author | ascarpino |
Tue, 11 Jun 2019 16:31:37 -0700 | |
changeset 55336 | c2398053ee90 |
parent 52512 | 1838347a803b |
permissions | -rw-r--r-- |
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
1 |
/* |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
2 |
* Copyright (c) 2018, 2019 Oracle and/or its affiliates. All rights reserved. |
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
3 |
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
4 |
* |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
5 |
* This code is free software; you can redistribute it and/or modify it |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
6 |
* under the terms of the GNU General Public License version 2 only, as |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
7 |
* published by the Free Software Foundation. |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
8 |
* |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
9 |
* This code is distributed in the hope that it will be useful, but WITHOUT |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
10 |
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
11 |
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
12 |
* version 2 for more details (a copy is included in the LICENSE file that |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
13 |
* accompanied this code). |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
14 |
* |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
15 |
* You should have received a copy of the GNU General Public License version |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
16 |
* 2 along with this work; if not, write to the Free Software Foundation, |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
17 |
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
18 |
* |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
19 |
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
20 |
* or visit www.oracle.com if you need additional information or have any |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
21 |
* questions. |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
22 |
*/ |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
23 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
24 |
/* |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
25 |
* @test |
52512
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
26 |
* @bug 8206929 8212885 |
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
27 |
* @summary ensure that client only resumes a session if certain properties |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
28 |
* of the session are compatible with the new connection |
55336
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
29 |
* @run main/othervm -Djdk.tls.client.protocols=TLSv1.2 -Djdk.tls.server.enableSessionTicketExtension=false -Djdk.tls.client.enableSessionTicketExtension=false ResumeChecksClient BASIC |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
30 |
* @run main/othervm -Djdk.tls.client.protocols=TLSv1.2 -Djdk.tls.server.enableSessionTicketExtension=true -Djdk.tls.client.enableSessionTicketExtension=false ResumeChecksClient BASIC |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
31 |
* @run main/othervm -Djdk.tls.client.protocols=TLSv1.2 -Djdk.tls.server.enableSessionTicketExtension=true -Djdk.tls.client.enableSessionTicketExtension=true ResumeChecksClient BASIC |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
32 |
* @run main/othervm -Djdk.tls.client.protocols=TLSv1.3 -Djdk.tls.server.enableSessionTicketExtension=true -Djdk.tls.client.enableSessionTicketExtension=true ResumeChecksClient BASIC |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
33 |
* @run main/othervm -Djdk.tls.client.protocols=TLSv1.2 -Djdk.tls.server.enableSessionTicketExtension=false -Djdk.tls.client.enableSessionTicketExtension=true ResumeChecksClient BASIC |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
34 |
* @run main/othervm -Djdk.tls.client.protocols=TLSv1.3 -Djdk.tls.server.enableSessionTicketExtension=false -Djdk.tls.client.enableSessionTicketExtension=true ResumeChecksClient BASIC |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
35 |
* @run main/othervm -Djdk.tls.server.enableSessionTicketExtension=false -Djdk.tls.client.enableSessionTicketExtension=true ResumeChecksClient BASIC |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
36 |
* @run main/othervm -Djdk.tls.server.enableSessionTicketExtension=true -Djdk.tls.client.enableSessionTicketExtension=true ResumeChecksClient VERSION_2_TO_3 |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
37 |
* @run main/othervm -Djdk.tls.server.enableSessionTicketExtension=true -Djdk.tls.client.enableSessionTicketExtension=true ResumeChecksClient VERSION_3_TO_2 |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
38 |
* @run main/othervm -Djdk.tls.client.protocols=TLSv1.3 -Djdk.tls.server.enableSessionTicketExtension=true -Djdk.tls.client.enableSessionTicketExtension=true ResumeChecksClient CIPHER_SUITE |
c2398053ee90
8211018: Session Resumption without Server-Side State
ascarpino
parents:
52512
diff
changeset
|
39 |
* @run main/othervm -Djdk.tls.client.protocols=TLSv1.3 -Djdk.tls.server.enableSessionTicketExtension=true -Djdk.tls.client.enableSessionTicketExtension=true ResumeChecksClient SIGNATURE_SCHEME |
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
40 |
* |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
41 |
*/ |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
42 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
43 |
import javax.net.*; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
44 |
import javax.net.ssl.*; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
45 |
import java.io.*; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
46 |
import java.security.*; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
47 |
import java.net.*; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
48 |
import java.util.*; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
49 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
50 |
public class ResumeChecksClient { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
51 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
52 |
static String pathToStores = "../../../../javax/net/ssl/etc"; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
53 |
static String keyStoreFile = "keystore"; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
54 |
static String trustStoreFile = "truststore"; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
55 |
static String passwd = "passphrase"; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
56 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
57 |
enum TestMode { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
58 |
BASIC, |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
59 |
VERSION_2_TO_3, |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
60 |
VERSION_3_TO_2, |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
61 |
CIPHER_SUITE, |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
62 |
SIGNATURE_SCHEME |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
63 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
64 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
65 |
public static void main(String[] args) throws Exception { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
66 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
67 |
TestMode mode = TestMode.valueOf(args[0]); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
68 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
69 |
String keyFilename = |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
70 |
System.getProperty("test.src", "./") + "/" + pathToStores + |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
71 |
"/" + keyStoreFile; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
72 |
