author | hb |
Tue, 05 Dec 2017 21:26:11 +0530 | |
changeset 48198 | bf64ff40f4eb |
parent 48144 | 364207a23251 |
child 50760 | 8e296de294e7 |
permissions | -rw-r--r-- |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
1 |
/* |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
2 |
* Copyright (c) 2017, Oracle and/or its affiliates. All rights reserved. |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
3 |
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
4 |
* |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
5 |
* This code is free software; you can redistribute it and/or modify it |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
6 |
* under the terms of the GNU General Public License version 2 only, as |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
7 |
* published by the Free Software Foundation. |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
8 |
* |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
9 |
* This code is distributed in the hope that it will be useful, but WITHOUT |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
10 |
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
11 |
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
12 |
* version 2 for more details (a copy is included in the LICENSE file that |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
13 |
* accompanied this code). |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
14 |
* |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
15 |
* You should have received a copy of the GNU General Public License version |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
16 |
* 2 along with this work; if not, write to the Free Software Foundation, |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
17 |
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
18 |
* |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
19 |
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
20 |
* or visit www.oracle.com if you need additional information or have any |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
21 |
* questions. |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
22 |
*/ |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
23 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
24 |
/* @test |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
25 |
* @bug 5016517 |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
26 |
* @summary Test Hashed passwords |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
27 |
* @library /test/lib |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
28 |
* @modules java.management |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
29 |
* @build HashedPasswordFileTest |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
30 |
* @run testng/othervm HashedPasswordFileTest |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
31 |
* |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
32 |
*/ |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
33 |
|
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
34 |
import jdk.test.lib.Utils; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
35 |
import jdk.test.lib.process.ProcessTools; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
36 |
import org.testng.Assert; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
37 |
import org.testng.annotations.AfterClass; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
38 |
import org.testng.annotations.Test; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
39 |
|
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
40 |
import javax.management.MBeanServer; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
41 |
import javax.management.remote.*; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
42 |
import java.io.*; |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
43 |
import java.lang.management.ManagementFactory; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
44 |
import java.nio.charset.StandardCharsets; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
45 |
import java.nio.file.FileSystems; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
46 |
import java.nio.file.Files; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
47 |
import java.nio.file.attribute.PosixFilePermission; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
48 |
import java.security.MessageDigest; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
49 |
import java.security.NoSuchAlgorithmException; |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
50 |
import java.util.*; |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
51 |
import java.util.List; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
52 |
import java.util.Set; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
53 |
import java.util.concurrent.*; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
54 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
55 |
@Test |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
56 |
public class HashedPasswordFileTest { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
57 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
58 |
private final String[] randomWords = {"accost", "savoie", "bogart", "merest", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
59 |
"azuela", "hoodie", "bursal", "lingua", "wincey", "trilby", "egesta", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
60 |
"wester", "gilgai", "weinek", "ochone", "sanest", "gainst", "defang", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
61 |
"ranket", "mayhem", "tagger", "timber", "eggcup", "mhren", "colloq", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
62 |
"dreamy", "hattie", "rootle", "bloody", "helyne", "beater", "cosine", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
63 |
"enmity", "outbox", "issuer", "lumina", "dekker", "vetoed", "dennis", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
64 |
"strove", "gurnet", "talkie", "bennie", "behove", "coates", "shiloh", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
65 |
"yemeni", "boleyn", "coaxal", "irne"}; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
66 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
67 |
private final String[] hashAlgs = { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
68 |
"MD2", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
69 |
"MD5", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
70 |
"SHA-1", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
71 |
"SHA-224", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
72 |
"SHA-256", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
73 |
"SHA-384", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
74 |
"SHA-512/224", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
75 |
"SHA-512/256", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
76 |
"SHA3-224", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
77 |
"SHA3-256", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
78 |
"SHA3-384", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
79 |
"SHA3-512" |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
80 |
}; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
81 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
82 |
private final Random random = Utils.getRandomInstance(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
83 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
84 |
private JMXConnectorServer cs; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
85 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
86 |
private String randomWord() { |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
87 |
int idx = random.nextInt(randomWords.length); |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
88 |
return randomWords[idx]; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
89 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
90 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
91 |
private String[] getHash(String algorithm, String password) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
92 |
try { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
93 |
byte[] salt = new byte[64]; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
94 |
random.nextBytes(salt); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
95 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
96 |
MessageDigest digest = MessageDigest.getInstance(algorithm); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
97 |
digest.reset(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
98 |
digest.update(salt); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
99 |
byte[] hash = digest.digest(password.getBytes(StandardCharsets.UTF_8)); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
100 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
101 |
String saltStr = Base64.getEncoder().encodeToString(salt); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
102 |
String hashStr = Base64.getEncoder().encodeToString(hash); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
