author | jnimeh |
Thu, 07 Jun 2018 21:55:35 -0700 | |
branch | JDK-8145252-TLS13-branch |
changeset 56704 | c3ee22c3a0f6 |
parent 56542 | 56aaa6cb3693 |
child 56708 | 25178bb3e8f5 |
permissions | -rw-r--r-- |
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
1 |
/* |
56542 | 2 |
* Copyright (c) 2015, 2018, Oracle and/or its affiliates. All rights reserved. |
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
3 |
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
4 |
* |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
5 |
* This code is free software; you can redistribute it and/or modify it |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
6 |
* under the terms of the GNU General Public License version 2 only, as |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
7 |
* published by the Free Software Foundation. Oracle designates this |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
8 |
* particular file as subject to the "Classpath" exception as provided |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
9 |
* by Oracle in the LICENSE file that accompanied this code. |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
10 |
* |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
11 |
* This code is distributed in the hope that it will be useful, but WITHOUT |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
12 |
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
13 |
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
14 |
* version 2 for more details (a copy is included in the LICENSE file that |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
15 |
* accompanied this code). |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
16 |
* |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
17 |
* You should have received a copy of the GNU General Public License version |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
18 |
* 2 along with this work; if not, write to the Free Software Foundation, |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
19 |
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
20 |
* |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
21 |
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
22 |
* or visit www.oracle.com if you need additional information or have any |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
23 |
* questions. |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
24 |
*/ |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
25 |
|
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
26 |
package sun.security.ssl; |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
27 |
|
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
28 |
import java.io.IOException; |
56542 | 29 |
import java.nio.ByteBuffer; |
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
30 |
import java.nio.charset.StandardCharsets; |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
31 |
import java.util.ArrayList; |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
32 |
import java.util.Collection; |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
33 |
import java.util.Collections; |
56542 | 34 |
import java.util.LinkedHashMap; |
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
35 |
import java.util.List; |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
36 |
import java.util.Map; |
56542 | 37 |
import java.util.Objects; |
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
38 |
import javax.net.ssl.SNIHostName; |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
39 |
import javax.net.ssl.SNIMatcher; |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
40 |
import javax.net.ssl.SNIServerName; |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
41 |
import javax.net.ssl.SSLProtocolException; |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
42 |
import javax.net.ssl.StandardConstants; |
56542 | 43 |
import static sun.security.ssl.SSLExtension.CH_SERVER_NAME; |
