author | mchung |
Thu, 28 May 2015 10:54:48 -0700 | |
changeset 30820 | 0d4717a011d3 |
parent 30690 | f6d8413a278c |
permissions | -rw-r--r-- |
2 | 1 |
/* |
28308
5fdc6e6c0b97
8046724: XML Signature ECKeyValue elements cannot be marshalled or unmarshalled
juh
parents:
18240
diff
changeset
|
2 |
* Copyright (c) 2005, 2015, Oracle and/or its affiliates. All rights reserved. |
2 | 3 |
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. |
4 |
* |
|
5 |
* This code is free software; you can redistribute it and/or modify it |
|
6 |
* under the terms of the GNU General Public License version 2 only, as |
|
7 |
* published by the Free Software Foundation. |
|
8 |
* |
|
9 |
* This code is distributed in the hope that it will be useful, but WITHOUT |
|
10 |
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or |
|
11 |
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License |
|
12 |
* version 2 for more details (a copy is included in the LICENSE file that |
|
13 |
* accompanied this code). |
|
14 |
* |
|
15 |
* You should have received a copy of the GNU General Public License version |
|
16 |
* 2 along with this work; if not, write to the Free Software Foundation, |
|
17 |
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. |
|
18 |
* |
|
5506 | 19 |
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA |
20 |
* or visit www.oracle.com if you need additional information or have any |
|
21 |
* questions. |
|
2 | 22 |
*/ |
23 |
||
24 |
/** |
|
25 |
* @test |
|
30690
f6d8413a278c
8079693: Add support for ECDSA P-384 and P-521 curves to XML Signature
juh
parents:
30648
diff
changeset
|
26 |
* @bug 4635230 6365103 6366054 6824440 7131084 8046724 8079693 |
2 | 27 |
* @summary Basic unit tests for validating XML Signatures with JSR 105 |
30820 | 28 |
* @modules java.base/sun.security.util |
29 |
* java.base/sun.security.x509 |
|
30 |
* java.xml.crypto/org.jcp.xml.dsig.internal.dom |
|
2 | 31 |
* @compile -XDignore.symbol.file KeySelectors.java SignatureValidator.java |
32 |
* X509KeySelector.java ValidationTests.java |
|
18240 | 33 |
* @run main/othervm ValidationTests |
2 | 34 |
* @author Sean Mullan |
35 |
*/ |
|
36 |
import java.io.File; |
|
37 |
import java.io.FileInputStream; |
|
38 |
import java.security.*; |
|
39 |
import javax.xml.crypto.Data; |
|
40 |
import javax.xml.crypto.KeySelector; |
|
30648
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
41 |
import javax.xml.crypto.MarshalException; |
2 | 42 |
import javax.xml.crypto.OctetStreamData; |
43 |
import javax.xml.crypto.URIDereferencer; |
|
44 |
import javax.xml.crypto.URIReference; |
|
45 |
import javax.xml.crypto.URIReferenceException; |
|
46 |
import javax.xml.crypto.XMLCryptoContext; |
|
3462 | 47 |
import javax.xml.crypto.dsig.XMLSignatureException; |
2 | 48 |
import javax.xml.crypto.dsig.XMLSignatureFactory; |
49 |
||
50 |
public class ValidationTests { |
|
51 |
||
52 |
private static SignatureValidator validator; |
|
53 |
private final static String DIR = System.getProperty("test.src", "."); |
|
54 |
private final static String DATA_DIR = |
|
55 |
DIR + System.getProperty("file.separator") + "data"; |
|
56 |
private final static String KEYSTORE = |
|
57 |
DATA_DIR + System.getProperty("file.separator") + "certs" + |
|
58 |
System.getProperty("file.separator") + "xmldsig.jks"; |
|
59 |
private final static String STYLESHEET = |
|
60 |
"http://www.w3.org/TR/xml-stylesheet"; |
|
61 |
private final static String STYLESHEET_B64 = |
|
62 |
"http://www.w3.org/Signature/2002/04/xml-stylesheet.b64"; |
|
63 |
||
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
64 |
static class Test { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
65 |
String file; |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
66 |
KeySelector ks; |
30648
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
67 |
Class exception; |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
68 |
|
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
69 |
Test(String file, KeySelector ks, Class exception) { |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
70 |
this.file = file; |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
71 |
this.ks = ks; |
30648
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
72 |
this.exception = exception; |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
73 |
} |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
74 |
|
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
75 |
// XMLSignatureException is expected by default |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
76 |
Test(String file, KeySelector ks) { |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
77 |
this(file, ks, XMLSignatureException.class); |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
78 |
} |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
79 |
} |
2 | 80 |
|
81 |
static KeySelector skks; |
|
82 |
static { |
|
83 |
try { |
|
84 |
skks = |
|
