View Javadoc
1   /*
2    * Copyright 2022 The Netty Project
3    *
4    * The Netty Project licenses this file to you under the Apache License,
5    * version 2.0 (the "License"); you may not use this file except in compliance
6    * with the License. You may obtain a copy of the License at:
7    *
8    *   https://www.apache.org/licenses/LICENSE-2.0
9    *
10   * Unless required by applicable law or agreed to in writing, software
11   * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12   * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13   * License for the specific language governing permissions and limitations
14   * under the License.
15   */
16  package io.netty.handler.ssl.ocsp;
17  
18  import io.netty.buffer.ByteBuf;
19  import io.netty.channel.ChannelHandlerContext;
20  import io.netty.channel.ChannelOutboundHandler;
21  import io.netty.channel.ChannelPromise;
22  import io.netty.handler.codec.ByteToMessageDecoder;
23  import io.netty.handler.ssl.SslHandler;
24  import io.netty.handler.ssl.SslHandshakeCompletionEvent;
25  import io.netty.resolver.dns.DnsNameResolver;
26  import io.netty.resolver.dns.DnsNameResolverBuilder;
27  import io.netty.util.AttributeKey;
28  import io.netty.util.concurrent.Future;
29  import io.netty.util.concurrent.GenericFutureListener;
30  import io.netty.util.concurrent.Promise;
31  import io.netty.util.internal.SystemPropertyUtil;
32  import org.bouncycastle.cert.ocsp.BasicOCSPResp;
33  import org.bouncycastle.cert.ocsp.OCSPException;
34  import org.bouncycastle.cert.ocsp.RevokedStatus;
35  import org.bouncycastle.cert.ocsp.SingleResp;
36  
37  import java.net.SocketAddress;
38  import java.security.cert.Certificate;
39  import java.security.cert.X509Certificate;
40  import java.util.Date;
41  import java.util.List;
42  import java.util.concurrent.TimeUnit;
43  
44  import static io.netty.util.internal.ObjectUtil.checkNotNull;
45  
46  /**
47   * {@link OcspServerCertificateValidator} validates incoming server's certificate
48   * using OCSP. Once TLS handshake is completed, {@link SslHandshakeCompletionEvent#SUCCESS} is fired, validator
49   * will perform certificate validation using OCSP over HTTP/1.1 with the server's certificate issuer OCSP responder.
50   */
51  public class OcspServerCertificateValidator extends ByteToMessageDecoder implements ChannelOutboundHandler {
52      /**
53       * An attribute used to mark all channels created by the {@link OcspServerCertificateValidator}.
54       */
55      public static final AttributeKey<Boolean> OCSP_PIPELINE_ATTRIBUTE =
56              AttributeKey.newInstance("io.netty.handler.ssl.ocsp.pipeline");
57  
58      /**
59       * Tolerate some clock skew in the OCSP validity time. Default to 15 minutes, which is the same as the JDK.
60       */
61      private static final long CLOCK_SKEW_TOLERANCE_MILLIS = getClockSkewTolerance();
62  
63      private static long getClockSkewTolerance() {
64          long defaultToleranceSeconds = TimeUnit.MINUTES.toSeconds(15);
65          long maxToleranceSeconds = TimeUnit.DAYS.toSeconds(2);
66          long configuredToleranceSeconds = SystemPropertyUtil.getLong("io.netty.handler.ssl.ocsp.clockSkew",
67              SystemPropertyUtil.getLong("com.sun.security.ocsp.clockSkew", defaultToleranceSeconds));
68          if (configuredToleranceSeconds < 0 || configuredToleranceSeconds > maxToleranceSeconds) {
69              // Ignore negative and extremely large values.
70              configuredToleranceSeconds = defaultToleranceSeconds;
71          }
72          return TimeUnit.SECONDS.toMillis(configuredToleranceSeconds);
73      }
74  
75      private final boolean closeAndThrowIfNotValid;
76      private final boolean validateNonce;
77      private final IoTransport ioTransport;
78      private final DnsNameResolver dnsNameResolver;
79      private boolean ocspQueryInProgress;
80      private boolean readPending;
81  
82      /**
83       * Create a new {@link OcspServerCertificateValidator} instance without nonce validation
84       * on OCSP response, using default {@link IoTransport#DEFAULT} instance,
85       * default {@link DnsNameResolver} implementation and with {@link #closeAndThrowIfNotValid}
86       * set to {@code true}
87       */
88      public OcspServerCertificateValidator() {
89          this(false);
90      }
91  
92      /**
93       * Create a new {@link OcspServerCertificateValidator} instance with
94       * default {@link IoTransport#DEFAULT} instance and default {@link DnsNameResolver} implementation
95       * and {@link #closeAndThrowIfNotValid} set to {@code true}.