44 |
import static sun.security.ssl.SSLExtension.EE_SERVER_NAME; |
|
45 |
import sun.security.ssl.SSLExtension.ExtensionConsumer; |
|
46 |
import static sun.security.ssl.SSLExtension.SH_SERVER_NAME; |
|
47 |
import sun.security.ssl.SSLExtension.SSLExtensionSpec; |
|
48 |
import sun.security.ssl.SSLHandshake.HandshakeMessage; |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
49 |
|
56542 | 50 |
/** |
51 |
* Pack of the "server_name" extensions [RFC 4366/6066]. |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
52 |
*/ |
56542 | 53 |
final class ServerNameExtension { |
54 |
static final HandshakeProducer chNetworkProducer = |
|
55 |
new CHServerNameProducer(); |
|
56704
c3ee22c3a0f6
Minor nits and cleanup across SSLExtension classes
jnimeh
parents:
56542
diff
changeset
|
56 |
static final ExtensionConsumer chOnLoadConsumer = |
56542 | 57 |
new CHServerNameConsumer(); |
58 |
static final SSLStringize chStringize = |
|
59 |
new CHServerNamesStringize(); |
|
60 |
||
61 |
static final HandshakeProducer shNetworkProducer = |
|
62 |
new SHServerNameProducer(); |
|
56704
c3ee22c3a0f6
Minor nits and cleanup across SSLExtension classes
jnimeh
parents:
56542
diff
changeset
|
63 |
static final ExtensionConsumer shOnLoadConsumer = |
56542 | 64 |
new SHServerNameConsumer(); |
65 |
static final SSLStringize shStringize = |
|
66 |
new SHServerNamesStringize(); |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
67 |
|
56542 | 68 |
static final HandshakeProducer eeNetworkProducer = |
69 |
new EEServerNameProducer(); |
|
56704
c3ee22c3a0f6
Minor nits and cleanup across SSLExtension classes
jnimeh
parents:
56542
diff
changeset
|
70 |
static final ExtensionConsumer eeOnLoadConsumer = |
56542 | 71 |
new EEServerNameConsumer(); |
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
72 |
|
56542 | 73 |
/** |
74 |
* The "server_name" extension. |
|
75 |
* |
|
76 |
* See RFC 4366/6066 for the specification of the extension. |
|
77 |
*/ |
|
78 |
static final class CHServerNamesSpec implements SSLExtensionSpec { |
|
79 |
// For backward compatibility, all future data structures associated |
|
80 |
// with new NameTypes MUST begin with a 16-bit length field. |
|
81 |
static final int NAME_HEADER_LENGTH = 3; // 1: NameType |
|
82 |
// +2: Name length |
|
83 |
final List<SNIServerName> serverNames; |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
84 |
|
56542 | 85 |
private CHServerNamesSpec(List<SNIServerName> serverNames) { |
86 |
this.serverNames = |
|
87 |
Collections.<SNIServerName>unmodifiableList(serverNames); |
|
88 |
} |
|
89 |
||
90 |
private CHServerNamesSpec(ByteBuffer buffer) throws IOException { |
|
91 |
if (buffer.remaining() < 2) { |
|
92 |
throw new SSLProtocolException( |
|
93 |
"Invalid server_name extension: insufficient data"); |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
94 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
95 |
|
56542 | 96 |
int sniLen = Record.getInt16(buffer); |
97 |
if ((sniLen == 0) || sniLen != buffer.remaining()) { |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
98 |
throw new SSLProtocolException( |
56542 | 99 |
"Invalid server_name extension: incomplete data"); |
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
100 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
101 |
|
56542 | 102 |
Map<Integer, SNIServerName> sniMap = new LinkedHashMap<>(); |
103 |
while (buffer.hasRemaining()) { |
|
104 |
int nameType = Record.getInt8(buffer); |
|
105 |
SNIServerName serverName; |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
106 |
|
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
107 |
// HostName (length read in getBytes16); |
56542 | 108 |
// |
109 |
// [RFC 6066] The data structure associated with the host_name |
|
110 |
// NameType is a variable-length vector that begins with a |
|
111 |
// 16-bit length. For backward compatibility, all future data |
|
112 |
// structures associated with new NameTypes MUST begin with a |