103 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
104 |
return new String[]{saltStr, hashStr}; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
105 |
} catch (NoSuchAlgorithmException ex) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
106 |
throw new RuntimeException(ex); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
107 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
108 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
109 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
110 |
private String getPasswordFilePath() { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
111 |
String testDir = System.getProperty("test.src"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
112 |
String testFileName = "jmxremote.password"; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
113 |
return testDir + File.separator + testFileName; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
114 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
115 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
116 |
private File createNewPasswordFile() throws IOException { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
117 |
File file = new File(getPasswordFilePath()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
118 |
if (file.exists()) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
119 |
file.delete(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
120 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
121 |
file.createNewFile(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
122 |
return file; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
123 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
124 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
125 |
private Map<String, String> generateClearTextPasswordFile() throws IOException { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
126 |
File file = createNewPasswordFile(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
127 |
Map<String, String> props = new HashMap<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
128 |
BufferedWriter br; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
129 |
try (FileWriter fw = new FileWriter(file)) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
130 |
br = new BufferedWriter(fw); |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
131 |
int numentries = random.nextInt(5) + 3; |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
132 |
for (int i = 0; i < numentries; i++) { |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
133 |
String username; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
134 |
do { |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
135 |
username = randomWord(); |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
136 |
} while (props.get(username) != null); |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
137 |
String password = randomWord(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
138 |
props.put(username, password); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
139 |
br.write(username + " " + password + "\n"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
140 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
141 |
br.flush(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
142 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
143 |
br.close(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
144 |
return props; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
145 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
146 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
147 |
private boolean isPasswordFileHashed() throws IOException { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
148 |
BufferedReader br; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
149 |
boolean result; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
150 |
try (FileReader fr = new FileReader(getPasswordFilePath())) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
151 |
br = new BufferedReader(fr); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
152 |
result = br.lines().anyMatch(line -> { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
153 |
if (line.startsWith("#")) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
154 |
return false; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
155 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
156 |
String[] tokens = line.split("\\s+"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
157 |
return tokens.length == 3 || tokens.length == 4; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
158 |
}); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
159 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
160 |
br.close(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
161 |
return result; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
162 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
163 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
164 |
private Map<String, String> generateHashedPasswordFile() throws IOException { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
165 |
File file = createNewPasswordFile(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
166 |
Map<String, String> props = new HashMap<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
167 |
BufferedWriter br; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
168 |
try (FileWriter fw = new FileWriter(file)) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
169 |
br = new BufferedWriter(fw); |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
170 |
int numentries = random.nextInt(5) + 3; |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
171 |
for (int i = 0; i < numentries; i++) { |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
172 |
String username; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
173 |
do { |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
174 |
username = randomWord(); |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
175 |
} while (props.get(username) != null); |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
176 |
String password = randomWord(); |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
177 |
String alg = hashAlgs[random.nextInt(hashAlgs.length)]; |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
178 |
String[] b64str = getHash(alg, password); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
179 |
br.write(username + " " + b64str[0] + " " + b64str[1] + " " + alg + "\n"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
180 |
props.put(username, password); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
181 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
182 |
br.flush(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
183 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
184 |
br.close(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
185 |
return props; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
186 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
187 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
188 |
private JMXServiceURL createServerSide(boolean useHash) |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
189 |
throws IOException { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
190 |
MBeanServer mbs = ManagementFactory.getPlatformMBeanServer(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
191 |
JMXServiceURL url = new JMXServiceURL("rmi", null, 0); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
192 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
193 |
HashMap<String, Object> env = new HashMap<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
194 |
env.put("jmx.remote.x.password.file", getPasswordFilePath()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
195 |
env.put("jmx.remote.x.password.toHashes", useHash ? "true" : "false"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
196 |
cs = JMXConnectorServerFactory.newJMXConnectorServer(url, env, mbs); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
197 |
cs.start(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
198 |
return cs.getAddress(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
199 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
200 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
201 |
@Test |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
202 |
public void testClearTextPasswordFile() throws IOException { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
203 |
Boolean[] bvals = new Boolean[]{true, false}; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
204 |
for (boolean bval : bvals) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
205 |
try { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
206 |
Map<String, String> credentials = generateClearTextPasswordFile(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
207 |
JMXServiceURL serverUrl = createServerSide(bval); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