96       *
97       * @param validateNonce Set to {@code true} if we should force nonce validation on
98       *                      OCSP response else set to {@code false}
99       */
100     public OcspServerCertificateValidator(boolean validateNonce) {
101         this(validateNonce, IoTransport.DEFAULT);
102     }
103 
104     /**
105      * Create a new {@link OcspServerCertificateValidator} instance
106      *
107      * @param validateNonce Set to {@code true} if we should force nonce validation on
108      *                      OCSP response else set to {@code false}
109      * @param ioTransport   {@link IoTransport} to use
110      */
111     public OcspServerCertificateValidator(boolean validateNonce, IoTransport ioTransport) {
112         this(validateNonce, ioTransport, createDefaultResolver(ioTransport));
113     }
114 
115     /**
116      * Create a new {@link IoTransport} instance with {@link #closeAndThrowIfNotValid} set to {@code true}
117      *
118      * @param validateNonce   Set to {@code true} if we should force nonce validation on
119      *                        OCSP response else set to {@code false}
120      * @param ioTransport     {@link IoTransport} to use
121      * @param dnsNameResolver {@link DnsNameResolver} implementation to use
122      */
123     public OcspServerCertificateValidator(boolean validateNonce, IoTransport ioTransport,
124                                           DnsNameResolver dnsNameResolver) {
125         this(true, validateNonce, ioTransport, dnsNameResolver);
126     }
127 
128     /**
129      * Create a new {@link IoTransport} instance
130      *
131      * @param closeAndThrowIfNotValid If set to {@code true} then we will close the channel and throw an exception
132      *                                when certificate is not {@link OcspResponse.Status#VALID}.
133      *                                If set to {@code false} then we will simply pass the {@link OcspValidationEvent}
134      *                                to the next handler in pipeline and let it decide what to do.
135      * @param validateNonce           Set to {@code true} if we should force nonce validation on
136      *                                OCSP response else set to {@code false}
137      * @param ioTransport             {@link IoTransport} to use
138      * @param dnsNameResolver         {@link DnsNameResolver} implementation to use
139      */
140     public OcspServerCertificateValidator(boolean closeAndThrowIfNotValid, boolean validateNonce,
141                                           IoTransport ioTransport, DnsNameResolver dnsNameResolver) {
142         this.closeAndThrowIfNotValid = closeAndThrowIfNotValid;
143         this.validateNonce = validateNonce;
144         this.ioTransport = checkNotNull(ioTransport, "IoTransport");
145         this.dnsNameResolver = checkNotNull(dnsNameResolver, "DnsNameResolver");
146     }
147 
148     protected static DnsNameResolver createDefaultResolver(final IoTransport ioTransport) {
149         return new DnsNameResolverBuilder()
150                 .eventLoop(ioTransport.eventLoop())
151                 .datagramChannelFactory(ioTransport.datagramChannel())
152                 .socketChannelFactory(ioTransport.socketChannel())
153                 .build();
154     }
155 
156     @Override
157     protected void decode(ChannelHandlerContext ctx, ByteBuf in, List<Object> out) {
158         // Just buffer until the handler is removed which will happen once we did finish the OCSP processing.
159     }
160 
161     @Override
162     public void userEventTriggered(final ChannelHandlerContext ctx, final Object evt) throws Exception {
163         if (evt instanceof SslHandshakeCompletionEvent) {
164             SslHandshakeCompletionEvent sslHandshakeCompletionEvent = (SslHandshakeCompletionEvent) evt;
165 
166             // If TLS handshake was successful then only we will perform OCSP certificate validation.
167             // If not, then just forward the event to next handler in pipeline and remove ourselves from pipeline.
168             if (sslHandshakeCompletionEvent.isSuccess()) {
169                 Certificate[] certificates = ctx.pipeline().get(SslHandler.class)
170                         .engine()
171                         .getSession()
172                         .getPeerCertificates();
173 
174                 assert certificates.length >= 2 : "There must an end-entity certificate and issuer certificate";
175 
176                 Promise<BasicOCSPResp> ocspRespPromise = ctx.executor().newPromise();
177                 OcspClient.query((X509Certificate) certificates[0], (X509Certificate) certificates[1],
178                         validateNonce, ioTransport, dnsNameResolver, ocspRespPromise);
179                 ocspQueryInProgress = true;
180                 ocspRespPromise.addListener((GenericFutureListener<Future<BasicOCSPResp>>) future -> {
181                     ocspQueryInProgress = false;
182                     try {
183                         // If Future is success then we have successfully received OCSP response
184                         // from OCSP responder. We will validate it now and process.