|
113 |
// 16-bit length field. TLS MAY treat provided server names as |
|
114 |
// opaque data and pass the names and types to the application. |
|
115 |
byte[] encoded = Record.getBytes16(buffer); |
|
116 |
if (nameType == StandardConstants.SNI_HOST_NAME) { |
|
117 |
if (encoded.length == 0) { |
|
118 |
throw new SSLProtocolException( |
|
119 |
"Empty HostName in server_name extension"); |
|
120 |
} |
|
121 |
||
122 |
try { |
|
123 |
serverName = new SNIHostName(encoded); |
|
124 |
} catch (IllegalArgumentException iae) { |
|
125 |
SSLProtocolException spe = new SSLProtocolException( |
|
126 |
"Illegal server name, type=host_name(" + |
|
127 |
nameType + "), name=" + |
|
128 |
(new String(encoded, StandardCharsets.UTF_8)) + |
|
129 |
", value={" + |
|
130 |
Utilities.toHexString(encoded) + "}"); |
|
131 |
throw (SSLProtocolException)spe.initCause(iae); |
|
132 |
} |
|
133 |
} else { |
|
134 |
try { |
|
135 |
serverName = new UnknownServerName(nameType, encoded); |
|
136 |
} catch (IllegalArgumentException iae) { |
|
137 |
SSLProtocolException spe = new SSLProtocolException( |
|
138 |
"Illegal server name, type=(" + nameType + |
|
139 |
"), value={" + |
|
140 |
Utilities.toHexString(encoded) + "}"); |
|
141 |
throw (SSLProtocolException)spe.initCause(iae); |
|
142 |
} |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
143 |
} |
56542 | 144 |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
145 |
// check for duplicated server name type |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
146 |
if (sniMap.put(serverName.getType(), serverName) != null) { |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
147 |
throw new SSLProtocolException( |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
148 |
"Duplicated server name of type " + |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
149 |
serverName.getType()); |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
150 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
151 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
152 |
|
56542 | 153 |
this.serverNames = new ArrayList<>(sniMap.values()); |
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
154 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
155 |
|
56542 | 156 |
@Override |
157 |
public String toString() { |
|
158 |
if (serverNames == null || serverNames.isEmpty()) { |
|
159 |
return "<no server name indicator specified>"; |
|
160 |
} else { |
|
161 |
StringBuilder builder = new StringBuilder(512); |
|
162 |
for (SNIServerName sn : serverNames) { |
|
163 |
builder.append(sn.toString()); |
|
164 |
builder.append("\n"); |
|
165 |
} |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
166 |
|
56542 | 167 |
return builder.toString(); |
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
168 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
169 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
170 |
|
56542 | 171 |
private static class UnknownServerName extends SNIServerName { |
172 |
UnknownServerName(int code, byte[] encoded) { |
|
173 |
super(code, encoded); |
|
174 |
} |
|
175 |
} |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
176 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
177 |
|
56542 | 178 |
private static final class CHServerNamesStringize implements SSLStringize { |
179 |
@Override |
|
180 |
public String toString(ByteBuffer buffer) { |
|
181 |
try { |
|
182 |
return (new CHServerNamesSpec(buffer)).toString(); |
|
183 |
} catch (IOException ioe) { |
|
184 |
// For debug logging only, so please swallow exceptions. |
|
185 |
return ioe.getMessage(); |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
186 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
187 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
188 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
189 |
|
56542 | 190 |
/** |
191 |
* Network data producer of a "server_name" extension in the |
|
192 |
* ClientHello handshake message. |
