author | mchung |
Mon, 27 Oct 2014 13:45:39 -0700 | |
changeset 27260 | 8d82d0e9556b |
parent 18240 | cda839ac048f |
child 28308 | 5fdc6e6c0b97 |
permissions | -rw-r--r-- |
2 | 1 |
/* |
18240 | 2 |
* Copyright (c) 2005, 2013, Oracle and/or its affiliates. All rights reserved. |
2 | 3 |
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. |
4 |
* |
|
5 |
* This code is free software; you can redistribute it and/or modify it |
|
6 |
* under the terms of the GNU General Public License version 2 only, as |
|
7 |
* published by the Free Software Foundation. |
|
8 |
* |
|
9 |
* This code is distributed in the hope that it will be useful, but WITHOUT |
|
10 |
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or |
|
11 |
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License |
|
12 |
* version 2 for more details (a copy is included in the LICENSE file that |
|
13 |
* accompanied this code). |
|
14 |
* |
|
15 |
* You should have received a copy of the GNU General Public License version |
|
16 |
* 2 along with this work; if not, write to the Free Software Foundation, |
|
17 |
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. |
|
18 |
* |
|
5506 | 19 |
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA |
20 |
* or visit www.oracle.com if you need additional information or have any |
|
21 |
* questions. |
|
2 | 22 |
*/ |
23 |
||
24 |
/** |
|
25 |
* @test |
|
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
26 |
* @bug 4635230 6365103 6366054 6824440 7131084 |
2 | 27 |
* @summary Basic unit tests for validating XML Signatures with JSR 105 |
28 |
* @compile -XDignore.symbol.file KeySelectors.java SignatureValidator.java |
|
29 |
* X509KeySelector.java ValidationTests.java |
|
18240 | 30 |
* @run main/othervm ValidationTests |
2 | 31 |
* @author Sean Mullan |
32 |
*/ |
|
33 |
import java.io.File; |
|
34 |
import java.io.FileInputStream; |
|
35 |
import java.security.*; |
|
36 |
import javax.xml.crypto.Data; |
|
37 |
import javax.xml.crypto.KeySelector; |
|
38 |
import javax.xml.crypto.OctetStreamData; |
|
39 |
import javax.xml.crypto.URIDereferencer; |
|
40 |
import javax.xml.crypto.URIReference; |
|
41 |
import javax.xml.crypto.URIReferenceException; |
|
42 |
import javax.xml.crypto.XMLCryptoContext; |
|
3462 | 43 |
import javax.xml.crypto.dsig.XMLSignatureException; |
2 | 44 |
import javax.xml.crypto.dsig.XMLSignatureFactory; |
45 |
||
46 |
public class ValidationTests { |
|
47 |
||
48 |
private static SignatureValidator validator; |
|
49 |
private final static String DIR = System.getProperty("test.src", "."); |
|
50 |
private final static String DATA_DIR = |
|
51 |
DIR + System.getProperty("file.separator") + "data"; |
|
52 |
private final static String KEYSTORE = |
|
53 |
DATA_DIR + System.getProperty("file.separator") + "certs" + |
|
54 |
System.getProperty("file.separator") + "xmldsig.jks"; |
|
55 |
private final static String STYLESHEET = |
|
56 |
"http://www.w3.org/TR/xml-stylesheet"; |
|
57 |
private final static String STYLESHEET_B64 = |
|
58 |
"http://www.w3.org/Signature/2002/04/xml-stylesheet.b64"; |
|
59 |
||
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
60 |
static class Test { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
61 |
String file; |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
62 |
KeySelector ks; |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
63 |
Test(String file, KeySelector ks) { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
64 |
this.file = file; |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
65 |
this.ks = ks; |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
66 |
} |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
67 |
} |
2 | 68 |
|
69 |
static KeySelector skks; |
|
70 |
static { |
|
71 |
try { |
|
72 |
skks = |
|
73 |
new KeySelectors.SecretKeySelector("secret".getBytes("ASCII")); |
|
74 |
} catch (Exception e) { |
|
75 |
//should not occur |
|
76 |
} |
|
77 |
} |
|
78 |
private final static KeySelector SKKS = skks; |
|
79 |
private final static KeySelector KVKS = |
|
80 |
new KeySelectors.KeyValueKeySelector(); |
|
81 |
private final static KeySelector CKS = |
|
82 |
new KeySelectors.CollectionKeySelector(new File(DATA_DIR)); |
|
83 |
private final static KeySelector RXKS = |
|
84 |
new KeySelectors.RawX509KeySelector(); |
|
85 |
private final static KeySelector XKS = null; |
|
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
86 |
private static URIDereferencer httpUd = null; |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
87 |
|
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
88 |
private final static Test[] VALID_TESTS = { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
89 |
new Test("signature-enveloped-dsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
90 |
new Test("signature-enveloping-b64-dsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
91 |
new Test("signature-enveloping-dsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
92 |
new Test("signature-enveloping-rsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
93 |
new Test("signature-enveloping-hmac-sha1.xml", SKKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
94 |
new Test("signature-external-dsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
95 |
new Test("signature-external-b64-dsa.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
96 |
new Test("signature-retrievalmethod-rawx509crt.xml", CKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
97 |
new Test("signature-keyname.xml", CKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
98 |
new Test("signature-x509-crt-crl.xml", RXKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
99 |
new Test("signature-x509-crt.xml", RXKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
100 |