String trustFilename = |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
73 |
System.getProperty("test.src", "./") + "/" + pathToStores + |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
74 |
"/" + trustStoreFile; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
75 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
76 |
System.setProperty("javax.net.ssl.keyStore", keyFilename); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
77 |
System.setProperty("javax.net.ssl.keyStorePassword", passwd); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
78 |
System.setProperty("javax.net.ssl.trustStore", trustFilename); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
79 |
System.setProperty("javax.net.ssl.trustStorePassword", passwd); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
80 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
81 |
Server server = startServer(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
82 |
server.signal(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
83 |
SSLContext sslContext = SSLContext.getDefault(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
84 |
while (!server.started) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
85 |
Thread.yield(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
86 |
} |
52512
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
87 |
SSLSession firstSession = connect(sslContext, server.port, mode, false); |
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
88 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
89 |
server.signal(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
90 |
long secondStartTime = System.currentTimeMillis(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
91 |
Thread.sleep(10); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
92 |
SSLSession secondSession = connect(sslContext, server.port, mode, true); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
93 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
94 |
server.go = false; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
95 |
server.signal(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
96 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
97 |
switch (mode) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
98 |
case BASIC: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
99 |
// fail if session is not resumed |
52512
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
100 |
checkResumedSession(firstSession, secondSession); |
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
101 |
break; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
102 |
case VERSION_2_TO_3: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
103 |
case VERSION_3_TO_2: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
104 |
case CIPHER_SUITE: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
105 |
case SIGNATURE_SCHEME: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
106 |
// fail if a new session is not created |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
107 |
if (secondSession.getCreationTime() <= secondStartTime) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
108 |
throw new RuntimeException("Existing session was used"); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
109 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
110 |
break; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
111 |
default: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
112 |
throw new RuntimeException("unknown mode: " + mode); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
113 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
114 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
115 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
116 |
private static class NoSig implements AlgorithmConstraints { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
117 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
118 |
private final String alg; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
119 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
120 |
NoSig(String alg) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
121 |
this.alg = alg; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
122 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
123 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
124 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
125 |
private boolean test(String a) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
126 |
return !a.toLowerCase().contains(alg.toLowerCase()); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
127 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
128 |
|
52512
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
129 |
@Override |
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
130 |
public boolean permits(Set<CryptoPrimitive> primitives, Key key) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
131 |
return true; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
132 |
} |
52512
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
133 |
@Override |
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
134 |
public boolean permits(Set<CryptoPrimitive> primitives, |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
135 |
String algorithm, AlgorithmParameters parameters) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
136 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
137 |
return test(algorithm); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
138 |
} |
52512
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
139 |
@Override |
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
140 |
public boolean permits(Set<CryptoPrimitive> primitives, |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
141 |
String algorithm, Key key, AlgorithmParameters parameters) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
142 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
143 |
return test(algorithm); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
144 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
145 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
146 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
147 |
private static SSLSession connect(SSLContext sslContext, int port, |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
148 |
TestMode mode, boolean second) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
149 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
150 |
try { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
151 |
SSLSocket sock = (SSLSocket) |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
152 |
sslContext.getSocketFactory().createSocket(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
153 |
SSLParameters params = sock.getSSLParameters(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
154 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
155 |
switch (mode) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
156 |
case BASIC: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
157 |
// do nothing to ensure resumption works |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
158 |
break; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
159 |
case VERSION_2_TO_3: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
160 |
if (second) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
161 |
params.setProtocols(new String[] {"TLSv1.3"}); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
162 |
} else { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
163 |
params.setProtocols(new String[] {"TLSv1.2"}); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
164 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
165 |
break; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
166 |
case VERSION_3_TO_2: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
167 |
if (second) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
168 |
