1 package org.eclipse.jetty.server.ssl;
2
3
4
5
6
7
8
9
10
11
12
13
14
15 import java.io.ByteArrayInputStream;
16 import java.io.IOException;
17 import java.security.cert.X509Certificate;
18
19 import javax.net.ssl.SSLPeerUnverifiedException;
20 import javax.net.ssl.SSLSession;
21 import javax.net.ssl.SSLSocket;
22
23 import org.eclipse.jetty.http.HttpSchemes;
24 import org.eclipse.jetty.io.EndPoint;
25 import org.eclipse.jetty.io.bio.SocketEndPoint;
26 import org.eclipse.jetty.server.Request;
27 import org.eclipse.jetty.util.TypeUtil;
28 import org.eclipse.jetty.util.log.Log;
29 import org.eclipse.jetty.util.log.Logger;
30
31 public class SslCertificates
32 {
33 private static final Logger LOG = Log.getLogger(SslCertificates.class);
34
35
36
37
38 static final String CACHED_INFO_ATTR = CachedInfo.class.getName();
39
40 public static X509Certificate[] getCertChain(SSLSession sslSession)
41 {
42 try
43 {
44 javax.security.cert.X509Certificate javaxCerts[]=sslSession.getPeerCertificateChain();
45 if (javaxCerts==null||javaxCerts.length==0)
46 return null;
47
48 int length=javaxCerts.length;
49 X509Certificate[] javaCerts=new X509Certificate[length];
50
51 java.security.cert.CertificateFactory cf=java.security.cert.CertificateFactory.getInstance("X.509");
52 for (int i=0; i<length; i++)
53 {
54 byte bytes[]=javaxCerts[i].getEncoded();
55 ByteArrayInputStream stream=new ByteArrayInputStream(bytes);
56 javaCerts[i]=(X509Certificate)cf.generateCertificate(stream);
57 }
58
59 return javaCerts;
60 }
61 catch (SSLPeerUnverifiedException pue)
62 {
63 return null;
64 }
65 catch (Exception e)
66 {
67 LOG.warn(Log.EXCEPTION,e);
68 return null;
69 }
70 }
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99 public static void customize(SSLSession sslSession, EndPoint endpoint, Request request) throws IOException
100 {
101 request.setScheme(HttpSchemes.HTTPS);
102
103 try
104 {
105 String cipherSuite=sslSession.getCipherSuite();
106 Integer keySize;
107 X509Certificate[] certs;
108 String idStr;
109
110 CachedInfo cachedInfo=(CachedInfo)sslSession.getValue(CACHED_INFO_ATTR);
111 if (cachedInfo!=null)
112 {
113 keySize=cachedInfo.getKeySize();
114 certs=cachedInfo.getCerts();
115 idStr=cachedInfo.getIdStr();
116 }
117 else
118 {
119 keySize=new Integer(ServletSSL.deduceKeyLength(cipherSuite));
120 certs=SslCertificates.getCertChain(sslSession);
121 byte[] bytes = sslSession.getId();
122 idStr = TypeUtil.toHexString(bytes);
123 cachedInfo=new CachedInfo(keySize,certs,idStr);
124 sslSession.putValue(CACHED_INFO_ATTR,cachedInfo);
125 }
126
127 if (certs!=null)
128 request.setAttribute("javax.servlet.request.X509Certificate",certs);
129
130 request.setAttribute("javax.servlet.request.cipher_suite",cipherSuite);
131 request.setAttribute("javax.servlet.request.key_size",keySize);
132 request.setAttribute("javax.servlet.request.ssl_session_id", idStr);
133 }
134 catch (Exception e)
135 {
136 LOG.warn(Log.EXCEPTION,e);
137 }
138 }
139
140
141
142
143
144
145
146
147 private static class CachedInfo
148 {
149 private final X509Certificate[] _certs;
150 private final Integer _keySize;
151 private final String _idStr;
152
153 CachedInfo(Integer keySize, X509Certificate[] certs,String idStr)
154 {
155 this._keySize=keySize;
156 this._certs=certs;
157 this._idStr=idStr;
158 }
159
160 X509Certificate[] getCerts()
161 {
162 return _certs;
163 }
164
165 Integer getKeySize()
166 {
167 return _keySize;
168 }
169
170 String getIdStr()
171 {
172 return _idStr;
173 }
174 }
175
176 }