author | chegar |
Thu, 17 Oct 2019 20:54:25 +0100 | |
branch | datagramsocketimpl-branch |
changeset 58679 | 9c3209ff7550 |
parent 58678 | 9cf78a70fa4f |
parent 57500 | ab6867688e7a |
permissions | -rw-r--r-- |
2 | 1 |
/* |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
2 |
* Copyright (c) 1999, 2019, Oracle and/or its affiliates. All rights reserved. |
2 | 3 |
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. |
4 |
* |
|
5 |
* This code is free software; you can redistribute it and/or modify it |
|
6 |
* under the terms of the GNU General Public License version 2 only, as |
|
5506 | 7 |
* published by the Free Software Foundation. Oracle designates this |
2 | 8 |
* particular file as subject to the "Classpath" exception as provided |
5506 | 9 |
* by Oracle in the LICENSE file that accompanied this code. |
2 | 10 |
* |
11 |
* This code is distributed in the hope that it will be useful, but WITHOUT |
|
12 |
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or |
|
13 |
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License |
|
14 |
* version 2 for more details (a copy is included in the LICENSE file that |
|
15 |
* accompanied this code). |
|
16 |
* |
|
17 |
* You should have received a copy of the GNU General Public License version |
|
18 |
* 2 along with this work; if not, write to the Free Software Foundation, |
|
19 |
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. |
|
20 |
* |
|
5506 | 21 |
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA |
22 |
* or visit www.oracle.com if you need additional information or have any |
|
23 |
* questions. |
|
2 | 24 |
*/ |
25 |
||
26 |
package sun.security.ssl; |
|
27 |
||
50768 | 28 |
import java.util.ArrayList; |
29 |
import java.util.Collections; |
|
2 | 30 |
import java.util.Enumeration; |
10369
e9d2e59e53f0
7059542: JNDI name operations should be locale independent
xuelei
parents:
5506
diff
changeset
|
31 |
import java.util.Locale; |
2 | 32 |
import javax.net.ssl.SSLSession; |
33 |
import javax.net.ssl.SSLSessionContext; |
|
51398
3c389a284345
8209416: Refactoring GetPropertyAction calls in security libs
weijun
parents:
50768
diff
changeset
|
34 |
|
52764
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
35 |
import sun.security.action.GetIntegerAction; |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
36 |
import sun.security.action.GetPropertyAction; |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
37 |
import sun.security.util.Cache; |
2 | 38 |
|
39 |
||
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
40 |
/** |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
41 |
* @systemProperty jdk.tls.server.enableSessionTicketExtension} determines if the |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
42 |
* server will provide stateless session tickets, if the client supports it, |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
43 |
* as described in RFC 5077 and RFC 8446. a stateless session ticket |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
44 |
* contains the encrypted server's state which saves server resources. |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
45 |
* |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
46 |
* {@systemProperty jdk.tls.client.enableSessionTicketExtension} determines if the |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
47 |
* client will send an extension in the ClientHello in the pre-TLS 1.3. |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
48 |
* This extension allows the client to accept the server's session state for |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
49 |
* Server Side stateless resumption (RFC 5077). Setting the property to |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
50 |
* "true" turns this on, by default it is false. For TLS 1.3, the system |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
51 |
* property is not needed as this support is part of the spec. |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
52 |
* |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
53 |
* {@systemProperty jdk.tls.server.sessionTicketTimeout} determines how long |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
54 |
* a session in the server cache or the stateless resumption tickets are |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
55 |
* available for use. The value set by the property can be modified by |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
56 |
* {@code SSLSessionContext.setSessionTimeout()} during runtime. |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
57 |
* |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
58 |
*/ |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
59 |
|
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
60 |
final class SSLSessionContextImpl implements SSLSessionContext { |
52764
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
61 |
private final static int DEFAULT_MAX_CACHE_SIZE = 20480; |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
62 |
// Default lifetime of a session. 24 hours |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
63 |
final static int DEFAULT_SESSION_TIMEOUT = 86400; |
52764
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
64 |
|
50768 | 65 |
private final Cache<SessionId, SSLSessionImpl> sessionCache; |