|
193 |
*/ |
|
194 |
private static final |
|
195 |
class CHServerNameProducer implements HandshakeProducer { |
|
196 |
// Prevent instantiation of this class. |
|
197 |
private CHServerNameProducer() { |
|
198 |
// blank |
|
199 |
} |
|
200 |
||
201 |
@Override |
|
202 |
public byte[] produce(ConnectionContext context, |
|
203 |
HandshakeMessage message) throws IOException { |
|
204 |
// The producing happens in client side only. |
|
205 |
ClientHandshakeContext chc = (ClientHandshakeContext)context; |
|
206 |
||
207 |
// Is it a supported and enabled extension? |
|
208 |
if (!chc.sslConfig.isAvailable(CH_SERVER_NAME)) { |
|
209 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl,handshake")) { |
|
210 |
SSLLogger.warning( |
|
211 |
"Ignore unavailable server_name extension"); |
|
212 |
} |
|
213 |
return null; |
|
214 |
} |
|
215 |
||
216 |
// Produce the extension. |
|
217 |
List<SNIServerName> serverNames; |
|
218 |
if (chc.isResumption && (chc.resumingSession != null)) { |
|
219 |
serverNames = |
|
220 |
chc.resumingSession.getRequestedServerNames(); |
|
221 |
} else { |
|
222 |
serverNames = chc.sslConfig.serverNames; |
|
223 |
} // Shall we use host too? |
|
224 |
||
225 |
// Empty server name list is not allowed in client mode. |
|
226 |
if ((serverNames != null) && !serverNames.isEmpty()) { |
|
227 |
int sniLen = 0; |
|
228 |
for (SNIServerName sniName : serverNames) { |
|
229 |
// For backward compatibility, all future data structures |
|
230 |
// associated with new NameTypes MUST begin with a 16-bit |
|
231 |
// length field. The header length of server name is 3 |
|
232 |
// bytes, including 1 byte NameType, and 2 bytes length |
|
233 |
// of the name. |
|
234 |
sniLen += CHServerNamesSpec.NAME_HEADER_LENGTH; |
|
235 |
sniLen += sniName.getEncoded().length; |
|
236 |
} |
|
237 |
||
238 |
byte[] extData = new byte[sniLen + 2]; |
|
239 |
ByteBuffer m = ByteBuffer.wrap(extData); |
|
240 |
Record.putInt16(m, sniLen); |
|
241 |
for (SNIServerName sniName : serverNames) { |
|
242 |
Record.putInt8(m, sniName.getType()); |
|
243 |
Record.putBytes16(m, sniName.getEncoded()); |
|
244 |
} |
|
245 |
||
246 |
// Update the context. |
|
247 |
chc.requestedServerNames = serverNames; |
|
248 |
chc.handshakeExtensions.put(CH_SERVER_NAME, |
|
249 |
new CHServerNamesSpec(serverNames)); |
|
250 |
||
251 |
return extData; |
|
252 |
} |
|
253 |
||
254 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl,handshake")) { |
|
255 |
SSLLogger.warning("Unable to indicate server name"); |
|
256 |
} |
|
257 |
return null; |
|
258 |
} |
|
259 |
} |
|
260 |
||
261 |
/** |
|
262 |
* Network data consumer of a "server_name" extension in the |
|
263 |
* ClientHello handshake message. |
|
264 |
*/ |
|
265 |
private static final |
|
266 |
class CHServerNameConsumer implements ExtensionConsumer { |
|
267 |
// Prevent instantiation of this class. |
|
268 |
private CHServerNameConsumer() { |
|
269 |
// blank |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
270 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
271 |
|
56542 | 272 |
@Override |
273 |
public void consume(ConnectionContext context, |
|
274 |
HandshakeMessage message, ByteBuffer buffer) throws IOException { |
|
56704
c3ee22c3a0f6
Minor nits and cleanup across SSLExtension classes
jnimeh
parents:
56542
diff
changeset
|
275 |
// The consuming happens in server side only. |
56542 | 276 |
ServerHandshakeContext shc = (ServerHandshakeContext)context; |
277 |
||
278 |
// Is it a supported and enabled extension? |
|
279 |
if (!shc.sslConfig.isAvailable(CH_SERVER_NAME)) { |
|
280 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl,handshake")) { |
|
281 |
SSLLogger.fine( |
|
282 |
"Ignore unavailable extension: " + CH_SERVER_NAME.name); |
|
283 |
} |
|
284 |
return; // ignore the extension |
|
285 |
} |
|
286 |
||
287 |
// Parse the extension. |
|
288 |
CHServerNamesSpec spec; |
|
289 |
try { |
|
290 |
