安卓10证书问题

Posted by bfpiaoran on July 19, 2020

最近换了安卓手机 好不容易root了 话说一加现在root也太麻烦了 传说定制化方便也不知道谁谣传的,开开心心装完证书之后,
发现抓不到https的包

最后一查才知道 原来安卓10以后不再信任用户证书需要 设置到系统用户 这就麻烦了 首先导出 burp证书 然后要用到openssl

openssl x509 -inform DER -in cacert.der -out cacert.pem  
#将证书 改成pem 
openssl x509 -inform PEM -subject_hash_old -in cacert.pem 
#查看证书hash
9a5ba575
-----BEGIN CERTIFICATE-----
MIIDyTCCArGgAwIBAgIEU8p2yzANBgkqhkiG9w0BAQsFADCBijEUMBIGA1UEBhML
UG9ydFN3aWdnZXIxFDASBgNVBAgTC1BvcnRTd2lnZ2VyMRQwEgYDVQQHEwtQb3J0
U3dpZ2dlcjEUMBIGA1UEChMLUG9ydFN3aWdnZXIxFzAVBgNVBAsTDlBvcnRTd2ln
Z2VyIENBMRcwFQYDVQQDEw5Qb3J0U3dpZ2dlciBDQTAeFw0xNDA3MTkxMzQ2NTFa
Fw00MDA3MTkxMzQ2NTFaMIGKMRQwEgYDVQQGEwtQb3J0U3dpZ2dlcjEUMBIGA1UE
CBMLUG9ydFN3aWdnZXIxFDASBgNVBAcTC1BvcnRTd2lnZ2VyMRQwEgYDVQQKEwtQ
b3J0U3dpZ2dlcjEXMBUGA1UECxMOUG9ydFN3aWdnZXIgQ0ExFzAVBgNVBAMTDlBv
cnRTd2lnZ2VyIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoDiJ
xGjf15+tK6wvA/sdbdqmahIG2DwtmRIhTgSfQ0MJUWCx2vYEQOeqyhTdHOsFc0qe
O1uobIpPUWV4HmRtURAHgfa4BDlkp4c7nQDbl5YVPTOHSiHrgGiDaCsZDuKOuEMv
awfjfAgKs7XrhYSFkKXIt+EA0QnLIZD0IKBJUDs2DybnfuOX3sCPr9fc+4rNcZIN
dx6Bp6mjTOptb1TkXxrn+KhqRn+kifplkXMGZUkRDLAb7Jv3JGvRE9CIelwMSaO8
GuTnxe+5AJV6aVY9OLl016jt2wpsxsckDRWhPM/zGZkoxCkAj6mxHD6DTDyvtxsl
2jUugPcLQhmCoDettQIDAQABozUwMzASBgNVHRMBAf8ECDAGAQH/AgEAMB0GA1Ud
DgQWBBTsCSWdrMzgY04DdscgJ80jd+gHHDANBgkqhkiG9w0BAQsFAAOCAQEAK9v5
7aErckiuke77Md9dF5VB8IT0Zcrse0cw+5oIy9+ax9Vrlr/qAYIQbsyn46PIO9T0
U3PHwDq9qaMrZASVVNAMqkGYKOG9qfiqCFxAH+bgqg7nFPVBOF+ZDXkqoHiKrshk
JfCBPJIuqhe4pVvCzZOFmyEb4KioG/2h4jbqkf/KSHJhy39M3Y4I4JxP7a+hw3M8
lH/ioU/6E02xzYzFbB+fF880LyhUvC5p+ZFvxPq88qLzUs03dlmmwG1HD966aw8s
DaIC9hx34F/w5yOIK7tX18V6oxlDpp/uYld2Rt9hbz6D7cNEvQ8y/khstCI5vk2z
3RjJ1EmX5EDBeU30sA==
-----END CERTIFICATE-----

# cp cacert.pem 9a5ba575.0
然后push到系统里  放到/system/etc/security/cacerts/ 目录下  这里记得将权限改为644
不然还是有问题 


最后终于抓到https了 不过不知道咋回事 抓包延迟很高 不清楚是不是路由器的问题