10785
1d42311b6355
7092897: sun.security.util.Cache should be generified
mullan
parents:
10369
diff
changeset
|
66 |
// session cache, session id as key |
50768 | 67 |
private final Cache<String, SSLSessionImpl> sessionHostPortCache; |
10785
1d42311b6355
7092897: sun.security.util.Cache should be generified
mullan
parents:
10369
diff
changeset
|
68 |
// session cache, "host:port" as key |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
69 |
private int cacheLimit; // the max cache size |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
70 |
private int timeout; // timeout in seconds |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
71 |
|
57483
afeafa018937
8227551: Session Resumption without Server-Side State off by default
ascarpino
parents:
55336
diff
changeset
|
72 |
// Default setting for stateless session resumption support (RFC 5077) |
57500
ab6867688e7a
8228396: Re-enable Stateless Resumption On by default for merge to mainline
ascarpino
parents:
57483
diff
changeset
|
73 |
private boolean statelessSession = true; |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
74 |
|
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
75 |
// package private |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
76 |
SSLSessionContextImpl(boolean server) { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
77 |
timeout = DEFAULT_SESSION_TIMEOUT; |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
78 |
cacheLimit = getDefaults(server); // default cache size |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
79 |
|
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
80 |
// use soft reference |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
81 |
sessionCache = Cache.newSoftMemoryCache(cacheLimit, timeout); |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
82 |
sessionHostPortCache = Cache.newSoftMemoryCache(cacheLimit, timeout); |
2 | 83 |
} |
84 |
||
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
85 |
// Stateless sessions when available, but there is a cache |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
86 |
boolean statelessEnabled() { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
87 |
return statelessSession; |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
88 |
} |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
89 |
|
2 | 90 |
/** |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
91 |
* Returns the <code>SSLSession</code> bound to the specified session id. |
2 | 92 |
*/ |
14664
e71aa0962e70
8003950: Adds missing Override annotations and removes unnecessary imports in sun.security.ssl
xuelei
parents:
10785
diff
changeset
|
93 |
@Override |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
94 |
public SSLSession getSession(byte[] sessionId) { |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
95 |
if (sessionId == null) { |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
96 |
throw new NullPointerException("session id cannot be null"); |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
97 |
} |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
98 |
|
10785
1d42311b6355
7092897: sun.security.util.Cache should be generified
mullan
parents:
10369
diff
changeset
|
99 |
SSLSessionImpl sess = sessionCache.get(new SessionId(sessionId)); |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
100 |
if (!isTimedout(sess)) { |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
101 |
return sess; |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
102 |
} |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
103 |
|
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
104 |
return null; |
2 | 105 |
} |
106 |
||
107 |
/** |
|
108 |
* Returns an enumeration of the active SSL sessions. |
|
109 |
*/ |
|
14664
e71aa0962e70
8003950: Adds missing Override annotations and removes unnecessary imports in sun.security.ssl
xuelei
parents:
10785
diff
changeset
|
110 |
@Override |
2 | 111 |
public Enumeration<byte[]> getIds() { |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
112 |
SessionCacheVisitor scVisitor = new SessionCacheVisitor(); |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
113 |
sessionCache.accept(scVisitor); |
2 | 114 |
|
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
115 |
return scVisitor.getSessionIds(); |
2 | 116 |
} |
117 |
||
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
118 |
/** |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
119 |
* Sets the timeout limit for cached <code>SSLSession</code> objects |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
120 |
* |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
121 |
* Note that after reset the timeout, the cached session before |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
122 |
* should be timed within the shorter one of the old timeout and the |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
123 |
* new timeout. |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
124 |
*/ |
14664
e71aa0962e70
8003950: Adds missing Override annotations and removes unnecessary imports in sun.security.ssl
xuelei
parents:
10785
diff
changeset
|
125 |
@Override |
2 | 126 |
public void setSessionTimeout(int seconds) |
127 |
throws IllegalArgumentException { |
|
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
128 |