spec = new CHServerNamesSpec(buffer); |
|
291 |
} catch (IOException ioe) { |
|
292 |
shc.conContext.fatal(Alert.UNEXPECTED_MESSAGE, ioe); |
|
293 |
return; // fatal() always throws, make the compiler happy. |
|
294 |
} |
|
295 |
||
296 |
// Update the context. |
|
297 |
shc.handshakeExtensions.put(CH_SERVER_NAME, spec); |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
298 |
|
56542 | 299 |
// Does the server match the server name request? |
300 |
SNIServerName sni = null; |
|
301 |
if (!shc.sslConfig.sniMatchers.isEmpty()) { |
|
302 |
sni = chooseSni(shc.sslConfig.sniMatchers, spec.serverNames); |
|
303 |
if (sni != null) { |
|
304 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl,handshake")) { |
|
305 |
SSLLogger.fine( |
|
306 |
"server name indication (" + |
|
307 |
sni + ") is accepted"); |
|
308 |
} |
|
309 |
} else { |
|
310 |
// We do not reject client without SNI extension currently. |
|
311 |
shc.conContext.fatal(Alert.UNRECOGNIZED_NAME, |
|
312 |
"Unrecognized server name indication"); |
|
313 |
} |
|
314 |
} else { |
|
315 |
// Note: Servers MAY require clients to send a valid |
|
316 |
// "server_name" extension and respond to a ClientHello |
|
317 |
// lacking a "server_name" extension by terminating the |
|
318 |
// connection with a "missing_extension" alert. |
|
319 |
// |
|
320 |
// We do not reject client without SNI extension currently. |
|
321 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl,handshake")) { |
|
322 |
SSLLogger.fine( |
|
323 |
"no server name matchers, " + |
|
324 |
"ignore server name indication"); |
|
325 |
} |
|
326 |
} |
|
327 |
||
328 |
// Impact on session resumption. |
|
329 |
// |
|
330 |
// Does the resuming session have the same principal? |
|
331 |
if (shc.isResumption && shc.resumingSession != null) { |
|
332 |
// A server that implements this extension MUST NOT accept |
|
333 |
// the request to resume the session if the server_name |
|
334 |
// extension contains a different name. |
|
335 |
// |
|
336 |
// May only need to check that the session SNI is one of |
|
337 |
// the requested server names. |
|
338 |
if (!Objects.equals( |
|
339 |
sni, shc.resumingSession.serverNameIndication)) { |
|
340 |
shc.isResumption = false; |
|
341 |
shc.resumingSession = null; |
|
342 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl,handshake")) { |
|
343 |
SSLLogger.fine( |
|
344 |
"abort session resumption, " + |
|
345 |
"different server name indication used"); |
|
346 |
} |
|
347 |
} |
|
348 |
} |
|
349 |
||
350 |
shc.requestedServerNames = spec.serverNames; |
|
351 |
shc.negotiatedServerName = sni; |
|
352 |
} |
|
353 |
||
354 |
private static SNIServerName chooseSni(Collection<SNIMatcher> matchers, |
|
355 |
List<SNIServerName> sniNames) { |
|
356 |
if (sniNames != null && !sniNames.isEmpty()) { |
|
357 |
for (SNIMatcher matcher : matchers) { |
|
358 |
int matcherType = matcher.getType(); |
|
359 |
for (SNIServerName sniName : sniNames) { |
|
360 |
if (sniName.getType() == matcherType) { |
|
361 |
if (matcher.matches(sniName)) { |
|
362 |
return sniName; |
|
363 |
} |
|
364 |
||
365 |
// no duplicated entry in the server names list. |
|
366 |
break; |
|
367 |
} |
|
368 |
} |
|
369 |
} |
|
370 |
} |
|
371 |
||
372 |
return null; |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
373 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
374 |
} |
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
375 |
|
56542 | 376 |
/** |
377 |
* The "server_name" extension in the ServerHello handshake message. |
|
378 |
* |
|
379 |
* The "extension_data" field of this extension shall be empty. |
|
380 |
*/ |
|
381 |
static final class SHServerNamesSpec implements SSLExtensionSpec { |
|
382 |
static final SHServerNamesSpec DEFAULT = new SHServerNamesSpec(); |
|
383 |
||
384 |
private SHServerNamesSpec() { |
|
385 |
// blank |
|
386 |
} |
|
387 |
||
388 |
private SHServerNamesSpec(ByteBuffer buffer) throws IOException { |
|
389 |
if (buffer.remaining() != 0) { |
