jdk/test/javax/net/ssl/TLSv11/ExportableStreamCipher.java
author alanb
Thu, 01 Dec 2016 08:57:53 +0000
changeset 42338 a60f280f803c
parent 40949 be7a612613ae
permissions -rw-r--r--
8169069: Module system implementation refresh (11/2016) Reviewed-by: plevart, chegar, psandoz, mchung, alanb, dfuchs, naoto, coffeys, weijun Contributed-by: alan.bateman@oracle.com, mandy.chung@oracle.com, claes.redestad@oracle.com, mark.reinhold@oracle.com
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
7039
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
     1
/*
40949
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
     2
 * Copyright (c) 2010, 2016, Oracle and/or its affiliates. All rights reserved.
7039
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
     3
 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
     4
 *
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
     5
 * This code is free software; you can redistribute it and/or modify it
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
     6
 * under the terms of the GNU General Public License version 2 only, as
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
     7
 * published by the Free Software Foundation.  Oracle designates this
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
     8
 * particular file as subject to the "Classpath" exception as provided
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
     9
 * by Oracle in the LICENSE file that accompanied this code.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    10
 *
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    11
 * This code is distributed in the hope that it will be useful, but WITHOUT
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    12
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    13
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    14
 * version 2 for more details (a copy is included in the LICENSE file that
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    15
 * accompanied this code).
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    16
 *
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    17
 * You should have received a copy of the GNU General Public License version
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    18
 * 2 along with this work; if not, write to the Free Software Foundation,
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    19
 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    20
 *
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    21
 * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    22
 * or visit www.oracle.com if you need additional information or have any
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    23
 * questions.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    24
 */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    25
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 23052
diff changeset
    26
//
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 23052
diff changeset
    27
// SunJSSE does not support dynamic system properties, no way to re-use
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 23052
diff changeset
    28
// system properties in samevm/agentvm mode.
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 23052
diff changeset
    29
//
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 23052
diff changeset
    30
7039
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    31
/*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    32
 * @test
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    33
 * @bug 4873188
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    34
 * @summary Support TLS 1.1
40949
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    35
 * @modules java.security.jgss
42338
a60f280f803c 8169069: Module system implementation refresh (11/2016)
alanb
parents: 40949
diff changeset
    36
 *          java.security.jgss/sun.security.krb5:+open
a60f280f803c 8169069: Module system implementation refresh (11/2016)
alanb
parents: 40949
diff changeset
    37
 *          java.security.jgss/sun.security.krb5.internal:+open
a60f280f803c 8169069: Module system implementation refresh (11/2016)
alanb
parents: 40949
diff changeset
    38
 *          java.security.jgss/sun.security.krb5.internal.ccache
40949
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    39
 *          java.security.jgss/sun.security.krb5.internal.crypto
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    40
 *          java.security.jgss/sun.security.krb5.internal.ktab
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    41
 *          java.base/sun.security.util
10328
06c93c42bca0 7055363: jdk_security3 test target cleanup
weijun
parents: 7039
diff changeset
    42
 * @run main/othervm ExportableStreamCipher
7039
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    43
 * @author Xuelei Fan
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    44
 */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    45
40949
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    46
import java.io.IOException;
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    47
import java.io.InputStream;
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    48
import java.io.OutputStream;
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    49
import javax.net.ssl.SSLException;
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    50
import javax.net.ssl.SSLHandshakeException;
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    51
import javax.net.ssl.SSLServerSocket;
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    52
import javax.net.ssl.SSLServerSocketFactory;
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    53
import javax.net.ssl.SSLSocket;
be7a612613ae 8166032: Fix module dependencies for javax.SSL tests
skovalev
parents: 30904
diff changeset
    54
import javax.net.ssl.SSLSocketFactory;
7039
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    55
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    56
public class ExportableStreamCipher {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    57
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    58
    /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    59
     * =============================================================
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    60
     * Set the various variables needed for the tests, then
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    61
     * specify what tests to run on each side.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    62
     */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    63
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    64
    /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    65
     * Should we run the client or server in a separate thread?
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    66
     * Both sides can throw exceptions, but do you have a preference
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    67
     * as to which side should be the main thread.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    68
     */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    69
    static boolean separateServerThread = false;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    70
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    71
    /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    72
     * Where do we find the keystores?