if (seconds < 0) { |
2 | 129 |
throw new IllegalArgumentException(); |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
130 |
} |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
131 |
|
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
132 |
if (timeout != seconds) { |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
133 |
sessionCache.setTimeout(seconds); |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
134 |
sessionHostPortCache.setTimeout(seconds); |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
135 |
timeout = seconds; |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
136 |
} |
2 | 137 |
} |
138 |
||
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
139 |
/** |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
140 |
* Gets the timeout limit for cached <code>SSLSession</code> objects |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
141 |
*/ |
14664
e71aa0962e70
8003950: Adds missing Override annotations and removes unnecessary imports in sun.security.ssl
xuelei
parents:
10785
diff
changeset
|
142 |
@Override |
2 | 143 |
public int getSessionTimeout() { |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
144 |
return timeout; |
2 | 145 |
} |
146 |
||
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
147 |
/** |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
148 |
* Sets the size of the cache used for storing |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
149 |
* <code>SSLSession</code> objects. |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
150 |
*/ |
14664
e71aa0962e70
8003950: Adds missing Override annotations and removes unnecessary imports in sun.security.ssl
xuelei
parents:
10785
diff
changeset
|
151 |
@Override |
2 | 152 |
public void setSessionCacheSize(int size) |
153 |
throws IllegalArgumentException { |
|
154 |
if (size < 0) |
|
155 |
throw new IllegalArgumentException(); |
|
156 |
||
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
157 |
if (cacheLimit != size) { |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
158 |
sessionCache.setCapacity(size); |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
159 |
sessionHostPortCache.setCapacity(size); |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
160 |
cacheLimit = size; |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
161 |
} |
2 | 162 |
} |
163 |
||
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
164 |
/** |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
165 |
* Gets the size of the cache used for storing |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
166 |
* <code>SSLSession</code> objects. |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
167 |
*/ |
14664
e71aa0962e70
8003950: Adds missing Override annotations and removes unnecessary imports in sun.security.ssl
xuelei
parents:
10785
diff
changeset
|
168 |
@Override |
2 | 169 |
public int getSessionCacheSize() { |
170 |
return cacheLimit; |
|
171 |
} |
|
172 |
||
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
173 |
// package-private method, used ONLY by ServerHandshaker |
2 | 174 |
SSLSessionImpl get(byte[] id) { |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
175 |
return (SSLSessionImpl)getSession(id); |
2 | 176 |
} |
177 |
||
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
178 |
// package-private method, used ONLY by ClientHandshaker |
2 | 179 |
SSLSessionImpl get(String hostname, int port) { |
180 |
/* |
|
181 |
* If no session caching info is available, we won't |
|
182 |
* get one, so exit before doing a lookup. |
|
183 |
*/ |
|
184 |
if (hostname == null && port == -1) { |
|
185 |
return null; |
|
186 |
} |
|
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
187 |
|
10785
1d42311b6355
7092897: sun.security.util.Cache should be generified
mullan
parents:
10369
diff
changeset
|
188 |
SSLSessionImpl sess = sessionHostPortCache.get(getKey(hostname, port)); |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
189 |
if (!isTimedout(sess)) { |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
190 |
return sess; |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
191 |
} |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
192 |
|
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
193 |
return null; |
2 | 194 |
} |
195 |
||
50768 | 196 |
private static String getKey(String hostname, int port) { |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
197 |
return (hostname + ":" + port).toLowerCase(Locale.ENGLISH); |
2 | 198 |
} |
199 |
||
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
200 |
// cache a SSLSession |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
201 |
// |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
202 |
// In SunJSSE implementation, a session is created while getting a |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
203 |
// client hello or a server hello message, and cached while the |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
204 |
// handshaking finished. |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
205 |
// Here we time the session from the time it cached instead of the |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
206 |
// time it created, which is a little longer than the expected. So |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
207 |