|
390 |
throw new SSLProtocolException( |
|
391 |
"Invalid ServerHello server_name extension: not empty"); |
|
392 |
} |
|
393 |
} |
|
394 |
||
395 |
@Override |
|
396 |
public String toString() { |
|
397 |
return "<empty extension_data field>"; |
|
398 |
} |
|
399 |
} |
|
400 |
||
401 |
private static final class SHServerNamesStringize implements SSLStringize { |
|
402 |
@Override |
|
403 |
public String toString(ByteBuffer buffer) { |
|
404 |
try { |
|
405 |
return (new SHServerNamesSpec(buffer)).toString(); |
|
406 |
} catch (IOException ioe) { |
|
407 |
// For debug logging only, so please swallow exceptions. |
|
408 |
return ioe.getMessage(); |
|
409 |
} |
|
410 |
} |
|
411 |
} |
|
412 |
||
413 |
/** |
|
414 |
* Network data producer of a "server_name" extension in the |
|
415 |
* ServerHello handshake message. |
|
416 |
*/ |
|
417 |
private static final |
|
418 |
class SHServerNameProducer implements HandshakeProducer { |
|
419 |
// Prevent instantiation of this class. |
|
420 |
private SHServerNameProducer() { |
|
421 |
// blank |
|
422 |
} |
|
423 |
||
424 |
@Override |
|
425 |
public byte[] produce(ConnectionContext context, |
|
426 |
HandshakeMessage message) throws IOException { |
|
427 |
// The producing happens in server side only. |
|
428 |
ServerHandshakeContext shc = (ServerHandshakeContext)context; |
|
429 |
||
430 |
// In response to "server_name" extension request only |
|
431 |
CHServerNamesSpec spec = (CHServerNamesSpec) |
|
432 |
shc.handshakeExtensions.get(CH_SERVER_NAME); |
|
433 |
if (spec == null) { |
|
434 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl,handshake")) { |
|
435 |
SSLLogger.finest( |
|
436 |
"Ignore unavailable extension: " + SH_SERVER_NAME.name); |
|
437 |
} |
|
438 |
return null; // ignore the extension |
|
439 |
} |
|
440 |
||
441 |
// When resuming a session, the server MUST NOT include a |
|
442 |
// server_name extension in the server hello. |
|
443 |
if (shc.isResumption || shc.negotiatedServerName == null) { |
|
444 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl,handshake")) { |
|
445 |
SSLLogger.finest( |
|
446 |
"No expected server name indication response"); |
|
447 |
} |
|
448 |
return null; // ignore the extension |
|
449 |
} |
|
450 |
||
451 |
// Produce the extension and update the context. |
|
452 |
shc.handshakeExtensions.put( |
|
453 |
SH_SERVER_NAME, SHServerNamesSpec.DEFAULT); |
|
454 |
||
455 |
return (new byte[0]); // the empty extension_data |
|
456 |
} |
|
457 |
} |
|
458 |
||
459 |
/** |
|
460 |
* Network data consumer of a "server_name" extension in the |
|
461 |
* ServerHello handshake message. |
|
462 |
*/ |
|
463 |
private static final |
|
464 |
class SHServerNameConsumer implements ExtensionConsumer { |
|
465 |
// Prevent instantiation of this class. |
|
466 |
private SHServerNameConsumer() { |
|
467 |
// blank |
|
468 |
} |
|
469 |
||
470 |
@Override |
|
471 |
public void consume(ConnectionContext context, |
|
472 |
HandshakeMessage message, ByteBuffer buffer) throws IOException { |
|
56704
c3ee22c3a0f6
Minor nits and cleanup across SSLExtension classes
jnimeh
parents:
56542
diff
changeset
|
473 |
// The consuming happens in client side only. |
56542 | 474 |
ClientHandshakeContext chc = (ClientHandshakeContext)context; |
475 |
||
476 |
// In response to "server_name" extension request only |
|
477 |
CHServerNamesSpec spec = (CHServerNamesSpec) |
|
478 |
chc.handshakeExtensions.get(CH_SERVER_NAME); |
|
479 |
if (spec == null) { |
|
480 |
chc.conContext.fatal(Alert.UNEXPECTED_MESSAGE, |
|
481 |
"Unexpected ServerHello server_name extension"); |
|
482 |
} |
|
483 |
||
484 |
// Parse the extension. |
|
485 |
if (buffer.remaining() != 0) { |
|
486 |
chc.conContext.fatal(Alert.UNEXPECTED_MESSAGE, |
|
487 |
"Invalid ServerHello server_name extension"); |
|
488 |
} |
|
489 |
||
490 |
// Update the context. |
|
491 |
chc.handshakeExtensions.put( |
|
492 |
SH_SERVER_NAME, SHServerNamesSpec.DEFAULT); |
