jdk/test/sun/security/tools/jarsigner/concise_jarsigner.sh
author vinnie
Tue, 23 Dec 2014 16:30:57 +0000
changeset 28243 47080f9ae750
parent 24116 9f9b4ba34aad
child 34382 5d11306d6969
permissions -rw-r--r--
8044445: JEP 229: Create PKCS12 Keystores by Default Reviewed-by: mullan, weijun
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
     1
#
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
     2
# Copyright (c) 2009, 2014, Oracle and/or its affiliates. All rights reserved.
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
     3
# DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
     4
#
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
     5
# This code is free software; you can redistribute it and/or modify it
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
     6
# under the terms of the GNU General Public License version 2 only, as
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
     7
# published by the Free Software Foundation.
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
     8
#
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
     9
# This code is distributed in the hope that it will be useful, but WITHOUT
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    10
# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    11
# FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    12
# version 2 for more details (a copy is included in the LICENSE file that
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    13
# accompanied this code).
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    14
#
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    15
# You should have received a copy of the GNU General Public License version
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    16
# 2 along with this work; if not, write to the Free Software Foundation,
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    17
# Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    18
#
5506
202f599c92aa 6943119: Rebrand source copyright notices
ohair
parents: 2432
diff changeset
    19
# Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
202f599c92aa 6943119: Rebrand source copyright notices
ohair
parents: 2432
diff changeset
    20
# or visit www.oracle.com if you need additional information or have any
202f599c92aa 6943119: Rebrand source copyright notices
ohair
parents: 2432
diff changeset
    21
# questions.
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    22
#
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    23
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    24
# @test
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    25
# @bug 6802846
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    26
# @summary jarsigner needs enhanced cert validation(options)
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    27
#
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    28
# @run shell concise_jarsigner.sh
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    29
#
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    30
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    31
if [ "${TESTJAVA}" = "" ] ; then
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    32
  JAVAC_CMD=`which javac`
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    33
  TESTJAVA=`dirname $JAVAC_CMD`/..
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    34
fi
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    35
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    36
# set platform-dependent variables
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    37
OS=`uname -s`
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    38
case "$OS" in
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    39
  Windows_* )
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    40
    FS="\\"
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    41
    ;;
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    42
  * )
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    43
    FS="/"
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    44
    ;;
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    45
esac
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    46
14929
59377f4b9919 7109274: Restrict the use of certificates with RSA keys less than 1024 bits
xuelei
parents: 14342
diff changeset
    47
# Choose 1024-bit RSA to make sure it runs fine and fast on all platforms. In
59377f4b9919 7109274: Restrict the use of certificates with RSA keys less than 1024 bits
xuelei
parents: 14342
diff changeset
    48
# fact, every keyalg/keysize combination is OK for this test.
10333
96264d6bb3a3 7079144: concise_jarsigner.sh test often fails on solaris
weijun
parents: 7525
diff changeset
    49
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
    50
KS=js.ks
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
    51
KT="$TESTJAVA${FS}bin${FS}keytool ${TESTTOOLVMOPTS} -storepass changeit -keypass changeit -keystore $KS -keyalg rsa -keysize 1024"
24116
9f9b4ba34aad 8040321: keytool and jarsigner tests doesn't pass though VM tools to tools
weijun
parents: 23010
diff changeset
    52
JAR="$TESTJAVA${FS}bin${FS}jar ${TESTTOOLVMOPTS}"
9f9b4ba34aad 8040321: keytool and jarsigner tests doesn't pass though VM tools to tools
weijun
parents: 23010
diff changeset
    53
JARSIGNER="$TESTJAVA${FS}bin${FS}jarsigner ${TESTTOOLVMOPTS}"
9f9b4ba34aad 8040321: keytool and jarsigner tests doesn't pass though VM tools to tools
weijun
parents: 23010
diff changeset
    54
JAVAC="$TESTJAVA${FS}bin${FS}javac ${TESTTOOLVMOPTS} ${TESTJAVACOPTS}"
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    55
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
    56
rm $KS
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    57
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    58
echo class A1 {} > A1.java
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    59
echo class A2 {} > A2.java
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    60
echo class A3 {} > A3.java
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    61
echo class A4 {} > A4.java
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    62
echo class A5 {} > A5.java
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    63
echo class A6 {} > A6.java
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    64
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    65
$JAVAC A1.java A2.java A3.java A4.java A5.java A6.java
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    66
YEAR=`date +%Y`
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    67
