1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19 package org.eclipse.jetty.server.ssl;
20
21 import java.io.ByteArrayInputStream;
22 import java.io.IOException;
23 import java.security.cert.X509Certificate;
24
25 import javax.net.ssl.SSLPeerUnverifiedException;
26 import javax.net.ssl.SSLSession;
27 import javax.net.ssl.SSLSocket;
28
29 import org.eclipse.jetty.http.HttpSchemes;
30 import org.eclipse.jetty.io.EndPoint;
31 import org.eclipse.jetty.io.bio.SocketEndPoint;
32 import org.eclipse.jetty.server.Request;
33 import org.eclipse.jetty.util.TypeUtil;
34 import org.eclipse.jetty.util.log.Log;
35 import org.eclipse.jetty.util.log.Logger;
36
37 public class SslCertificates
38 {
39 private static final Logger LOG = Log.getLogger(SslCertificates.class);
40
41
42
43
44 static final String CACHED_INFO_ATTR = CachedInfo.class.getName();
45
46 public static X509Certificate[] getCertChain(SSLSession sslSession)
47 {
48 try
49 {
50 javax.security.cert.X509Certificate javaxCerts[]=sslSession.getPeerCertificateChain();
51 if (javaxCerts==null||javaxCerts.length==0)
52 return null;
53
54 int length=javaxCerts.length;
55 X509Certificate[] javaCerts=new X509Certificate[length];
56
57 java.security.cert.CertificateFactory cf=java.security.cert.CertificateFactory.getInstance("X.509");
58 for (int i=0; i<length; i++)
59 {
60 byte bytes[]=javaxCerts[i].getEncoded();
61 ByteArrayInputStream stream=new ByteArrayInputStream(bytes);
62 javaCerts[i]=(X509Certificate)cf.generateCertificate(stream);
63 }
64
65 return javaCerts;
66 }
67 catch (SSLPeerUnverifiedException pue)
68 {
69 return null;
70 }
71 catch (Exception e)
72 {
73 LOG.warn(Log.EXCEPTION,e);
74 return null;
75 }
76 }
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105 public static void customize(SSLSession sslSession, EndPoint endpoint, Request request) throws IOException
106 {
107 request.setScheme(HttpSchemes.HTTPS);
108
109 try
110 {
111 String cipherSuite=sslSession.getCipherSuite();
112 Integer keySize;
113 X509Certificate[] certs;
114 String idStr;
115
116 CachedInfo cachedInfo=(CachedInfo)sslSession.getValue(CACHED_INFO_ATTR);
117 if (cachedInfo!=null)
118 {
119 keySize=cachedInfo.getKeySize();
120 certs=cachedInfo.getCerts();
121 idStr=cachedInfo.getIdStr();
122 }
123 else
124 {
125 keySize=new Integer(ServletSSL.deduceKeyLength(cipherSuite));
126 certs=SslCertificates.getCertChain(sslSession);
127 byte[] bytes = sslSession.getId();
128 idStr = TypeUtil.toHexString(bytes);
129 cachedInfo=new CachedInfo(keySize,certs,idStr);
130 sslSession.putValue(CACHED_INFO_ATTR,cachedInfo);
131 }
132
133 if (certs!=null)
134 request.setAttribute("javax.servlet.request.X509Certificate",certs);
135
136 request.setAttribute("javax.servlet.request.cipher_suite",cipherSuite);
137 request.setAttribute("javax.servlet.request.key_size",keySize);
138 request.setAttribute("javax.servlet.request.ssl_session_id", idStr);
139 }
140 catch (Exception e)
141 {
142 LOG.warn(Log.EXCEPTION,e);
143 }
144 }
145
146
147
148
149
150
151
152
153 private static class CachedInfo
154 {
155 private final X509Certificate[] _certs;
156 private final Integer _keySize;
157 private final String _idStr;
158
159 CachedInfo(Integer keySize, X509Certificate[] certs,String idStr)
160 {
161 this._keySize=keySize;
162 this._certs=certs;
163 this._idStr=idStr;
164 }
165
166 X509Certificate[] getCerts()
167 {
168 return _certs;
169 }
170
171 Integer getKeySize()
172 {
173 return _keySize;
174 }
175
176 String getIdStr()
177 {
178 return _idStr;
179 }
180 }
181
182 }