View Javadoc
1   /*
2    * Copyright 2018 The Netty Project
3    *
4    * The Netty Project licenses this file to you under the Apache License,
5    * version 2.0 (the "License"); you may not use this file except in compliance
6    * with the License. You may obtain a copy of the License at:
7    *
8    *   https://www.apache.org/licenses/LICENSE-2.0
9    *
10   * Unless required by applicable law or agreed to in writing, software
11   * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12   * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13   * License for the specific language governing permissions and limitations
14   * under the License.
15   */
16  package io.netty.handler.ssl;
17  
18  import io.netty.util.internal.EmptyArrays;
19  import io.netty.util.internal.SuppressJava6Requirement;
20  
21  import javax.net.ssl.ExtendedSSLSession;
22  import javax.net.ssl.SSLException;
23  import javax.net.ssl.SSLPeerUnverifiedException;
24  import javax.net.ssl.SSLSessionBindingEvent;
25  import javax.net.ssl.SSLSessionBindingListener;
26  import javax.security.cert.X509Certificate;
27  import java.security.Principal;
28  import java.security.cert.Certificate;
29  import java.util.Collections;
30  import java.util.List;
31  
32  /**
33   * Delegates all operations to a wrapped {@link OpenSslSession} except the methods defined by {@link ExtendedSSLSession}
34   * itself.
35   */
36  @SuppressJava6Requirement(reason = "Usage guarded by java version check")
37  abstract class ExtendedOpenSslSession extends ExtendedSSLSession implements OpenSslSession {
38  
39      // TODO: use OpenSSL API to actually fetch the real data but for now just do what Conscrypt does:
40      // https://github.com/google/conscrypt/blob/1.2.0/common/
41      // src/main/java/org/conscrypt/Java7ExtendedSSLSession.java#L32
42      private static final String[] LOCAL_SUPPORTED_SIGNATURE_ALGORITHMS = {
43              "SHA512withRSA", "SHA512withECDSA", "SHA384withRSA", "SHA384withECDSA", "SHA256withRSA",
44              "SHA256withECDSA", "SHA224withRSA", "SHA224withECDSA", "SHA1withRSA", "SHA1withECDSA",
45              "RSASSA-PSS",
46      };
47  
48      private final OpenSslSession wrapped;
49  
50      ExtendedOpenSslSession(OpenSslSession wrapped) {
51          this.wrapped = wrapped;
52      }
53  
54      // Use rawtypes an unchecked override to be able to also work on java7.
55      @Override
56      @SuppressWarnings({ "unchecked", "rawtypes" })
57      public abstract List getRequestedServerNames();
58  
59      // Do not mark as override so we can compile on java8.
60      public List<byte[]> getStatusResponses() {
61          // Just return an empty list for now until we support it as otherwise we will fail in java9
62          // because of their sun.security.ssl.X509TrustManagerImpl class.