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    73
     */
23052
241885315119 8032473: Restructure JSSE regression test hierarchy in jdk test
xuelei
parents: 14342
diff changeset
    74
    static String pathToStores = "../etc";
7039
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    75
    static String keyStoreFile = "keystore";
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    76
    static String trustStoreFile = "truststore";
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    77
    static String passwd = "passphrase";
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    78
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    79
    /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    80
     * Is the server ready to serve?
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    81
     */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    82
    volatile static boolean serverReady = false;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    83
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    84
    /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    85
     * Turn on SSL debugging?
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    86
     */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    87
    static boolean debug = false;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    88
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    89
    /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    90
     * If the client or server is doing some kind of object creation
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    91
     * that the other side depends on, and that thread prematurely
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    92
     * exits, you may experience a hang.  The test harness will
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    93
     * terminate all hung threads after its timeout has expired,
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    94
     * currently 3 minutes by default, but you might try to be
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    95
     * smart about it....
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    96
     */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    97
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    98
    /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
    99
     * Define the server side of the test.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   100
     *
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   101
     * If the server prematurely exits, serverReady will be set to true
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   102
     * to avoid infinite hangs.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   103
     */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   104
    void doServerSide() throws Exception {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   105
        SSLServerSocketFactory sslssf =
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   106
            (SSLServerSocketFactory) SSLServerSocketFactory.getDefault();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   107
        SSLServerSocket sslServerSocket =
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   108
            (SSLServerSocket) sslssf.createServerSocket(serverPort);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   109
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   110
        serverPort = sslServerSocket.getLocalPort();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   111
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   112
        /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   113
         * Signal Client, we're ready for his connect.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   114
         */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   115
        serverReady = true;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   116
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   117
        SSLSocket sslSocket = (SSLSocket) sslServerSocket.accept();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   118
        InputStream sslIS = sslSocket.getInputStream();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   119
        OutputStream sslOS = sslSocket.getOutputStream();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   120
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   121
        boolean interrupted = false;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   122
        try {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   123
            sslIS.read();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   124
            sslOS.write('A');
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   125
            sslOS.flush();
30904
ec0224270f90 8043758: Datagram Transport Layer Security (DTLS)
xuelei
parents: 23052
diff changeset
   126
        } catch (IOException ioe) {
7039
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   127
            // get the expected exception
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   128
            interrupted = true;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   129
        } finally {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   130
            sslSocket.close();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   131
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   132
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   133
        if (!interrupted) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   134
            throw new SSLHandshakeException(
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   135
                "A weak cipher suite is negotiated, " +
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   136
                "TLSv1.1 must not negotiate the exportable cipher suites.");
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   137
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   138
    }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   139
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   140
    /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   141
     * Define the client side of the test.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   142
     *
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   143
     * If the server prematurely exits, serverReady will be set to true
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   144
     * to avoid infinite hangs.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   145
     */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   146
    void doClientSide() throws Exception {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   147
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   148
        /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   149
         * Wait for server to get started.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   150
         */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   151
        while (!serverReady) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   152
            Thread.sleep(50);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   153
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   154
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   155
        SSLSocketFactory sslsf =
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   156
            (SSLSocketFactory) SSLSocketFactory.getDefault();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   157
        SSLSocket sslSocket = (SSLSocket)
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   158
            sslsf.createSocket("localhost", serverPort);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   159
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   160
        // enable TLSv1.1 only
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   161
        sslSocket.setEnabledProtocols(new String[] {"TLSv1.1"});
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   162
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   163
        // enable a exportable stream cipher
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   164
        sslSocket.setEnabledCipherSuites(
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   165
            new String[] {"SSL_RSA_EXPORT_WITH_RC4_40_MD5"});
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   166
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   167
        InputStream sslIS = sslSocket.getInputStream();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   168
        OutputStream sslOS = sslSocket.getOutputStream();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   169
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   170
        boolean interrupted = false;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   171
        try {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   172
            sslOS.write('B');
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   173
            sslOS.flush();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   174
            sslIS.read();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   175
        } catch (SSLException ssle) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   176
            // get the expected exception
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   177
            interrupted = true;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   178
        } finally {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   179
            sslSocket.close();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   180
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   181
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   182
        if (!interrupted) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   183
            throw new SSLHandshakeException(
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   184
                "A weak cipher suite is negotiated, " +
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   185
                "TLSv1.1 must not negotiate the exportable cipher suites.");
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   186
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   187
    }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   188
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   189
    /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   190
     * =============================================================
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   191
     * The remainder is just support stuff
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   192
     */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   193
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   194
    // use any free port by default
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   195
    volatile int serverPort = 0;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   196
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   197
    volatile Exception serverException = null;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   198
    volatile Exception clientException = null;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   199
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   200
    public static void main(String[] args) throws Exception {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   201
        String keyFilename =
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   202
            System.getProperty("test.src", ".") + "/" + pathToStores +
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   203
                "/" + keyStoreFile;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   204
        String trustFilename =
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   205
            System.getProperty("test.src", ".") + "/" + pathToStores +