185                         if (future.isSuccess()) {
186                             SingleResp response = future.getNow().getResponses()[0];
187 
188                             Date thisUpdate = response.getThisUpdate();
189                             Date nextUpdate = response.getNextUpdate();
190                             long now = System.currentTimeMillis();
191                             Date nowLower = new Date(now - CLOCK_SKEW_TOLERANCE_MILLIS);
192                             Date nowUpper = new Date(now + CLOCK_SKEW_TOLERANCE_MILLIS);
193                             if (thisUpdate == null || nowUpper.before(thisUpdate) ||
194                                 nowLower.after(nextUpdate == null ? thisUpdate : nextUpdate)) {
195                                 ctx.fireExceptionCaught(new IllegalStateException("OCSP Response is out-of-date"));
196                                 if (closeAndThrowIfNotValid) {
197                                     ctx.close();
198                                 }
199                                 return;
200                             }
201 
202                             OcspResponse.Status status;
203                             if (response.getCertStatus() == null) {
204                                 // 'null' means certificate is valid
205                                 status = OcspResponse.Status.VALID;
206                             } else if (response.getCertStatus() instanceof RevokedStatus) {
207                                 status = OcspResponse.Status.REVOKED;
208                             } else {
209                                 status = OcspResponse.Status.UNKNOWN;
210                             }
211 
212                             ctx.fireUserEventTriggered(new OcspValidationEvent(
213                                 new OcspResponse(status, thisUpdate, nextUpdate)));
214 
215                             // If Certificate is not VALID and 'closeAndThrowIfNotValid' is set
216                             // to 'true' then close the channel and throw an exception.
217                             if (status != OcspResponse.Status.VALID && closeAndThrowIfNotValid) {
218                                 // Certificate is not valid. Throw
219                                 ctx.fireExceptionCaught(new OCSPException(
220                                     "Certificate not valid. Status: " + status));
221                                 ctx.close();
222                             }
223                         } else {
224                             ctx.fireExceptionCaught(future.cause());
225                             if (closeAndThrowIfNotValid) {
226                                 ctx.close();
227                             }
228                         }
229                     } catch (Throwable th) {
230                         ctx.fireExceptionCaught(th);
231                         if (closeAndThrowIfNotValid) {
232                             ctx.close();
233                         }
234                     } finally {
235                         ctx.fireUserEventTriggered(evt);
236                         // Lets remove ourselves from the pipeline because we are done processing validation.
237                         ctx.pipeline().remove(this);
238                         if (readPending) {
239                             readPending = false;
240                             ctx.read();
241                         }
242                     }
243                 });
244             } else {
245                 ctx.fireUserEventTriggered(evt);
246             }
247         } else {
248             ctx.fireUserEventTriggered(evt);
249         }
250     }
251 
252     @Override
253     public void exceptionCaught(ChannelHandlerContext ctx, Throwable cause) {
254         ctx.close();
255     }
256 
257     @Override
258     public void bind(ChannelHandlerContext ctx, SocketAddress localAddress, ChannelPromise promise) throws Exception {
259         ctx.bind(localAddress, promise);
260     }
261 
262     @Override
263     public void connect(ChannelHandlerContext ctx, SocketAddress remoteAddress,
264                         SocketAddress localAddress, ChannelPromise promise) throws Exception {
265         ctx.connect(remoteAddress, localAddress, promise);
266     }
267 
268     @Override
269     public void disconnect(ChannelHandlerContext ctx, ChannelPromise promise) throws Exception {
270         ctx.disconnect(promise);
271     }
272 
273     @Override
274     public void close(ChannelHandlerContext ctx, ChannelPromise promise) throws Exception {
275         ctx.close(promise);
276     }
277 
278     @Override
279     public void deregister(ChannelHandlerContext ctx, ChannelPromise promise) throws Exception {
280         ctx.deregister(promise);
281     }
282 
283     @Override
284     public void read(ChannelHandlerContext ctx) throws Exception {
285         // Let's stop reading until we are done with the processing of the OCSP query.
286         if (ocspQueryInProgress) {
287             readPending = true;
288         } else {
289             readPending = false;
290             ctx.read();
291         }
292     }
293 
294     @Override
295     public void write(ChannelHandlerContext ctx, Object msg, ChannelPromise promise) throws Exception {
296         ctx.write(msg, promise);
297     }
298 
299     @Override
300     public void flush(ChannelHandlerContext ctx) throws Exception {
301         ctx.flush();
302     }
303 }