.err:     at
W/System.err:     at *******.***.*******.common.CometSocketApi.openSSLSocketWithCA(

Upvotes: 0

Views: 311

Answers (1)

Varun Narisetty
Varun Narisetty

Reputation: 155

After a lot of searching on web. I have landed on this page Updating security provider Finally, this solution worked for me

I have called this piece of code in onCreate of my main activity

 try {
    } catch (GooglePlayServicesRepairableException e) {
        GooglePlayServicesUtil.getErrorDialog(e.getConnectionStatusCode(), callingActivity, 0);
    } catch (GooglePlayServicesNotAvailableException e) {
        Log.e("SecurityException", "Google Play Services not available.");

This solved my issue

Upvotes: 1

Related Questions