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    68
# ==========================================================
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    69
# First part: output format
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    70
# ==========================================================
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    71
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    72
$KT -genkeypair -alias a1 -dname CN=a1 -validity 365
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    73
$KT -genkeypair -alias a2 -dname CN=a2 -validity 365
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    74
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    75
# a.jar includes 8 unsigned, 2 signed by a1 and a2, 2 signed by a3
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    76
$JAR cvf a.jar A1.class A2.class
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
    77
$JARSIGNER -keystore $KS -storepass changeit a.jar a1
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    78
$JAR uvf a.jar A3.class A4.class
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
    79
$JARSIGNER -keystore $KS -storepass changeit a.jar a2
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    80
$JAR uvf a.jar A5.class A6.class
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    81
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    82
# Verify OK
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    83
$JARSIGNER -verify a.jar
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    84
[ $? = 0 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    85
7525
16d2b5e6517a 7004168: jarsigner -verify checks for KeyUsage codesigning ext on all certs instead of just signing cert
weijun
parents: 7524
diff changeset
    86
# 4(chainNotValidated)+16(hasUnsignedEntry)
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    87
$JARSIGNER -verify a.jar -strict
7525
16d2b5e6517a 7004168: jarsigner -verify checks for KeyUsage codesigning ext on all certs instead of just signing cert
weijun
parents: 7524
diff changeset
    88
[ $? = 20 ] || exit $LINENO
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    89
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    90
# 16(hasUnsignedEntry)
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
    91
$JARSIGNER -verify a.jar -strict -keystore $KS -storepass changeit
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    92
[ $? = 16 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    93
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    94
# 16(hasUnsignedEntry)+32(notSignedByAlias)
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
    95
$JARSIGNER -verify a.jar a1 -strict -keystore $KS -storepass changeit
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    96
[ $? = 48 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    97
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
    98
# 16(hasUnsignedEntry)
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
    99
$JARSIGNER -verify a.jar a1 a2 -strict -keystore $KS -storepass changeit
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   100
[ $? = 16 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   101
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   102
# 12 entries all together
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   103
LINES=`$JARSIGNER -verify a.jar -verbose | grep $YEAR | wc -l`
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   104
[ $LINES = 12 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   105
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   106
# 12 entries all listed
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   107
LINES=`$JARSIGNER -verify a.jar -verbose:grouped | grep $YEAR | wc -l`
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   108
[ $LINES = 12 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   109
7524
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   110
# 4 groups: MANIFST, unrelated, signed, unsigned
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   111
LINES=`$JARSIGNER -verify a.jar -verbose:summary | grep $YEAR | wc -l`
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   112
[ $LINES = 4 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   113
7524
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   114
# still 4 groups, but MANIFEST group has no other file
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   115
LINES=`$JARSIGNER -verify a.jar -verbose:summary | grep "more)" | wc -l`
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   116
[ $LINES = 3 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   117
7524
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   118
# 5 groups: MANIFEST, unrelated, signed by a1/a2, signed by a2, unsigned
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   119
LINES=`$JARSIGNER -verify a.jar -verbose:summary -certs | grep $YEAR | wc -l`
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   120
[ $LINES = 5 ] || exit $LINENO
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   121
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   122
# 2 for MANIFEST, 2*2 for A1/A2, 2 for A3/A4
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   123
LINES=`$JARSIGNER -verify a.jar -verbose -certs | grep "\[certificate" | wc -l`
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   124
[ $LINES = 8 ] || exit $LINENO
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   125
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   126
# a1,a2 for MANIFEST, a1,a2 for A1/A2, a2 for A3/A4
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   127
LINES=`$JARSIGNER -verify a.jar -verbose:grouped -certs | grep "\[certificate" | wc -l`
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   128
[ $LINES = 5 ] || exit $LINENO
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   129
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   130
# a1,a2 for MANIFEST, a1,a2 for A1/A2, a2 for A3/A4
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   131
LINES=`$JARSIGNER -verify a.jar -verbose:summary -certs | grep "\[certificate" | wc -l`
7524
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   132
[ $LINES = 5 ] || exit $LINENO
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   133
7524
ec12e1e6fa20 7004035: signed jar with only META-INF/* inside is not verifiable
weijun
parents: 5506
diff changeset
   134
# still 5 groups, but MANIFEST group has no other file
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   135