// please do check isTimedout() while getting entry from the cache. |
2 | 208 |
void put(SSLSessionImpl s) { |
209 |
sessionCache.put(s.getSessionId(), s); |
|
210 |
||
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
211 |
// If no hostname/port info is available, don't add this one. |
2 | 212 |
if ((s.getPeerHost() != null) && (s.getPeerPort() != -1)) { |
213 |
sessionHostPortCache.put( |
|
214 |
getKey(s.getPeerHost(), s.getPeerPort()), s); |
|
215 |
} |
|
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
216 |
|
2 | 217 |
s.setContext(this); |
218 |
} |
|
219 |
||
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
220 |
// package-private method, remove a cached SSLSession |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
221 |
void remove(SessionId key) { |
10785
1d42311b6355
7092897: sun.security.util.Cache should be generified
mullan
parents:
10369
diff
changeset
|
222 |
SSLSessionImpl s = sessionCache.get(key); |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
223 |
if (s != null) { |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
224 |
sessionCache.remove(key); |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
225 |
sessionHostPortCache.remove( |
50768 | 226 |
getKey(s.getPeerHost(), s.getPeerPort())); |
2 | 227 |
} |
228 |
} |
|
229 |
||
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
230 |
private int getDefaults(boolean server) { |
2 | 231 |
try { |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
232 |
String st; |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
233 |
|
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
234 |
// Property for Session Cache state |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
235 |
if (server) { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
236 |
st = GetPropertyAction.privilegedGetProperty( |
57500
ab6867688e7a
8228396: Re-enable Stateless Resumption On by default for merge to mainline
ascarpino
parents:
57483
diff
changeset
|
237 |
"jdk.tls.server.enableSessionTicketExtension", "true"); |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
238 |
} else { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
239 |
st = GetPropertyAction.privilegedGetProperty( |
57500
ab6867688e7a
8228396: Re-enable Stateless Resumption On by default for merge to mainline
ascarpino
parents:
57483
diff
changeset
|
240 |
"jdk.tls.client.enableSessionTicketExtension", "true"); |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
241 |
} |
57483
afeafa018937
8227551: Session Resumption without Server-Side State off by default
ascarpino
parents:
55336
diff
changeset
|
242 |
|
57500
ab6867688e7a
8228396: Re-enable Stateless Resumption On by default for merge to mainline
ascarpino
parents:
57483
diff
changeset
|
243 |
if (st.compareToIgnoreCase("false") == 0) { |
ab6867688e7a
8228396: Re-enable Stateless Resumption On by default for merge to mainline
ascarpino
parents:
57483
diff
changeset
|
244 |
statelessSession = false; |
ab6867688e7a
8228396: Re-enable Stateless Resumption On by default for merge to mainline
ascarpino
parents:
57483
diff
changeset
|
245 |
} |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
246 |
|
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
247 |
// Property for Session Ticket Timeout. The value can be changed |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
248 |
// by SSLSessionContext.setSessionTimeout(int) |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
249 |
String s = GetPropertyAction.privilegedGetProperty( |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
250 |
"jdk.tls.server.sessionTicketTimeout"); |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
251 |
if (s != null) { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
252 |
try { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
253 |
int t = Integer.parseInt(s); |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
254 |
if (t < 0 || |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
255 |
t > NewSessionTicket.MAX_TICKET_LIFETIME) { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
256 |
timeout = DEFAULT_SESSION_TIMEOUT; |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
257 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl")) { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
258 |
SSLLogger.warning("Invalid timeout given " + |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
259 |
"jdk.tls.server.sessionTicketTimeout: " + t + |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
260 |
". Set to default value " + timeout); |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
261 |
} |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
262 |
} else { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
263 |
timeout = t; |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
264 |
} |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
265 |
} catch (NumberFormatException e) { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
266 |
setSessionTimeout(DEFAULT_SESSION_TIMEOUT); |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
267 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl")) { |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
268 |
SSLLogger.warning("Invalid timeout for " + |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
269 |