208 |
for (Map.Entry<String, String> entry : credentials.entrySet()) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
209 |
HashMap<String, Object> env = new HashMap<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
210 |
env.put("jmx.remote.credentials", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
211 |
new String[]{entry.getKey(), entry.getValue()}); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
212 |
try (JMXConnector cc = JMXConnectorFactory.connect(serverUrl, env)) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
213 |
cc.getMBeanServerConnection(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
214 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
215 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
216 |
Assert.assertEquals(isPasswordFileHashed(), bval); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
217 |
} finally { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
218 |
cs.stop(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
219 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
220 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
221 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
222 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
223 |
@Test |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
224 |
public void testReadOnlyPasswordFile() throws IOException { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
225 |
Boolean[] bvals = new Boolean[]{true, false}; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
226 |
for (boolean bval : bvals) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
227 |
try { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
228 |
Map<String, String> credentials = generateClearTextPasswordFile(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
229 |
File file = new File(getPasswordFilePath()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
230 |
file.setReadOnly(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
231 |
JMXServiceURL serverUrl = createServerSide(bval); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
232 |
for (Map.Entry<String, String> entry : credentials.entrySet()) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
233 |
HashMap<String, Object> env = new HashMap<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
234 |
env.put("jmx.remote.credentials", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
235 |
new String[]{entry.getKey(), entry.getValue()}); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
236 |
try (JMXConnector cc = JMXConnectorFactory.connect(serverUrl, env)) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
237 |
cc.getMBeanServerConnection(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
238 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
239 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
240 |
Assert.assertEquals(isPasswordFileHashed(), false); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
241 |
} finally { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
242 |
cs.stop(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
243 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
244 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
245 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
246 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
247 |
@Test |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
248 |
public void testHashedPasswordFile() throws IOException { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
249 |
Boolean[] bvals = new Boolean[]{true, false}; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
250 |
for (boolean bval : bvals) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
251 |
try { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
252 |
Map<String, String> credentials = generateHashedPasswordFile(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
253 |
JMXServiceURL serverUrl = createServerSide(bval); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
254 |
Assert.assertEquals(isPasswordFileHashed(), true); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
255 |
for (Map.Entry<String, String> entry : credentials.entrySet()) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
256 |
HashMap<String, Object> env = new HashMap<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
257 |
env.put("jmx.remote.credentials", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
258 |
new String[]{entry.getKey(), entry.getValue()}); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
259 |
try (JMXConnector cc = JMXConnectorFactory.connect(serverUrl, env)) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
260 |
cc.getMBeanServerConnection(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
261 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
262 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
263 |
} finally { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
264 |
cs.stop(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
265 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
266 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
267 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
268 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
269 |
private static class SimpleJMXClient implements Callable { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
270 |
private final JMXServiceURL url; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
271 |
private final Map<String, String> credentials; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
272 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
273 |
public SimpleJMXClient(JMXServiceURL url, Map<String, String> credentials) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
274 |
this.url = url; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
275 |
this.credentials = credentials; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
276 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
277 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
278 |
@Override |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
279 |
public Object call() throws Exception { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
280 |
for (Map.Entry<String, String> entry : credentials.entrySet()) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
281 |
HashMap<String, Object> env = new HashMap<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
282 |
env.put("jmx.remote.credentials", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
283 |
new String[]{entry.getKey(), entry.getValue()}); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
284 |
try (JMXConnector cc = JMXConnectorFactory.connect(url, env)) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
285 |
cc.getMBeanServerConnection(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
286 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
287 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
288 |
return null; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
289 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
290 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
291 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
292 |
@Test |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
293 |
public void testMultipleClients() throws Throwable { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
294 |
Map<String, String> credentials = generateClearTextPasswordFile(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
295 |
JMXServiceURL serverUrl = createServerSide(true); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
296 |
Assert.assertEquals(isPasswordFileHashed(), false); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
297 |
// create random number of clients |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
298 |
int numClients = random.nextInt(20) + 10; |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
299 |
List<Future> futures = new ArrayList<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
300 |
ExecutorService executor = Executors.newFixedThreadPool(numClients); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
301 |
for (int i = 0; i < numClients; i++) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
302 |
Future future = executor.submit(new SimpleJMXClient(serverUrl, credentials)); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
303 |
futures.add(future); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
304 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
305 |
try { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
306 |
for (Future future : futures) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
307 |
future.get(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
308 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
309 |
} catch (InterruptedException ex) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
310 |
Thread.currentThread().interrupt(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