85 |
new KeySelectors.SecretKeySelector("secret".getBytes("ASCII")); |
|
86 |
} catch (Exception e) { |
|
87 |
//should not occur |
|
88 |
} |
|
89 |
} |
|
90 |
private final static KeySelector SKKS = skks; |
|
91 |
private final static KeySelector KVKS = |
|
92 |
new KeySelectors.KeyValueKeySelector(); |
|
93 |
private final static KeySelector CKS = |
|
94 |
new KeySelectors.CollectionKeySelector(new File(DATA_DIR)); |
|
95 |
private final static KeySelector RXKS = |
|
96 |
new KeySelectors.RawX509KeySelector(); |
|
97 |
private final static KeySelector XKS = null; |
|
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
98 |
private static URIDereferencer httpUd = null; |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
99 |
|
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
100 |
private final static Test[] VALID_TESTS = { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
101 |
new Test("signature-enveloped-dsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
102 |
new Test("signature-enveloping-b64-dsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
103 |
new Test("signature-enveloping-dsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
104 |
new Test("signature-enveloping-rsa.xml", KVKS), |
28308
5fdc6e6c0b97
8046724: XML Signature ECKeyValue elements cannot be marshalled or unmarshalled
juh
parents:
18240
diff
changeset
|
105 |
new Test("signature-enveloping-p256-sha1.xml", KVKS), |
30690
f6d8413a278c
8079693: Add support for ECDSA P-384 and P-521 curves to XML Signature
juh
parents:
30648
diff
changeset
|
106 |
new Test("signature-enveloping-p384-sha1.xml", KVKS), |
f6d8413a278c
8079693: Add support for ECDSA P-384 and P-521 curves to XML Signature
juh
parents:
30648
diff
changeset
|
107 |
new Test("signature-enveloping-p521-sha1.xml", KVKS), |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
108 |
new Test("signature-enveloping-hmac-sha1.xml", SKKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
109 |
new Test("signature-external-dsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
110 |
new Test("signature-external-b64-dsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
111 |
new Test("signature-retrievalmethod-rawx509crt.xml", CKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
112 |
new Test("signature-keyname.xml", CKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
113 |
new Test("signature-x509-crt-crl.xml", RXKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
114 |
new Test("signature-x509-crt.xml", RXKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
115 |
new Test("signature-x509-is.xml", CKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
116 |
new Test("signature-x509-ski.xml", CKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
117 |
new Test("signature-x509-sn.xml", CKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
118 |
new Test("signature.xml", XKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
119 |
new Test("exc-signature.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
120 |
new Test("sign-spec.xml", RXKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
121 |
new Test("xmldsig-xfilter2.xml", KVKS) |
2 | 122 |
}; |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
123 |
|
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
124 |
private final static Test[] INVALID_TESTS = { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
125 |
new Test("signature-enveloping-hmac-sha1-40.xml", SKKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
126 |
new Test("signature-enveloping-hmac-sha1-trunclen-0-attack.xml", SKKS), |
30648
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
127 |
new Test("signature-enveloping-hmac-sha1-trunclen-8-attack.xml", SKKS), |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
128 |
new Test("signature-extra-text-in-signed-info.xml", SKKS, |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
129 |
MarshalException.class), |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
130 |
new Test("signature-wrong-canonicalization-method-algorithm.xml", SKKS, |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
131 |
MarshalException.class), |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
132 |
new Test("signature-wrong-transform-algorithm.xml", SKKS, |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
133 |
MarshalException.class), |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
134 |
new Test("signature-no-reference-uri.xml", SKKS), |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
135 |
new Test("signature-wrong-signature-method-algorithm.xml", SKKS, |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
136 |
MarshalException.class), |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
137 |
new Test("signature-wrong-tag-names.xml", SKKS, MarshalException.class) |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
138 |
}; |
2 | 139 |
|
140 |
