Recently JSSA (Japan Smartphone Security Association) issued the 2017 edition of their Android Application Secure Design/Secure Coding Guidebook in which they have given examples of communicating via HTTPS with trusted as well as private certificates. For trusted certificate the code is supposed to check for:
- The server certificate is signed by a trusted third party certificate authority
- The period and other properties of the server certificate are valid
- The server's host name matches the CN (Common Name) or SAN (Subject Alternative Names) in the Subject field of the server certificate
The example code they have given for connecting to a secure server with trusted certificate is same as normal HTTP unsecured connection as below
.
.
URL url = new URL(strUrl);
response = (HttpURLConnection) url.openConnection();
response.setRequestMethod("GET");
response.connect();
checkResponse(response);
.
.
However, the sample given for private certificate connection seems to be a bit more elaborate and looks adequate for its intended purpose.
Expecting expert advice on the credibility of the sample code in securing the transaction, since they are not even using HttpsURLConnection, or any or all of the above mentioned validation goals seems to be left unaddressed as per the given sample code.
Thanks in advance.
PS: The document link for reference. http://www.jssec.org/dl/android_securecoding_en.pdf