new Test("signature-x509-is.xml", CKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
101 |
new Test("signature-x509-ski.xml", CKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
102 |
new Test("signature-x509-sn.xml", CKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
103 |
new Test("signature.xml", XKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
104 |
new Test("exc-signature.xml", KVKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
105 |
new Test("sign-spec.xml", RXKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
106 |
new Test("xmldsig-xfilter2.xml", KVKS) |
2 | 107 |
}; |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
108 |
|
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
109 |
private final static Test[] INVALID_TESTS = { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
110 |
new Test("signature-enveloping-hmac-sha1-40.xml", SKKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
111 |
new Test("signature-enveloping-hmac-sha1-trunclen-0-attack.xml", SKKS), |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
112 |
new Test("signature-enveloping-hmac-sha1-trunclen-8-attack.xml", SKKS) |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
113 |
}; |
2 | 114 |
|
115 |
public static void main(String args[]) throws Exception { |
|
116 |
httpUd = new HttpURIDereferencer(); |
|
117 |
||
118 |
validator = new SignatureValidator(new File(DATA_DIR)); |
|
119 |
||
120 |
boolean atLeastOneFailed = false; |
|
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
121 |
for (Test test : VALID_TESTS) { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
122 |
System.out.println("Validating " + test.file); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
123 |
if (test_signature(test)) { |
2 | 124 |
System.out.println("PASSED"); |
125 |
} else { |
|
126 |
System.out.println("FAILED"); |
|
127 |
atLeastOneFailed = true; |
|
128 |
} |
|
129 |
} |
|
130 |
// test with reference caching enabled |
|
131 |
System.out.println("Validating sign-spec.xml with caching enabled"); |
|
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
132 |
if (test_signature(new Test("sign-spec.xml", RXKS), true)) { |
2 | 133 |
System.out.println("PASSED"); |
134 |
} else { |
|
135 |
System.out.println("FAILED"); |
|
136 |
atLeastOneFailed = true; |
|
137 |
} |
|
138 |
||
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
139 |
for (Test test : INVALID_TESTS) { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
140 |
System.out.println("Validating " + test.file); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
141 |
try { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
142 |
test_signature(test); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
143 |
System.out.println("FAILED"); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
144 |
atLeastOneFailed = true; |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
145 |
} catch (XMLSignatureException xse) { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
146 |
System.out.println(xse.getMessage()); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
147 |
System.out.println("PASSED"); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
148 |
} |
3462 | 149 |
} |
150 |
||
2 | 151 |
if (atLeastOneFailed) { |
152 |
throw new Exception |
|
153 |
("At least one signature did not validate as expected"); |
|
154 |
} |
|
155 |
} |
|
156 |
||
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
157 |
public static boolean test_signature(Test test) throws Exception { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
158 |
return test_signature(test, false); |
2 | 159 |
} |
160 |
||
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
161 |
public static boolean test_signature(Test test, boolean cache) |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
162 |
throws Exception |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
163 |
{ |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
164 |
if (test.ks == null) { |
2 | 165 |
KeyStore keystore = KeyStore.getInstance("JKS"); |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
166 |
try (FileInputStream fis = new FileInputStream(KEYSTORE)) { |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
167 |
keystore.load(fis, "changeit".toCharArray()); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
168 |
test.ks = new X509KeySelector(keystore, false); |
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
169 |
} |
2 | 170 |
} |
11674
a657f8ba55fc
7131084: XMLDSig XPathFilter2Transform regression involving intersect filter
mullan
parents:
5506
diff
changeset
|
171 |
return validator.validate(test.file, test.ks, httpUd, cache); |
2 | 172 |
} |
173 |
||
174 |
/** |
|
175 |
* This URIDereferencer returns locally cached copies of http content to |
|
176 |
* avoid test failures due to network glitches, etc. |
|
177 |
*/ |
|
178 |
private static class HttpURIDereferencer implements URIDereferencer { |
|
179 |
private URIDereferencer defaultUd; |
|
180 |
||
181 |
HttpURIDereferencer() { |
|
182 |
defaultUd = XMLSignatureFactory.getInstance().getURIDereferencer(); |
|
183 |
} |
|
184 |
||
185 |
public Data dereference(final URIReference ref, XMLCryptoContext ctx) |
|
186 |
throws URIReferenceException { |
|
187 |
String uri = ref.getURI(); |
|
188 |
if (uri.equals(STYLESHEET) || uri.equals(STYLESHEET_B64)) { |
|
189 |
try { |
|
190 |
FileInputStream fis = new FileInputStream(new File |
|
191 |
(DATA_DIR, uri.substring(uri.lastIndexOf('/')))); |
|
192 |
return new OctetStreamData(fis,ref.getURI(),ref.getType()); |
|
193 |
} catch (Exception e) { throw new URIReferenceException(e); } |
|
194 |
} |
|
195 |
||
196 |
// fallback on builtin deref |
|
197 |
return defaultUd.dereference(ref, ctx); |
|
198 |
} |
|
199 |
} |
|
200 |
} |