Mercurial > 510Connectbot
comparison src/org/tn5250j/framework/transport/SSL/X509CertificateTrustManager.java @ 3:e8d2a24e85c6 tn5250
adding tn5250 files
author | Carl Byington <carl@five-ten-sg.com> |
---|---|
date | Thu, 22 May 2014 12:11:10 -0700 |
parents | |
children | e773d0952613 |
comparison
equal
deleted
inserted
replaced
2:a01665cb683d | 3:e8d2a24e85c6 |
---|---|
1 package org.tn5250j.framework.transport.SSL; | |
2 | |
3 /* | |
4 * @(#)X509CertificateTrustManager.java | |
5 * | |
6 * Copyright: Copyright (c) 2001 | |
7 * | |
8 * This program is free software; you can redistribute it and/or modify | |
9 * it under the terms of the GNU General Public License as published by | |
10 * the Free Software Foundation; either version 2, or (at your option) | |
11 * any later version. | |
12 * | |
13 * This program is distributed in the hope that it will be useful, | |
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
16 * GNU General Public License for more details. | |
17 * | |
18 * You should have received a copy of the GNU General Public License | |
19 * along with this software; see the file COPYING. If not, write to | |
20 * the Free Software Foundation, Inc., 59 Temple Place, Suite 330, | |
21 * Boston, MA 02111-1307 USA | |
22 * | |
23 */ | |
24 import javax.net.ssl.TrustManager; | |
25 import javax.net.ssl.X509TrustManager; | |
26 import java.security.cert.X509Certificate; | |
27 import java.security.KeyStore; | |
28 import java.security.cert.CertificateException; | |
29 import java.util.ArrayList; | |
30 import java.util.Arrays; | |
31 | |
32 import javax.swing.JOptionPane; | |
33 | |
34 /** | |
35 * This class is used to trust certificates exchanged during an SSL socket | |
36 * handshake. It allows the user to accept the certificate so that connections | |
37 * can be made without requiring the server to have a certificate signed by a | |
38 * CA (Verisign, Thawte, etc.). | |
39 * | |
40 * @author Stephen M. Kennedy <skennedy@tenthpowertech.com> | |
41 * @deprecated. no longer used. | |
42 * | |
43 */ | |
44 public class X509CertificateTrustManager implements X509TrustManager { | |
45 | |
46 KeyStore ks = null; | |
47 TrustManager[] trustManagers; | |
48 //X509TrustManager trustManager = null; | |
49 | |
50 public X509CertificateTrustManager(TrustManager[] managers, KeyStore keyStore) { | |
51 trustManagers = managers; | |
52 ks = keyStore; | |
53 } | |
54 | |
55 public void checkClientTrusted(X509Certificate[] chain, String type) throws CertificateException { | |
56 throw new SecurityException("checkClientTrusted unsupported"); | |
57 } | |
58 | |
59 | |
60 /** | |
61 * Checks the server certificate. If it isn't trusted by the trust manager | |
62 * passed to the constructor, then the user will be prompted to accept the | |
63 * certificate. | |
64 */ | |
65 public void checkServerTrusted(X509Certificate[] chain, String type) | |
66 throws CertificateException { | |
67 try { | |
68 for (int i=0; i<trustManagers.length; i++) { | |
69 if (trustManagers[i] instanceof X509TrustManager) | |
70 ((X509TrustManager)trustManagers[i]).checkServerTrusted(chain,type); | |
71 } | |
72 return; | |
73 } catch (CertificateException ce) { | |
74 X509Certificate cert = chain[0]; | |
75 String certInfo = "Version: " + cert.getVersion() + "\n"; | |
76 certInfo = certInfo.concat("Serial Number: " + cert.getSerialNumber()+"\n"); | |
77 certInfo = certInfo.concat("Signature Algorithm: " + cert.getSigAlgName()+"\n"); | |
78 certInfo = certInfo.concat("Issuer: " + cert.getIssuerDN().getName()+"\n"); | |
79 certInfo = certInfo.concat("Valid From: " + cert.getNotBefore()+"\n"); | |
80 certInfo = certInfo.concat("Valid To: " + cert.getNotAfter()+"\n"); | |
81 certInfo = certInfo.concat("Subject DN: " + cert.getSubjectDN().getName()+"\n"); | |
82 certInfo = certInfo.concat("Public Key: " + cert.getPublicKey().getFormat()+"\n"); | |
83 | |
84 int accept = JOptionPane.showConfirmDialog(null,certInfo, | |
85 "Accept Certificate",javax.swing.JOptionPane.YES_NO_OPTION); | |
86 if (accept != JOptionPane.YES_OPTION) { | |
87 throw new java.security.cert.CertificateException("Certificate Not Accepted"); | |
88 } | |
89 } | |
90 } | |
91 | |
92 public X509Certificate[] getAcceptedIssuers() { | |
93 ArrayList<X509Certificate> list = new ArrayList<X509Certificate>(10); | |
94 for (int i=0; i<trustManagers.length; i++) { | |
95 if (trustManagers[i] instanceof X509TrustManager) | |
96 list.addAll(Arrays.asList(((X509TrustManager)trustManagers[i]).getAcceptedIssuers())); | |
97 } | |
98 X509Certificate[] acceptedIssuers = new X509Certificate[list.size()]; | |
99 acceptedIssuers = list.toArray(acceptedIssuers); | |
100 return acceptedIssuers; | |
101 } | |
102 } |