SecureSocketsRegistrar.java
/*
** Module : SecureSocketsRegistrar.java
** Abstract : JCE/JSSE provider registrar.
**
** Copyright (c) 2022-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- ---------------------------------Description----------------------------------
** 001 IAS 20220626 Created initial version.
** TJD 20220722 Switched default implementation from TLS to TLS1.2
** 002 GBB 20230512 Logging methods replaced by CentralLogger/ConversionStatus.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
**
** Additional terms under GNU Affero GPL version 3 section 7:
**
** Under Section 7 of the GNU Affero GPL version 3, the following additional
** terms apply to the works covered under the License. These additional terms
** are non-permissive additional terms allowed under Section 7 of the GNU
** Affero GPL version 3 and may not be removed by you.
**
** 0. Attribution Requirement.
**
** You must preserve all legal notices or author attributions in the covered
** work or Appropriate Legal Notices displayed by works containing the covered
** work. You may not remove from the covered work any author or developer
** credit already included within the covered work.
**
** 1. No License To Use Trademarks.
**
** This license does not grant any license or rights to use the trademarks
** Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
** of Golden Code Development Corporation. You are not authorized to use the
** name Golden Code, FWD, or the names of any author or contributor, for
** publicity purposes without written authorization.
**
** 2. No Misrepresentation of Affiliation.
**
** You may not represent yourself as Golden Code Development Corporation or FWD.
**
** You may not represent yourself for publicity purposes as associated with
** Golden Code Development Corporation, FWD, or any author or contributor to
** the covered work, without written authorization.
**
** 3. No Misrepresentation of Source or Origin.
**
** You may not represent the covered work as solely your work. All modified
** versions of the covered work must be marked in a reasonable way to make it
** clear that the modified work is not originating from Golden Code Development
** Corporation or FWD. All modified versions must contain the notices of
** attribution required in this license.
*/
package com.goldencode.p2j.security;
import java.security.*;
import java.util.logging.*;
import javax.net.ssl.*;
import com.goldencode.p2j.util.logging.*;
import org.bouncycastle.jsse.provider.*;
import com.goldencode.p2j.cfg.*;
/**
* JCE/JSSE provider registrar
*/
public class SecureSocketsRegistrar
{
/** Logger. */
private static final CentralLogger LOG = CentralLogger.get(SecureSocketsRegistrar.class.getName());
/**
* Register JCE/JSSE provider and optionally create SSLContext
* @param bc
* bootstrap config
* @param createContext
* flag indicating that SSLContext should be created
* @return SSLContext or <code>bull</code> if not required.
*
* @throws NoSuchAlgorithmException
* if "TLS" algorithm is not supported by a selected provider
* @throws NoSuchProviderException
* if unknown provider was specified
* @throws ConfigurationException
* if boostrap configuration is incorrect
*/
public static SSLContext register(BootstrapConfig bc, boolean createContext)
throws NoSuchAlgorithmException,
NoSuchProviderException,
ConfigurationException
{
SSLContext ctx = null;
String provider = bc.getConfigItem("security", "provider", "name");
if ("bouncycastle".equals(provider) && BCProbe.bcFound)
{
Security.insertProviderAt(BCHolder.JCE, 1);
Security.insertProviderAt(BCHolder.JSSE, 2);
if (createContext)
{
ctx = SSLContext.getInstance("TLSv1.2", BCHolder.JSSE);
}
else
{
try
{
KeyManagerFactory.getInstance("PKIX", BouncyCastleJsseProvider.PROVIDER_NAME);
TrustManagerFactory.getInstance("PKIX", BouncyCastleJsseProvider.PROVIDER_NAME);
}
catch (NoSuchAlgorithmException |
NoSuchProviderException e)
{
LOG.log(Level.WARNING, "Failed to create key manager factories", e);
}
}
}
else if ("conscrypt".equals(provider) && CSProbe.csFound)
{
Security.insertProviderAt(CSHolder.SSL, 1);
if (createContext)
{
ctx = SSLContext.getInstance("TLSv1.2", "Conscrypt");
}
}
else
{
if (provider != null)
{
LOG.log(Level.WARNING,
String.format("Unknown security provider name: [%s], default one will be used",
provider)
);
}
if (createContext)
{
ctx = SSLContext.getInstance("TLSv1.2");
}
}
return ctx;
}
}