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   206
                "/" + trustStoreFile;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   207
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   208
        System.setProperty("javax.net.ssl.keyStore", keyFilename);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   209
        System.setProperty("javax.net.ssl.keyStorePassword", passwd);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   210
        System.setProperty("javax.net.ssl.trustStore", trustFilename);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   211
        System.setProperty("javax.net.ssl.trustStorePassword", passwd);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   212
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   213
        if (debug)
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   214
            System.setProperty("javax.net.debug", "all");
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   215
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   216
        /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   217
         * Start the tests.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   218
         */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   219
        new ExportableStreamCipher();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   220
    }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   221
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   222
    Thread clientThread = null;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   223
    Thread serverThread = null;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   224
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   225
    /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   226
     * Primary constructor, used to drive remainder of the test.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   227
     *
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   228
     * Fork off the other side, then do your work.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   229
     */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   230
    ExportableStreamCipher() throws Exception {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   231
        try {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   232
            if (separateServerThread) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   233
                startServer(true);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   234
                startClient(false);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   235
            } else {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   236
                startClient(true);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   237
                startServer(false);
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   238
            }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   239
        } catch (Exception e) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   240
            // swallow for now.  Show later
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   241
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   242
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   243
        /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   244
         * Wait for other side to close down.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   245
         */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   246
        if (separateServerThread) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   247
            serverThread.join();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   248
        } else {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   249
            clientThread.join();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   250
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   251
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   252
        /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   253
         * When we get here, the test is pretty much over.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   254
         * Which side threw the error?
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   255
         */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   256
        Exception local;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   257
        Exception remote;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   258
        String whichRemote;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   259
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   260
        if (separateServerThread) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   261
            remote = serverException;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   262
            local = clientException;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   263
            whichRemote = "server";
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   264
        } else {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   265
            remote = clientException;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   266
            local = serverException;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   267
            whichRemote = "client";
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   268
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   269
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   270
        /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   271
         * If both failed, return the curthread's exception, but also
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   272
         * print the remote side Exception
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   273
         */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   274
        if ((local != null) && (remote != null)) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   275
            System.out.println(whichRemote + " also threw:");
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   276
            remote.printStackTrace();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   277
            System.out.println();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   278
            throw local;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   279
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   280
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   281
        if (remote != null) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   282
            throw remote;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   283
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   284
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   285
        if (local != null) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   286
            throw local;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   287
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   288
    }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   289
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   290
    void startServer(boolean newThread) throws Exception {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   291
        if (newThread) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   292
            serverThread = new Thread() {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   293
                public void run() {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   294
                    try {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   295
                        doServerSide();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   296
                    } catch (Exception e) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   297
                        /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   298
                         * Our server thread just died.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   299
                         *
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   300
                         * Release the client, if not active already...
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   301
                         */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   302
                        System.err.println("Server died...");
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   303
                        serverReady = true;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   304
                        serverException = e;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   305
                    }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   306
                }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   307
            };
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   308
            serverThread.start();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   309
        } else {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   310
            try {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   311
                doServerSide();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   312
            } catch (Exception e) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   313
                serverException = e;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   314
            } finally {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   315
                serverReady = true;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   316
            }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   317
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   318
    }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   319
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   320
    void startClient(boolean newThread) throws Exception {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   321
        if (newThread) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   322
            clientThread = new Thread() {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   323
                public void run() {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   324
                    try {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   325
                        doClientSide();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   326
                    } catch (Exception e) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   327
                        /*
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   328
                         * Our client thread just died.
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   329
                         */
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   330
                        System.err.println("Client died...");
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   331
                        clientException = e;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   332
                    }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   333
                }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   334
            };
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   335
            clientThread.start();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   336
        } else {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   337
            try {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   338
                doClientSide();
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   339
            } catch (Exception e) {
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   340
                clientException = e;
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   341
            }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   342
        }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   343
    }
6464c8e62a18 4873188: Support TLS 1.1
xuelei
parents:
diff changeset
   344
}