Go 开发 http tls 附带证书请求

作者: 小新

发布于 2020-01-14 | 最后更新 2020-01-14


在微信支付H5接口中,要求请求必须附带pem证书,那么我们现在就写个简单的例子,请看代码:

package wget
 
import (
	"crypto/tls"
	"crypto/x509"
	"io"
	"net/http"
	"os"
)
 
func client(rootCa, rootKey string) *http.Client {
	var tr *http.Transport
	certs, err := tls.LoadX509KeyPair(rootCa, rootKey)
	if err != nil {
		tr = &http.Transport{
			TLSClientConfig: &tls.Config{InsecureSkipVerify: true},
		}
	} else {
		ca, err := x509.ParseCertificate(certs.Certificate[0])
		if err != nil {
			return &http.Client{Transport: tr}
		}
		pool := x509.NewCertPool()
		pool.AddCert(ca)
 
		tr = &http.Transport{
			TLSClientConfig: &tls.Config{RootCAs: pool},
		}
 
	}
	return &http.Client{Transport: tr}
}
 
func Wget(url, name, rootCa, rootKey string) (bool, error) {
	resp, err := client(rootCa, rootKey).Get(url)
	if err != nil {
		return false, err
	}
	defer resp.Body.Close()
	File, err := os.Create(name)
	if err != nil {
		return false, err
	}
	io.Copy(File, resp.Body)
	File.Close()
	return true, nil
}

调用方式:

//调用
Wget("http://test.com","test","path/cert.pem","path/key.pem")