SSLHelper.java

/*
** Module   : SSLHelper.java
** Abstract : SSL processing convenience methods
**
** Copyright (c) 2016-2017, Golden Code Development Corporation.
**
** -#- -I- --Date-- -------------------------------Description-----------------------------------
** 001 GES 20160113 First version.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.security;

import java.io.*;
import java.util.*;
import java.security.*;
import java.security.cert.*;
import javax.net.ssl.*;

/**
 * Provides static SSL processing convenience methods.
 */
public class SSLHelper
{
   /** Detailed return codes. */
   public static enum ErrorCode
   {
      NO_ERROR,
      NULL_KEYSTORE,
      NULL_FILENAME,
      FILE_DOESNT_EXIST,
      LOAD_IO_FAILURE,
      LOAD_ALGORITHM_FAILURE,
      LOAD_CERT_FAILURE,
      INVALID_RESULT_ARRAY,
      KEYMANAGER_INIT_FAILURE,
      KEYMANAGER_ALGORITHM_FAILURE,
      KEY_READ_FAILURE,
      UNEXPECTED_FAILURE
   };
   
   /**
    * Private constructor to disallow instantiation.
    */
   private SSLHelper()
   {
   }
   
   /**
    * Given a valid key store instance and a filename to an existing file that
    * is a valid keystore, the contents will be loaded from the file system.
    *
    * @param    ks
    *           The in-memory key store into which to load.
    * @param    fname
    *           The filename of the file system resource that contains the key
    *           store from which to load.
    * @param    pw
    *           A valid password needed to decrypt the contents during load or
    *           <code>null</code> if no password is needed.
    *
    * @return   <code>ErrorCode.NO_ERROR</code> on success, otherwise a descriptive
    *           return code to explain the failure.
    */
   public static ErrorCode loadKeyStoreFromFile(KeyStore ks, String fname, String pw)
   {
      if (ks == null)
      {
         return ErrorCode.NULL_KEYSTORE;
      }
      
      if (fname == null)
      {
         return ErrorCode.NULL_FILENAME;
      }
      
      InputStream kis = null;
      
      try
      {
         File file = new File(fname);
         
         if (file.exists())
         {
            kis = new FileInputStream(fname);
         }
         else
         {
            return ErrorCode.FILE_DOESNT_EXIST;
         }
         
         ks.load(kis, (pw == null) ? null : pw.toCharArray());
      }
      
      catch (NullPointerException npe)
      {
         // should not occur
         return ErrorCode.UNEXPECTED_FAILURE;
      }
      
      catch (FileNotFoundException fnf)
      {
         // should not occur
         return ErrorCode.FILE_DOESNT_EXIST;
      }
      
      catch (IOException ioe)
      {
         return ErrorCode.LOAD_IO_FAILURE;
      }
      
      catch (NoSuchAlgorithmException nsa)
      {
         return ErrorCode.LOAD_ALGORITHM_FAILURE;
      }
      
      catch (CertificateException ce)
      {
         return ErrorCode.LOAD_CERT_FAILURE;
      }
      
      finally
      {
         if (kis != null)
         {
            try
            {
               kis.close();
            }
            
            catch (IOException ioe)
            {
               // nothing to do, ignore this
            }
         }
      }
      
      return ErrorCode.NO_ERROR;
   }
   
   /**
    * Initialize the key manager array using the given key store.
    *
    * @param    ks
    *           Key store from which to initialize the key managers.
    * @param    pw
    *           Key entry password or <code>null</code> if not needed.
    * @param    result
    *           An array into which the key manager array reference can be returned. The
    *           array size must be at least 1 element and the 0 index element will be
    *           replaced with a <code>KeyManager[]</code> reference on success.
    *
    * @return   <code>ErrorCode.NO_ERROR</code> on success, otherwise a descriptive
    *           return code to explain the failure.
    */
   public static ErrorCode initKeyManagers(KeyStore ks, String pw, Object[] result)
   {
      if (ks == null)
      {
         return ErrorCode.NULL_KEYSTORE;
      }
      
      if (result == null || result.length < 1)
      {
         return ErrorCode.INVALID_RESULT_ARRAY;
      }
      
      try
      {
      
         KeyManagerFactory kmf = KeyManagerFactory.getInstance("SunX509");
         
         kmf.init(ks, (pw == null) ? null : pw.toCharArray());
      
         result[0] = kmf.getKeyManagers();
      }
      
      catch (NoSuchAlgorithmException nsa)
      {
         return ErrorCode.KEYMANAGER_ALGORITHM_FAILURE;
      }
      
      catch (KeyStoreException kse)
      {
         return ErrorCode.KEYMANAGER_INIT_FAILURE;
      }
      
      catch (UnrecoverableKeyException uke)
      {
         return ErrorCode.KEY_READ_FAILURE;
      }
      
      return ErrorCode.NO_ERROR;
   }
}