LdapSocketFactory.java

/*
** Module   : LdapSocketFactory.java
** Abstract : Socket factory used to connect LDAP server using TLS.  
**
** Copyright (c) 2005-2017, Golden Code Development Corporation.
**
** -#- -I- --Date-- -T- --JPRM-- ----------------Description-----------------
** 001 SIY 20050424 NEW  @21018  Created initial version
** 002 SIY 20050516 CHG  @21197  Updated documentation.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.directory;

import java.io.FileInputStream;
import java.io.IOException;
import java.net.InetAddress;
import java.net.Socket;
import java.net.UnknownHostException;
import java.security.KeyStore;
import java.util.Enumeration;

import javax.net.SocketFactory;
import javax.net.ssl.KeyManagerFactory;
import javax.net.ssl.SSLContext;
import javax.net.ssl.SSLSocketFactory;
import javax.net.ssl.TrustManagerFactory;

import com.goldencode.p2j.cfg.ConfigurationException;

/**
 * Implementation of custom socket factory for use with LDAP server accessed
 * via TLS connection.
 * 
 * @author  SIY
 * @version 1.0
 */
public class LdapSocketFactory
extends SocketFactory
{
   /** Actual implementation of the factory */
   private static SSLSocketFactory factory = null;

   /**
    * Construct an instance of socket factory which will used keys from the
    * provided password encrypted file.
    * <p>
    * The approach of handling stores and certificates is taken from
    * <code>TransportSecurity</code> class.
    * 
    * @param   keyFile
    *          File name for the keystore.
    * @param   keyPass
    *          Password for keystore.
    * @param   trustFile
    *          File name for truststore.
    * @param   trustPass
    *          Password for truststore.
    * @param   subjectAlias
    *          Alias of the certificate to use.
    * @param   aliasPass
    *          Password for the certificate.
    * @throws  ConfigurationException
    *          In case of problems accessing required data.
    */
   static synchronized void initSocketFactory(String keyFile, String keyPass,
                                              String trustFile,
                                              String trustPass,
                                              String subjectAlias,
                                              String aliasPass)
   throws ConfigurationException
   {
      if (factory != null)
         return;

      KeyStore trustStore = null;
      KeyStore keyStore = null;
 
      try
      { 
         // client side truststore initialization
         // this is a file specified in bootstrap config
         trustStore = KeyStore.getInstance("JKS");
         FileInputStream trustIn = new FileInputStream(trustFile);
         trustStore.load(trustIn, trustPass.toCharArray());
         trustIn.close();
      }
      catch (Exception e)
      {
         throw new ConfigurationException("misconfigured truststore "
            + trustFile, e);
      }

      try
      {
         // creating an in-memory keystore
         keyStore = KeyStore.getInstance("JKS");
         FileInputStream keyIn = new FileInputStream(keyFile);
         keyStore.load(keyIn, keyPass.toCharArray());
         keyIn.close();
      }
      catch (Exception e)
      {
         throw new ConfigurationException("misconfigured keystore " + keyFile,
                                          e);
      }

      try
      {
         // verifying the keystore: must have alias that matches subjectAlias
         // or, if not specified, exactly one key entry
         if (subjectAlias != null && !keyStore.isKeyEntry(subjectAlias))
            throw new ConfigurationException("misconfigured keystore: "
               + "no matching alias for " + subjectAlias);

         if (subjectAlias == null)
         {
            Enumeration en = keyStore.aliases();
            int numkeys = 0;
            String alias = null;

            while (en.hasMoreElements())
            {
               alias = (String)en.nextElement();
               if (keyStore.isKeyEntry(alias))
                  numkeys++;
               if (subjectAlias == null)
                  subjectAlias = alias;
            }
            if (numkeys == 0)
               throw new ConfigurationException("misconfigured keystore: "
                  + "no private keys");
            if (numkeys > 1)
               throw new ConfigurationException("misconfigured keystore: "
                  + "multiple private keys " + "without alias");
         }

         // normalizing the keystore by deleting all unnecessary entries
         Enumeration en = keyStore.aliases();

         while (en.hasMoreElements())
         {
            String alias = (String)en.nextElement();

            if (!subjectAlias.equals(alias))
            {
               keyStore.deleteEntry(alias);
            }
         }
         // create a trust manager
         TrustManagerFactory tmf = TrustManagerFactory.getInstance("SunX509");
         tmf.init(trustStore);

         // create a key manager
         KeyManagerFactory kmf = KeyManagerFactory.getInstance("SunX509");
         kmf.init(keyStore, aliasPass.toCharArray());

         SSLContext ctx = SSLContext.getInstance("TLS");

         ctx.init(kmf.getKeyManagers(), tmf.getTrustManagers(), null);

         factory = ctx.getSocketFactory();
      }
      catch (Exception e)
      {
         throw new ConfigurationException("Unable to initialize SSLContext",
                                          e);
      }
   }
   
   /**
    * Return an instance of the LdapSocketFactory for use by client.
    * 
    * @return  LdapSocketFactory instance.
    */
   public static SocketFactory getDefault()
   {
      return new LdapSocketFactory();
   }

   /**
    * {@inheritDoc}
    */
   public Socket createSocket(String arg0, int arg1)
   throws IOException,
      UnknownHostException
   {
      return factory.createSocket(arg0, arg1);
   }

   /**
    * {@inheritDoc}
    */
   public Socket createSocket(InetAddress arg0, int arg1)
   throws IOException
   {
      return factory.createSocket(arg0, arg1);
   }

   /**
    * {@inheritDoc}
    */
   public Socket createSocket(String arg0, int arg1, InetAddress arg2,
                              int arg3)
   throws IOException,
      UnknownHostException
   {
      return factory.createSocket(arg0, arg1, arg2, arg3);
   }

   /**
    * {@inheritDoc}
    */
   public Socket createSocket(InetAddress arg0, int arg1, InetAddress arg2,
                              int arg3)
   throws IOException
   {
      return factory.createSocket(arg0, arg1, arg2, arg3);
   }
}