public static void main(String args[]) throws Exception { |
|
141 |
httpUd = new HttpURIDereferencer(); |
|
142 |
||
143 |
validator = new SignatureValidator(new File(DATA_DIR)); |
|
144 |
||
145 |
boolean atLeastOneFailed = false; |
|
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
146 |
for (Test test : VALID_TESTS) { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
147 |
System.out.println("Validating " + test.file); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
148 |
if (test_signature(test)) { |
2 | 149 |
System.out.println("PASSED"); |
150 |
} else { |
|
151 |
System.out.println("FAILED"); |
|
152 |
atLeastOneFailed = true; |
|
153 |
} |
|
154 |
} |
|
155 |
// test with reference caching enabled |
|
156 |
System.out.println("Validating sign-spec.xml with caching enabled"); |
|
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
157 |
if (test_signature(new Test("sign-spec.xml", RXKS), true)) { |
2 | 158 |
System.out.println("PASSED"); |
159 |
} else { |
|
160 |
System.out.println("FAILED"); |
|
161 |
atLeastOneFailed = true; |
|
162 |
} |
|
163 |
||
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
164 |
for (Test test : INVALID_TESTS) { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
165 |
System.out.println("Validating " + test.file); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
166 |
try { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
167 |
test_signature(test); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
168 |
System.out.println("FAILED"); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
169 |
atLeastOneFailed = true; |
30648
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
170 |
} catch (Exception e) { |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
171 |
System.out.println("Exception: " + e); |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
172 |
if (e.getClass() != test.exception) { |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
173 |
System.out.println("FAILED: unexpected exception"); |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
174 |
atLeastOneFailed = true; |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
175 |
} else { |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
176 |
System.out.println("PASSED"); |
91e34299190c
8079138: Additional negative tests for XML signature processing
asmotrak
parents:
28308
diff
changeset
|
177 |
} |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
178 |
} |
3462 | 179 |
} |
180 |
||
2 | 181 |
if (atLeastOneFailed) { |
182 |
throw new Exception |
|
183 |
("At least one signature did not validate as expected"); |
|
184 |
} |
|
185 |
} |
|
186 |
||
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
187 |
public static boolean test_signature(Test test) throws Exception { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
188 |
return test_signature(test, false); |
2 | 189 |
} |
190 |
||
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
191 |
public static boolean test_signature(Test test, boolean cache) |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
192 |
throws Exception |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
193 |
{ |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
194 |
if (test.ks == null) { |
2 | 195 |
KeyStore keystore = KeyStore.getInstance("JKS"); |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
196 |
try (FileInputStream fis = new FileInputStream(KEYSTORE)) { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
197 |
keystore.load(fis, "changeit".toCharArray()); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
198 |
test.ks = new X509KeySelector(keystore, false); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
199 |
} |
2 | 200 |
} |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
201 |
return validator.validate(test.file, test.ks, httpUd, cache); |
2 | 202 |
} |
203 |
||
204 |
/** |
|
205 |
* This URIDereferencer returns locally cached copies of http content to |
|
206 |
* avoid test failures due to network glitches, etc. |
|
207 |
*/ |
|
208 |
private static class HttpURIDereferencer implements URIDereferencer { |
|
209 |
private URIDereferencer defaultUd; |
|
210 |
||
211 |
HttpURIDereferencer() { |
|
212 |
defaultUd = XMLSignatureFactory.getInstance().getURIDereferencer(); |
|
213 |
} |
|
214 |
||
215 |
public Data dereference(final URIReference ref, XMLCryptoContext ctx) |
|
216 |
throws URIReferenceException { |
|
217 |
String uri = ref.getURI(); |
|
218 |
if (uri.equals(STYLESHEET) || uri.equals(STYLESHEET_B64)) { |
|
219 |
try { |
|
220 |
FileInputStream fis = new FileInputStream(new File |
|
221 |
(DATA_DIR, uri.substring(uri.lastIndexOf('/')))); |
|
222 |
return new OctetStreamData(fis,ref.getURI(),ref.getType()); |
|
223 |
} catch (Exception e) { throw new URIReferenceException(e); } |
|
224 |
} |
|
225 |
||
226 |
// fallback on builtin deref |
|
227 |
return defaultUd.dereference(ref, ctx); |
|
228 |
} |
|
229 |
} |
|
230 |
} |