311 |
} catch (ExecutionException ex) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
312 |
throw ex.getCause(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
313 |
} finally { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
314 |
executor.shutdown(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
315 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
316 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
317 |
Assert.assertEquals(isPasswordFileHashed(), true); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
318 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
319 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
320 |
@Test |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
321 |
public void testPasswordChange() throws IOException { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
322 |
try { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
323 |
Map<String, String> credentials = generateClearTextPasswordFile(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
324 |
JMXServiceURL serverUrl = createServerSide(true); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
325 |
Assert.assertEquals(isPasswordFileHashed(), false); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
326 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
327 |
for (Map.Entry<String, String> entry : credentials.entrySet()) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
328 |
HashMap<String, Object> env = new HashMap<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
329 |
env.put("jmx.remote.credentials", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
330 |
new String[]{entry.getKey(), entry.getValue()}); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
331 |
try (JMXConnector cc = JMXConnectorFactory.connect(serverUrl, env)) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
332 |
cc.getMBeanServerConnection(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
333 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
334 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
335 |
Assert.assertEquals(isPasswordFileHashed(), true); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
336 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
337 |
// Read the file back. Add new entries. Change passwords for few |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
338 |
BufferedReader br = new BufferedReader(new FileReader(getPasswordFilePath())); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
339 |
String line; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
340 |
StringBuilder sbuild = new StringBuilder(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
341 |
while ((line = br.readLine()) != null) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
342 |
if (line.trim().startsWith("#")) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
343 |
sbuild.append(line).append("\n"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
344 |
continue; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
345 |
} |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
346 |
|
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
347 |
// Change password for random entries |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
348 |
if (random.nextBoolean()) { |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
349 |
String[] tokens = line.split("\\s+"); |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
350 |
if ((tokens.length == 4 || tokens.length == 3)) { |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
351 |
String password = randomWord(); |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
352 |
credentials.put(tokens[0], password); |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
353 |
sbuild.append(tokens[0]).append(" ").append(password).append("\n"); |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
354 |
} |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
355 |
} else { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
356 |
sbuild.append(line).append("\n"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
357 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
358 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
359 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
360 |
// Add new entries in clear |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
361 |
int newentries = random.nextInt(2) + 3; |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
362 |
for (int i = 0; i < newentries; i++) { |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
363 |
String username; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
364 |
do { |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
365 |
username = randomWord(); |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
366 |
} while (credentials.get(username) != null); |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
367 |
String password = randomWord(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
368 |
credentials.put(username, password); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
369 |
sbuild.append(username).append(" ").append(password).append("\n"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
370 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
371 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
372 |
// Add new entries as a hash |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
373 |
int numentries = random.nextInt(2) + 3; |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
374 |
for (int i = 0; i < numentries; i++) { |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
375 |
String username; |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
376 |
do { |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
377 |
username = randomWord(); |
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
378 |
} while (credentials.get(username) != null); |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
379 |
String password = randomWord(); |
48198
bf64ff40f4eb
8192909: Invalid username or password in HashedPasswordFileTest.java
hb
parents:
48144
diff
changeset
|
380 |
String alg = hashAlgs[random.nextInt(hashAlgs.length)]; |
48144
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
381 |
String[] b64str = getHash(alg, password); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
382 |
credentials.put(username, password); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
383 |
sbuild.append(username).append(" ").append(b64str[0]) |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
384 |
.append(" ").append(b64str[1]).append(" ") |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
385 |
.append(alg).append("\n"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
386 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
387 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
388 |
try (BufferedWriter bw = new BufferedWriter(new FileWriter(getPasswordFilePath()))) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
389 |
bw.write(sbuild.toString()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
390 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
391 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
392 |
for (Map.Entry<String, String> entry : credentials.entrySet()) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
393 |
HashMap<String, Object> env = new HashMap<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
394 |
env.put("jmx.remote.credentials", |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
395 |
new String[]{entry.getKey(), entry.getValue()}); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
396 |
try (JMXConnector cc = JMXConnectorFactory.connect(serverUrl, env)) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
397 |
cc.getMBeanServerConnection(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
398 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
399 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
400 |
} finally { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
401 |
cs.stop(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
402 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
403 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
404 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
405 |
@Test |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
406 |
public void testDefaultAgent() throws Exception { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
407 |
List<String> pbArgs = new ArrayList<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
408 |
int port = Utils.getFreePort(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
409 |
generateClearTextPasswordFile(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
410 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
411 |
// This will run only on a POSIX compliant system |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
412 |
if (!FileSystems.getDefault().supportedFileAttributeViews().contains("posix")) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