params.setProtocols(new String[] {"TLSv1.2"}); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
169 |
} else { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
170 |
params.setProtocols(new String[] {"TLSv1.3"}); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
171 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
172 |
break; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
173 |
case CIPHER_SUITE: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
174 |
if (second) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
175 |
params.setCipherSuites( |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
176 |
new String[] {"TLS_AES_256_GCM_SHA384"}); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
177 |
} else { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
178 |
params.setCipherSuites( |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
179 |
new String[] {"TLS_AES_128_GCM_SHA256"}); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
180 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
181 |
break; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
182 |
case SIGNATURE_SCHEME: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
183 |
AlgorithmConstraints constraints = |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
184 |
params.getAlgorithmConstraints(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
185 |
if (second) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
186 |
params.setAlgorithmConstraints(new NoSig("ecdsa")); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
187 |
} else { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
188 |
params.setAlgorithmConstraints(new NoSig("rsa")); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
189 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
190 |
break; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
191 |
default: |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
192 |
throw new RuntimeException("unknown mode: " + mode); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
193 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
194 |
sock.setSSLParameters(params); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
195 |
sock.connect(new InetSocketAddress("localhost", port)); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
196 |
PrintWriter out = new PrintWriter( |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
197 |
new OutputStreamWriter(sock.getOutputStream())); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
198 |
out.println("message"); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
199 |
out.flush(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
200 |
BufferedReader reader = new BufferedReader( |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
201 |
new InputStreamReader(sock.getInputStream())); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
202 |
String inMsg = reader.readLine(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
203 |
System.out.println("Client received: " + inMsg); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
204 |
SSLSession result = sock.getSession(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
205 |
sock.close(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
206 |
return result; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
207 |
} catch (Exception ex) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
208 |
// unexpected exception |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
209 |
throw new RuntimeException(ex); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
210 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
211 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
212 |
|
52512
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
213 |
private static void checkResumedSession(SSLSession initSession, |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
214 |
SSLSession resSession) throws Exception { |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
215 |
StringBuilder diffLog = new StringBuilder(); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
216 |
|
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
217 |
// Initial and resumed SSLSessions should have the same creation |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
218 |
// times so they get invalidated together. |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
219 |
long initCt = initSession.getCreationTime(); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
220 |
long resumeCt = resSession.getCreationTime(); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
221 |
if (initCt != resumeCt) { |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
222 |
diffLog.append("Session creation time is different. Initial: "). |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
223 |
append(initCt).append(", Resumed: ").append(resumeCt). |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
224 |
append("\n"); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
225 |
} |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
226 |
|
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
227 |
// Ensure that peer and local certificate lists are preserved |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
228 |
if (!Arrays.equals(initSession.getLocalCertificates(), |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
229 |
resSession.getLocalCertificates())) { |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
230 |
diffLog.append("Local certificate mismatch between initial " + |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
231 |
"and resumed sessions\n"); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
232 |
} |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
233 |
|
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
234 |
if (!Arrays.equals(initSession.getPeerCertificates(), |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
235 |
resSession.getPeerCertificates())) { |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
236 |
diffLog.append("Peer certificate mismatch between initial " + |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
237 |
"and resumed sessions\n"); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
238 |
} |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
239 |
|
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
240 |
// Buffer sizes should also be the same |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
241 |
if (initSession.getApplicationBufferSize() != |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
242 |
resSession.getApplicationBufferSize()) { |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
243 |
diffLog.append(String.format( |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
244 |
"App Buffer sizes differ: Init: %d, Res: %d\n", |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
245 |
initSession.getApplicationBufferSize(), |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
246 |
resSession.getApplicationBufferSize())); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
247 |
} |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
248 |
|
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
249 |
if (initSession.getPacketBufferSize() != |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
250 |
resSession.getPacketBufferSize()) { |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
251 |
diffLog.append(String.format( |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
252 |
"Packet Buffer sizes differ: Init: %d, Res: %d\n", |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
253 |
initSession.getPacketBufferSize(), |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
254 |
resSession.getPacketBufferSize())); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
255 |
} |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
256 |
|
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
257 |
