Mercurial > 510Connectbot
annotate src/org/tn5250j/framework/transport/SSL/X509CertificateTrustManager.java @ 303:a218d9cd725b ganymed
add ecdsa key support everywhere
author | Carl Byington <carl@five-ten-sg.com> |
---|---|
date | Tue, 29 Jul 2014 20:24:24 -0700 |
parents | 77ac18bc1b2f |
children |
rev | line source |
---|---|
3 | 1 package org.tn5250j.framework.transport.SSL; |
2 | |
3 /* | |
4 * @(#)X509CertificateTrustManager.java | |
5 * | |
6 * Copyright: Copyright (c) 2001 | |
7 * | |
8 * This program is free software; you can redistribute it and/or modify | |
9 * it under the terms of the GNU General Public License as published by | |
10 * the Free Software Foundation; either version 2, or (at your option) | |
11 * any later version. | |
12 * | |
13 * This program is distributed in the hope that it will be useful, | |
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
16 * GNU General Public License for more details. | |
17 * | |
18 * You should have received a copy of the GNU General Public License | |
19 * along with this software; see the file COPYING. If not, write to | |
20 * the Free Software Foundation, Inc., 59 Temple Place, Suite 330, | |
21 * Boston, MA 02111-1307 USA | |
22 * | |
23 */ | |
24 import javax.net.ssl.TrustManager; | |
25 import javax.net.ssl.X509TrustManager; | |
26 import java.security.cert.X509Certificate; | |
27 import java.security.KeyStore; | |
28 import java.security.cert.CertificateException; | |
29 import java.util.ArrayList; | |
30 import java.util.Arrays; | |
31 | |
14 | 32 import com.five_ten_sg.connectbot.R; |
10 | 33 import com.five_ten_sg.connectbot.service.TerminalBridge; |
34 import com.five_ten_sg.connectbot.service.TerminalManager; | |
35 | |
3 | 36 |
37 /** | |
38 * This class is used to trust certificates exchanged during an SSL socket | |
39 * handshake. It allows the user to accept the certificate so that connections | |
40 * can be made without requiring the server to have a certificate signed by a | |
41 * CA (Verisign, Thawte, etc.). | |
10 | 42 * |
3 | 43 * @author Stephen M. Kennedy <skennedy@tenthpowertech.com> |
44 * @deprecated. no longer used. | |
45 * | |
46 */ | |
47 public class X509CertificateTrustManager implements X509TrustManager { | |
48 | |
112
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
49 KeyStore ks = null; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
50 TrustManager[] trustManagers; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
51 TerminalBridge bridge = null; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
52 TerminalManager manager = null; |
3 | 53 |
112
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
54 public X509CertificateTrustManager(TrustManager[] managers, KeyStore keyStore, TerminalBridge bridge, TerminalManager manager) { |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
55 this.bridge = bridge; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
56 this.manager = manager; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
57 trustManagers = managers; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
58 ks = keyStore; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
59 } |
3 | 60 |
112
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
61 public void checkClientTrusted(X509Certificate[] chain, String type) throws CertificateException { |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
62 throw new SecurityException("checkClientTrusted unsupported"); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
63 } |
10 | 64 |
65 | |
112
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
66 /** |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
67 * Checks the server certificate. If it isn't trusted by the trust manager |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
68 * passed to the constructor, then the user will be prompted to accept the |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
69 * certificate. |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
70 */ |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
71 public void checkServerTrusted(X509Certificate[] chain, String type) |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
72 throws CertificateException { |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
73 try { |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
74 for (int i = 0; i < trustManagers.length; i++) { |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
75 if (trustManagers[i] instanceof X509TrustManager) |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
76 ((X509TrustManager)trustManagers[i]).checkServerTrusted(chain, type); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
77 } |
10 | 78 |
112
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
79 return; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
80 } |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
81 catch (CertificateException ce) { |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
82 X509Certificate cert = chain[0]; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
83 String certInfo = "Version: " + cert.getVersion() + "\n"; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
84 certInfo = certInfo.concat("Serial Number: " + cert.getSerialNumber() + "\n"); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
85 certInfo = certInfo.concat("Signature Algorithm: " + cert.getSigAlgName() + "\n"); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
86 certInfo = certInfo.concat("Issuer: " + cert.getIssuerDN().getName() + "\n"); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
87 certInfo = certInfo.concat("Valid From: " + cert.getNotBefore() + "\n"); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
88 certInfo = certInfo.concat("Valid To: " + cert.getNotAfter() + "\n"); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
89 certInfo = certInfo.concat("Subject DN: " + cert.getSubjectDN().getName() + "\n"); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
90 certInfo = certInfo.concat("Public Key: " + cert.getPublicKey().getFormat() + "\n"); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
91 bridge.outputLine(manager.res.getString(R.string.host_certificate, certInfo)); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
92 Boolean result = bridge.promptHelper.requestBooleanPrompt(null, manager.res.getString(R.string.prompt_accept_certificate)); |
3 | 93 |
112
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
94 if ((result == null) || (!result.booleanValue())) { |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
95 throw new java.security.cert.CertificateException("Certificate Not Accepted"); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
96 } |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
97 } |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
98 } |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
99 |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
100 public X509Certificate[] getAcceptedIssuers() { |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
101 ArrayList<X509Certificate> list = new ArrayList<X509Certificate>(10); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
102 |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
103 for (int i = 0; i < trustManagers.length; i++) { |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
104 if (trustManagers[i] instanceof X509TrustManager) |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
105 list.addAll(Arrays.asList(((X509TrustManager)trustManagers[i]).getAcceptedIssuers())); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
106 } |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
107 |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
108 X509Certificate[] acceptedIssuers = new X509Certificate[list.size()]; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
109 acceptedIssuers = list.toArray(acceptedIssuers); |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
110 return acceptedIssuers; |
77ac18bc1b2f
cleanup java formatting
Carl Byington <carl@five-ten-sg.com>
parents:
14
diff
changeset
|
111 } |
3 | 112 } |