63          return Collections.emptyList();
64      }
65  
66      @Override
67      public OpenSslSessionId sessionId() {
68          return wrapped.sessionId();
69      }
70  
71      @Override
72      public void setSessionId(OpenSslSessionId id) {
73          wrapped.setSessionId(id);
74      }
75  
76      @Override
77      public final void setLocalCertificate(Certificate[] localCertificate) {
78          wrapped.setLocalCertificate(localCertificate);
79      }
80  
81      @Override
82      public String[] getPeerSupportedSignatureAlgorithms() {
83          return EmptyArrays.EMPTY_STRINGS;
84      }
85  
86      @Override
87      public final void tryExpandApplicationBufferSize(int packetLengthDataOnly) {
88          wrapped.tryExpandApplicationBufferSize(packetLengthDataOnly);
89      }
90  
91      @Override
92      public final String[] getLocalSupportedSignatureAlgorithms() {
93          return LOCAL_SUPPORTED_SIGNATURE_ALGORITHMS.clone();
94      }
95  
96      @Override
97      public final byte[] getId() {
98          return wrapped.getId();
99      }
100 
101     @Override
102     public final OpenSslSessionContext getSessionContext() {
103         return wrapped.getSessionContext();
104     }
105 
106     @Override
107     public final long getCreationTime() {
108         return wrapped.getCreationTime();
109     }
110 
111     @Override
112     public final long getLastAccessedTime() {
113         return wrapped.getLastAccessedTime();
114     }
115 
116     @Override
117     public final void invalidate() {
118         wrapped.invalidate();
119     }
120 
121     @Override
122     public final boolean isValid() {
123         return wrapped.isValid();
124     }
125 
126     @Override
127     public final void putValue(String name, Object value) {
128         if (value instanceof SSLSessionBindingListener) {
129             // Decorate the value if needed so we submit the correct SSLSession instance
130             value = new SSLSessionBindingListenerDecorator((SSLSessionBindingListener) value);
131         }
132         wrapped.putValue(name, value);
133     }
134 
135     @Override
136     public final Object getValue(String s) {
137         Object value =  wrapped.getValue(s);
138         if (value instanceof SSLSessionBindingListenerDecorator) {
139             // Unwrap as needed so we return the original value
140             return ((SSLSessionBindingListenerDecorator) value).delegate;
141         }
142         return value;
143     }
144 
145     @Override
146     public final void removeValue(String s) {
147         wrapped.removeValue(s);
148     }
149 
150     @Override
151     public final String[] getValueNames() {
152         return wrapped.getValueNames();
153     }
154 
155     @Override
156     public final Certificate[] getPeerCertificates() throws SSLPeerUnverifiedException {
157         return wrapped.getPeerCertificates();
158     }
159 
160     @Override
161     public final Certificate[] getLocalCertificates() {
162         return wrapped.getLocalCertificates();
163     }
164 
165     @Override
166     public final X509Certificate[] getPeerCertificateChain() throws SSLPeerUnverifiedException {
167         return wrapped.getPeerCertificateChain();
168     }
169 
170     @Override
171     public final Principal getPeerPrincipal() throws SSLPeerUnverifiedException {
172         return wrapped.getPeerPrincipal();
173     }
174 
175     @Override
176     public final Principal getLocalPrincipal() {
177         return wrapped.getLocalPrincipal();
178     }
179 
180     @Override
181     public final String getCipherSuite() {
182         return wrapped.getCipherSuite();
183     }
184 
185     @Override
186     public String getProtocol() {
187         return wrapped.getProtocol();
188     }
189 
190     @Override
191     public final String getPeerHost() {
192         return wrapped.getPeerHost();
193     }
194 
195     @Override
196     public final int getPeerPort() {
197         return wrapped.getPeerPort();
198     }
199 
200     @Override
201     public final int getPacketBufferSize() {
202         return wrapped.getPacketBufferSize();
203     }
204 
205     @Override
206     public final int getApplicationBufferSize() {
207         return wrapped.getApplicationBufferSize();
208     }
209 
210     private final class SSLSessionBindingListenerDecorator implements SSLSessionBindingListener {
211 
212         final SSLSessionBindingListener delegate;
213 
214         SSLSessionBindingListenerDecorator(SSLSessionBindingListener delegate) {
215             this.delegate = delegate;
216         }
217 
218         @Override
219         public void valueBound(SSLSessionBindingEvent event) {
220             delegate.valueBound(new SSLSessionBindingEvent(ExtendedOpenSslSession.this, event.getName()));
221         }
222 
223         @Override
224         public void valueUnbound(SSLSessionBindingEvent event) {
225             delegate.valueUnbound(new SSLSessionBindingEvent(ExtendedOpenSslSession.this, event.getName()));
226         }
227     }
228 
229     @Override
230     public void handshakeFinished(byte[] id, String cipher, String protocol, byte[] peerCertificate,
231                                   byte[][] peerCertificateChain, long creationTime, long timeout) throws SSLException {
232         wrapped.handshakeFinished(id, cipher, protocol, peerCertificate, peerCertificateChain, creationTime, timeout);
233     }
234 
235     @Override
236     public String toString() {
237         return "ExtendedOpenSslSession{" +
238                 "wrapped=" + wrapped +
239                 '}';
240     }
241 }