413 |
return; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
414 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
415 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
416 |
// Make sure only owner is able to read/write the file or else |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
417 |
// default agent will fail to start |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
418 |
File file = new File(getPasswordFilePath()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
419 |
Set<PosixFilePermission> perms = new HashSet<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
420 |
perms.add(PosixFilePermission.OWNER_READ); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
421 |
perms.add(PosixFilePermission.OWNER_WRITE); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
422 |
Files.setPosixFilePermissions(file.toPath(), perms); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
423 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
424 |
pbArgs.add("-cp"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
425 |
pbArgs.add(System.getProperty("test.class.path")); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
426 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
427 |
pbArgs.add("-Dcom.sun.management.jmxremote.port=" + port); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
428 |
pbArgs.add("-Dcom.sun.management.jmxremote.authenticate=true"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
429 |
pbArgs.add("-Dcom.sun.management.jmxremote.password.file=" + file.getAbsolutePath()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
430 |
pbArgs.add("-Dcom.sun.management.jmxremote.ssl=false"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
431 |
pbArgs.add(TestApp.class.getSimpleName()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
432 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
433 |
ProcessBuilder pb = ProcessTools.createJavaProcessBuilder( |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
434 |
pbArgs.toArray(new String[0])); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
435 |
Process process = ProcessTools.startProcess( |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
436 |
TestApp.class.getSimpleName(), |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
437 |
pb); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
438 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
439 |
if (process.waitFor() != 0) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
440 |
throw new RuntimeException("Test Failed : Error starting default agent"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
441 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
442 |
Assert.assertEquals(isPasswordFileHashed(), true); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
443 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
444 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
445 |
@Test |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
446 |
public void testDefaultAgentNoHash() throws Exception { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
447 |
List<String> pbArgs = new ArrayList<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
448 |
int port = Utils.getFreePort(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
449 |
generateClearTextPasswordFile(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
450 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
451 |
// This will run only on a POSIX compliant system |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
452 |
if (!FileSystems.getDefault().supportedFileAttributeViews().contains("posix")) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
453 |
return; |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
454 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
455 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
456 |
// Make sure only owner is able to read/write the file or else |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
457 |
// default agent will fail to start |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
458 |
File file = new File(getPasswordFilePath()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
459 |
Set<PosixFilePermission> perms = new HashSet<>(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
460 |
perms.add(PosixFilePermission.OWNER_READ); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
461 |
perms.add(PosixFilePermission.OWNER_WRITE); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
462 |
Files.setPosixFilePermissions(file.toPath(), perms); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
463 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
464 |
pbArgs.add("-cp"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
465 |
pbArgs.add(System.getProperty("test.class.path")); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
466 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
467 |
pbArgs.add("-Dcom.sun.management.jmxremote.port=" + port); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
468 |
pbArgs.add("-Dcom.sun.management.jmxremote.authenticate=true"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
469 |
pbArgs.add("-Dcom.sun.management.jmxremote.password.file=" + file.getAbsolutePath()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
470 |
pbArgs.add("-Dcom.sun.management.jmxremote.password.toHashes=false"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
471 |
pbArgs.add("-Dcom.sun.management.jmxremote.ssl=false"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
472 |
pbArgs.add(TestApp.class.getSimpleName()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
473 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
474 |
ProcessBuilder pb = ProcessTools.createJavaProcessBuilder( |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
475 |
pbArgs.toArray(new String[0])); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
476 |
Process process = ProcessTools.startProcess( |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
477 |
TestApp.class.getSimpleName(), |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
478 |
pb); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
479 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
480 |
if (process.waitFor() != 0) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
481 |
throw new RuntimeException("Test Failed : Error starting default agent"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
482 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
483 |
Assert.assertEquals(isPasswordFileHashed(), false); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
484 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
485 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
486 |
@AfterClass |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
487 |
public void cleanUp() { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
488 |
File file = new File(getPasswordFilePath()); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
489 |
if (file.exists()) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
490 |
file.delete(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
491 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
492 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
493 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
494 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
495 |
class TestApp { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
496 |
|
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
497 |
public static void main(String[] args) throws IOException { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
498 |
try { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
499 |
JMXServiceURL url = new JMXServiceURL("service:jmx:rmi:///jndi/rmi://localhost:" |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
500 |
+ System.getProperty("com.sun.management.jmxremote.port") + "/jmxrmi"); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
501 |
Map<String, Object> env = new HashMap<>(1); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
502 |
// any dummy credentials will do. We just have to trigger password hashing |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
503 |
env.put("jmx.remote.credentials", new String[]{"a", "a"}); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
504 |
try (JMXConnector cc = JMXConnectorFactory.connect(url, env)) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
505 |
cc.getMBeanServerConnection(); |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
506 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
507 |
} catch (SecurityException ex) { |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
508 |
// Catch authentication failure here |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
509 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
510 |
} |
364207a23251
5016517: Replace plaintext passwords by hashed passwords for out-of-the-box JMX Agent
hb
parents:
diff
changeset
|
511 |
} |