// Cipher suite should match |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
258 |
if (!initSession.getCipherSuite().equals( |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
259 |
resSession.getCipherSuite())) { |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
260 |
diffLog.append(String.format( |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
261 |
"CipherSuite does not match - Init: %s, Res: %s\n", |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
262 |
initSession.getCipherSuite(), resSession.getCipherSuite())); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
263 |
} |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
264 |
|
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
265 |
// Peer host/port should match |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
266 |
if (!initSession.getPeerHost().equals(resSession.getPeerHost()) || |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
267 |
initSession.getPeerPort() != resSession.getPeerPort()) { |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
268 |
diffLog.append(String.format( |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
269 |
"Host/Port mismatch - Init: %s/%d, Res: %s/%d\n", |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
270 |
initSession.getPeerHost(), initSession.getPeerPort(), |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
271 |
resSession.getPeerHost(), resSession.getPeerPort())); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
272 |
} |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
273 |
|
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
274 |
// Check protocol |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
275 |
if (!initSession.getProtocol().equals(resSession.getProtocol())) { |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
276 |
diffLog.append(String.format( |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
277 |
"Protocol mismatch - Init: %s, Res: %s\n", |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
278 |
initSession.getProtocol(), resSession.getProtocol())); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
279 |
} |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
280 |
|
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
281 |
// If the StringBuilder has any data in it then one of the checks |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
282 |
// above failed and we should throw an exception. |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
283 |
if (diffLog.length() > 0) { |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
284 |
throw new RuntimeException(diffLog.toString()); |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
285 |
} |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
286 |
} |
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
287 |
|
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
288 |
private static Server startServer() { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
289 |
Server server = new Server(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
290 |
new Thread(server).start(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
291 |
return server; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
292 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
293 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
294 |
private static class Server implements Runnable { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
295 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
296 |
public volatile boolean go = true; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
297 |
private boolean signal = false; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
298 |
public volatile int port = 0; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
299 |
public volatile boolean started = false; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
300 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
301 |
private synchronized void waitForSignal() { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
302 |
while (!signal) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
303 |
try { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
304 |
wait(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
305 |
} catch (InterruptedException ex) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
306 |
// do nothing |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
307 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
308 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
309 |
signal = false; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
310 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
311 |
public synchronized void signal() { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
312 |
signal = true; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
313 |
notify(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
314 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
315 |
|
52512
1838347a803b
8212885: TLS 1.3 resumed session does not retain peer certificate chain
jnimeh
parents:
51134
diff
changeset
|
316 |
@Override |
51134
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
317 |
public void run() { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
318 |
try { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
319 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
320 |
SSLContext sc = SSLContext.getDefault(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
321 |
ServerSocketFactory fac = sc.getServerSocketFactory(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
322 |
SSLServerSocket ssock = (SSLServerSocket) |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
323 |
fac.createServerSocket(0); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
324 |
this.port = ssock.getLocalPort(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
325 |
|
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
326 |
waitForSignal(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
327 |
started = true; |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
328 |
while (go) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
329 |
try { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
330 |
System.out.println("Waiting for connection"); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
331 |
Socket sock = ssock.accept(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
332 |
BufferedReader reader = new BufferedReader( |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
333 |
new InputStreamReader(sock.getInputStream())); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
334 |
String line = reader.readLine(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
335 |
System.out.println("server read: " + line); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
336 |
PrintWriter out = new PrintWriter( |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
337 |
new OutputStreamWriter(sock.getOutputStream())); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
338 |
out.println(line); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
339 |
out.flush(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
340 |
waitForSignal(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
341 |
} catch (Exception ex) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
342 |
ex.printStackTrace(); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
343 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
344 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
345 |
} catch (Exception ex) { |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
346 |
throw new RuntimeException(ex); |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
347 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
348 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
349 |
} |
a0de9a3a6766
8206929: Check session context for TLS 1.3 session resumption
apetcher
parents:
diff
changeset
|
350 |
} |