|
493 |
// The negotiated server name is unknown in client side. Just |
|
494 |
// use the first request name as the value is not actually used |
|
495 |
// in the current implementation. |
|
496 |
chc.negotiatedServerName = spec.serverNames.get(0); |
|
497 |
} |
|
498 |
} |
|
499 |
||
500 |
/** |
|
501 |
* Network data producer of a "server_name" extension in the |
|
502 |
* EncryptedExtensions handshake message. |
|
503 |
*/ |
|
504 |
private static final |
|
505 |
class EEServerNameProducer implements HandshakeProducer { |
|
506 |
// Prevent instantiation of this class. |
|
507 |
private EEServerNameProducer() { |
|
508 |
// blank |
|
509 |
} |
|
510 |
||
511 |
@Override |
|
512 |
public byte[] produce(ConnectionContext context, |
|
513 |
HandshakeMessage message) throws IOException { |
|
514 |
// The producing happens in server side only. |
|
515 |
ServerHandshakeContext shc = (ServerHandshakeContext)context; |
|
516 |
||
517 |
// In response to "server_name" extension request only |
|
518 |
CHServerNamesSpec spec = (CHServerNamesSpec) |
|
519 |
shc.handshakeExtensions.get(CH_SERVER_NAME); |
|
520 |
if (spec == null) { |
|
521 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl,handshake")) { |
|
522 |
SSLLogger.finest( |
|
523 |
"Ignore unavailable extension: " + EE_SERVER_NAME.name); |
|
524 |
} |
|
525 |
return null; // ignore the extension |
|
526 |
} |
|
527 |
||
528 |
// When resuming a session, the server MUST NOT include a |
|
529 |
// server_name extension in the server hello. |
|
530 |
if (shc.isResumption || shc.negotiatedServerName == null) { |
|
531 |
if (SSLLogger.isOn && SSLLogger.isOn("ssl,handshake")) { |
|
532 |
SSLLogger.finest( |
|
533 |
"No expected server name indication response"); |
|
534 |
} |
|
535 |
return null; // ignore the extension |
|
536 |
} |
|
537 |
||
538 |
// Produce the extension and update the context. |
|
539 |
shc.handshakeExtensions.put( |
|
540 |
EE_SERVER_NAME, SHServerNamesSpec.DEFAULT); |
|
541 |
||
542 |
return (new byte[0]); // the empty extension_data |
|
543 |
} |
|
544 |
} |
|
545 |
||
546 |
/** |
|
547 |
* Network data consumer of a "server_name" extension in the |
|
548 |
* EncryptedExtensions handshake message. |
|
549 |
*/ |
|
550 |
private static final |
|
551 |
class EEServerNameConsumer implements ExtensionConsumer { |
|
552 |
// Prevent instantiation of this class. |
|
553 |
private EEServerNameConsumer() { |
|
554 |
// blank |
|
555 |
} |
|
556 |
||
557 |
@Override |
|
558 |
public void consume(ConnectionContext context, |
|
559 |
HandshakeMessage message, ByteBuffer buffer) throws IOException { |
|
56704
c3ee22c3a0f6
Minor nits and cleanup across SSLExtension classes
jnimeh
parents:
56542
diff
changeset
|
560 |
// The consuming happens in client side only. |
56542 | 561 |
ClientHandshakeContext chc = (ClientHandshakeContext)context; |
562 |
||
563 |
// In response to "server_name" extension request only |
|
564 |
CHServerNamesSpec spec = (CHServerNamesSpec) |
|
565 |
chc.handshakeExtensions.get(CH_SERVER_NAME); |
|
566 |
if (spec == null) { |
|
567 |
chc.conContext.fatal(Alert.UNEXPECTED_MESSAGE, |
|
568 |
"Unexpected EncryptedExtensions server_name extension"); |
|
569 |
} |
|
570 |
||
571 |
// Parse the extension. |
|
572 |
if (buffer.remaining() != 0) { |
|
573 |
chc.conContext.fatal(Alert.UNEXPECTED_MESSAGE, |
|
574 |
"Invalid EncryptedExtensions server_name extension"); |
|
575 |
} |
|
576 |
||
577 |
// Update the context. |
|
578 |
chc.handshakeExtensions.put( |
|
579 |
EE_SERVER_NAME, SHServerNamesSpec.DEFAULT); |
|
580 |
// The negotiated server name is unknown in client side. Just |
|
581 |
// use the first request name as the value is not actually used |
|
582 |
// in the current implementation. |
|
583 |
chc.negotiatedServerName = spec.serverNames.get(0); |
|
584 |
} |
|
585 |
} |
|
14330
e4cb78065603
8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK
ohrstrom
parents:
diff
changeset
|
586 |
} |