LINES=`$JARSIGNER -verify a.jar -verbose:summary -certs | grep "more)" | wc -l`
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   136
[ $LINES = 4 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   137
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   138
# ==========================================================
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   139
# Second part: exit code 2, 4, 8
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   140
# 16 and 32 already covered in the first part
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   141
# ==========================================================
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   142
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   143
$KT -genkeypair -alias expired -dname CN=expired -startdate -10m
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   144
$KT -genkeypair -alias notyetvalid -dname CN=notyetvalid -startdate +1m
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   145
$KT -genkeypair -alias badku -dname CN=badku -ext KU=cRLSign -validity 365
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   146
$KT -genkeypair -alias badeku -dname CN=badeku -ext EKU=sa -validity 365
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   147
$KT -genkeypair -alias goodku -dname CN=goodku -ext KU=dig -validity 365
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   148
$KT -genkeypair -alias goodeku -dname CN=goodeku -ext EKU=codesign -validity 365
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   149
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   150
# badchain signed by ca, but ca is removed later
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   151
$KT -genkeypair -alias badchain -dname CN=badchain -validity 365
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   152
$KT -genkeypair -alias ca -dname CN=ca -ext bc -validity 365
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   153
$KT -certreq -alias badchain | $KT -gencert -alias ca -validity 365 | \
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   154
        $KT -importcert -alias badchain
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   155
$KT -delete -alias ca
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   156
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
   157
$JARSIGNER -strict -keystore $KS -storepass changeit a.jar expired
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   158
[ $? = 4 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   159
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
   160
$JARSIGNER -strict -keystore $KS -storepass changeit a.jar notyetvalid
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   161
[ $? = 4 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   162
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
   163
$JARSIGNER -strict -keystore $KS -storepass changeit a.jar badku
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   164
[ $? = 8 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   165
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
   166
$JARSIGNER -strict -keystore $KS -storepass changeit a.jar badeku
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   167
[ $? = 8 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   168
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
   169
$JARSIGNER -strict -keystore $KS -storepass changeit a.jar goodku
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   170
[ $? = 0 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   171
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
   172
$JARSIGNER -strict -keystore $KS -storepass changeit a.jar goodeku
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   173
[ $? = 0 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   174
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
   175
$JARSIGNER -strict -keystore $KS -storepass changeit a.jar badchain
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   176
[ $? = 4 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   177
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   178
$JARSIGNER -verify a.jar
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   179
[ $? = 0 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   180
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   181
# ==========================================================
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   182
# Third part: -certchain test
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   183
# ==========================================================
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   184
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   185
# altchain signed by ca2, but ca2 is removed later
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   186
$KT -genkeypair -alias altchain -dname CN=altchain -validity 365
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   187
$KT -genkeypair -alias ca2 -dname CN=ca2 -ext bc -validity 365
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   188
$KT -certreq -alias altchain | $KT -gencert -alias ca2 -validity 365 -rfc > certchain
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   189
$KT -exportcert -alias ca2 -rfc >> certchain
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   190
$KT -delete -alias ca2
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   191
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   192
# Now altchain is still self-signed
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
   193
$JARSIGNER -strict -keystore $KS -storepass changeit a.jar altchain
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   194
[ $? = 0 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   195
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   196
# If -certchain is used, then it's bad
28243
47080f9ae750 8044445: JEP 229: Create PKCS12 Keystores by Default
vinnie
parents: 24116
diff changeset
   197
$JARSIGNER -strict -keystore $KS -storepass changeit -certchain certchain a.jar altchain
2432
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   198
[ $? = 4 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   199
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   200
$JARSIGNER -verify a.jar
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   201
[ $? = 0 ] || exit $LINENO
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   202
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   203
echo OK
dc17f417ef85 6802846: jarsigner needs enhanced cert validation(options)
weijun
parents:
diff changeset
   204
exit 0