SecureSocketsRegistrar.java

/*
** Module   : SecureSocketsRegistrar.java
** Abstract : JCE/JSSE provider registrar. 
**
** Copyright (c) 2022-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- ---------------------------------Description----------------------------------
** 001 IAS 20220626 Created initial version.
**     TJD 20220722 Switched default implementation from TLS to TLS1.2
** 002 GBB 20230512 Logging methods replaced by CentralLogger/ConversionStatus.
*/ 

/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.security;

import java.security.*;
import java.util.logging.*;

import javax.net.ssl.*;

import com.goldencode.p2j.util.logging.*;
import org.bouncycastle.jsse.provider.*;

import com.goldencode.p2j.cfg.*;

/**
 * JCE/JSSE provider registrar  
 */
public class SecureSocketsRegistrar
{
   /** Logger. */
   private static final CentralLogger LOG = CentralLogger.get(SecureSocketsRegistrar.class.getName());

   /**
    * Register JCE/JSSE provider and optionally create SSLContext
    * @param bc
    *        bootstrap config 
    * @param createContext
    *        flag indicating that SSLContext should be created 
    * @return SSLContext or <code>bull</code> if not required.
    * 
    * @throws NoSuchAlgorithmException
    *         if "TLS" algorithm is not supported by a selected provider
    * @throws NoSuchProviderException
    *         if unknown provider was specified
    * @throws ConfigurationException
    *         if boostrap configuration is incorrect
    */
   public static SSLContext register(BootstrapConfig bc, boolean createContext) 
   throws NoSuchAlgorithmException, 
          NoSuchProviderException, 
          ConfigurationException
   {
      SSLContext ctx = null;
      String provider = bc.getConfigItem("security", "provider", "name");
      if ("bouncycastle".equals(provider) && BCProbe.bcFound)
      {
         Security.insertProviderAt(BCHolder.JCE, 1);
         Security.insertProviderAt(BCHolder.JSSE, 2);
         if (createContext)
         {
            ctx = SSLContext.getInstance("TLSv1.2", BCHolder.JSSE);
         }
         else
         {
            try
            {
               KeyManagerFactory.getInstance("PKIX", BouncyCastleJsseProvider.PROVIDER_NAME);
               TrustManagerFactory.getInstance("PKIX", BouncyCastleJsseProvider.PROVIDER_NAME);
            }
            catch (NoSuchAlgorithmException | 
                   NoSuchProviderException e)
            {
               LOG.log(Level.WARNING, "Failed to create key manager factories", e);
            }
         }
      }
      else if ("conscrypt".equals(provider) && CSProbe.csFound)
      {
         Security.insertProviderAt(CSHolder.SSL, 1);
         if (createContext)
         {
            ctx = SSLContext.getInstance("TLSv1.2", "Conscrypt");
         }
      }
      else
      {
         if (provider != null)
         {
            LOG.log(Level.WARNING,
                    String.format("Unknown security provider name: [%s], default one will be used", 
                                  provider)
                    );
         }         
         if (createContext)
         {
            ctx = SSLContext.getInstance("TLSv1.2");
         }
      }
      return ctx;
   }
}