"jdk.tls.server.sessionTicketTimeout: " + s + |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
270 |
". Set to default value " + timeout); |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
271 |
|
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
272 |
} |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
273 |
} |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
274 |
} |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52764
diff
changeset
|
275 |
|
52764
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
276 |
int defaultCacheLimit = GetIntegerAction.privilegedGetProperty( |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
277 |
"javax.net.ssl.sessionCacheSize", DEFAULT_MAX_CACHE_SIZE); |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
278 |
|
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
279 |
if (defaultCacheLimit >= 0) { |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
280 |
return defaultCacheLimit; |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
281 |
} else if (SSLLogger.isOn && SSLLogger.isOn("ssl")) { |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
282 |
SSLLogger.warning( |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
283 |
"invalid System Property javax.net.ssl.sessionCacheSize, " + |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
284 |
"use the default session cache size (" + |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
285 |
DEFAULT_MAX_CACHE_SIZE + ") instead"); |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
286 |
} |
2 | 287 |
} catch (Exception e) { |
52764
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
288 |
// unlikely, log it for safe |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
289 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl")) { |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
290 |
SSLLogger.warning( |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
291 |
"the System Property javax.net.ssl.sessionCacheSize is " + |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
292 |
"not available, use the default value (" + |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
293 |
DEFAULT_MAX_CACHE_SIZE + ") instead"); |
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
294 |
} |
2 | 295 |
} |
296 |
||
52764
8a85d21d9616
8210985: Update the default SSL session cache size to 20480
xuelei
parents:
51398
diff
changeset
|
297 |
return DEFAULT_MAX_CACHE_SIZE; |
2 | 298 |
} |
299 |
||
50768 | 300 |
private boolean isTimedout(SSLSession sess) { |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
301 |
if (timeout == 0) { |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
302 |
return false; |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
303 |
} |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
304 |
|
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
305 |
if ((sess != null) && ((sess.getCreationTime() + timeout * 1000L) |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
306 |
<= (System.currentTimeMillis()))) { |
2 | 307 |
sess.invalidate(); |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
308 |
return true; |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
309 |
} |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
310 |
|
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
311 |
return false; |
2 | 312 |
} |
313 |
||
50768 | 314 |
private final class SessionCacheVisitor |
10785
1d42311b6355
7092897: sun.security.util.Cache should be generified
mullan
parents:
10369
diff
changeset
|
315 |
implements Cache.CacheVisitor<SessionId, SSLSessionImpl> { |
50768 | 316 |
ArrayList<byte[]> ids = null; |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
317 |
|
10785
1d42311b6355
7092897: sun.security.util.Cache should be generified
mullan
parents:
10369
diff
changeset
|
318 |
// public void visit(java.util.Map<K,V> map) {} |
14664
e71aa0962e70
8003950: Adds missing Override annotations and removes unnecessary imports in sun.security.ssl
xuelei
parents:
10785
diff
changeset
|
319 |
@Override |
10785
1d42311b6355
7092897: sun.security.util.Cache should be generified
mullan
parents:
10369
diff
changeset
|
320 |
public void visit(java.util.Map<SessionId, SSLSessionImpl> map) { |
50768 | 321 |
ids = new ArrayList<>(map.size()); |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
322 |
|
10785
1d42311b6355
7092897: sun.security.util.Cache should be generified
mullan
parents:
10369
diff
changeset
|
323 |
for (SessionId key : map.keySet()) { |
1d42311b6355
7092897: sun.security.util.Cache should be generified
mullan
parents:
10369
diff
changeset
|
324 |
SSLSessionImpl value = map.get(key); |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
325 |
if (!isTimedout(value)) { |
50768 | 326 |
ids.add(key.getId()); |
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
327 |
} |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
328 |
} |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
329 |
} |
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
330 |
|
50768 | 331 |
Enumeration<byte[]> getSessionIds() { |
332 |
return ids != null ? Collections.enumeration(ids) : |
|
333 |
Collections.emptyEnumeration(); |
|
2060
75e464ce81af
4918870: Examine session cache implementation (sun.misc.Cache)
xuelei
parents:
2
diff
changeset
|
334 |
} |
2 | 335 |
} |
336 |
} |