From f1840b51d07bef3fc6b33164e4a26532d5caaca2 Mon Sep 17 00:00:00 2001 From: Dave Syer Date: Wed, 28 Jun 2023 15:39:44 +0000 Subject: [PATCH] Move certs into files --- spring-cloud-commons/pom.xml | 6 - .../cloud/configuration/KeyAndCert.java | 93 -------------- .../cloud/configuration/KeyTool.java | 113 ------------------ .../configuration/SSHContextFactoryTests.java | 58 ++------- .../src/test/resources/MyCA.p12 | Bin 0 -> 822 bytes .../src/test/resources/MyCert.p12 | Bin 0 -> 1736 bytes 6 files changed, 8 insertions(+), 262 deletions(-) delete mode 100644 spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/KeyAndCert.java delete mode 100644 spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/KeyTool.java create mode 100644 spring-cloud-commons/src/test/resources/MyCA.p12 create mode 100644 spring-cloud-commons/src/test/resources/MyCert.p12 diff --git a/spring-cloud-commons/pom.xml b/spring-cloud-commons/pom.xml index 4fc9ba42..6fcfa118 100644 --- a/spring-cloud-commons/pom.xml +++ b/spring-cloud-commons/pom.xml @@ -187,11 +187,5 @@ micrometer-observation-test test - - org.bouncycastle - bcpkix-jdk18on - 1.74 - test - diff --git a/spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/KeyAndCert.java b/spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/KeyAndCert.java deleted file mode 100644 index b3fb81ca..00000000 --- a/spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/KeyAndCert.java +++ /dev/null @@ -1,93 +0,0 @@ -/* - * Copyright 2018-2019 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * https://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.cloud.configuration; - -import java.security.KeyPair; -import java.security.KeyStore; -import java.security.PrivateKey; -import java.security.PublicKey; -import java.security.cert.Certificate; -import java.security.cert.X509Certificate; - -public class KeyAndCert { - - private KeyPair keyPair; - - private X509Certificate certificate; - - public KeyAndCert(KeyPair keyPair, X509Certificate certificate) { - this.keyPair = keyPair; - this.certificate = certificate; - } - - public KeyPair keyPair() { - return keyPair; - } - - public PublicKey publicKey() { - return keyPair.getPublic(); - } - - public PrivateKey privateKey() { - return keyPair.getPrivate(); - } - - public X509Certificate certificate() { - return certificate; - } - - public String subject() { - String dn = certificate.getSubjectX500Principal().getName(); - int index = dn.indexOf('='); - return dn.substring(index + 1); - } - - public KeyAndCert sign(String subject) throws Exception { - KeyTool tool = new KeyTool(); - return tool.signCertificate(subject, this); - } - - public KeyAndCert sign(KeyPair keyPair, String subject) throws Exception { - KeyTool tool = new KeyTool(); - return tool.signCertificate(keyPair, subject, this); - } - - public KeyStore storeKeyAndCert(String keyPassword) throws Exception { - KeyStore result = KeyStore.getInstance("PKCS12"); - result.load(null); - - result.setKeyEntry(subject(), keyPair.getPrivate(), keyPassword.toCharArray(), certChain()); - return result; - } - - private Certificate[] certChain() { - return new Certificate[] { certificate() }; - } - - public KeyStore storeCert() throws Exception { - return storeCert("PKCS12"); - } - - public KeyStore storeCert(String storeType) throws Exception { - KeyStore result = KeyStore.getInstance(storeType); - result.load(null); - - result.setCertificateEntry(subject(), certificate()); - return result; - } - -} diff --git a/spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/KeyTool.java b/spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/KeyTool.java deleted file mode 100644 index ea403d16..00000000 --- a/spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/KeyTool.java +++ /dev/null @@ -1,113 +0,0 @@ -/* - * Copyright 2018-2019 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * https://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.cloud.configuration; - -import java.math.BigInteger; -import java.security.KeyPair; -import java.security.KeyPairGenerator; -import java.security.PrivateKey; -import java.security.PublicKey; -import java.security.SecureRandom; -import java.security.cert.X509Certificate; -import java.util.Date; - -import org.bouncycastle.asn1.DERSequence; -import org.bouncycastle.asn1.x500.X500Name; -import org.bouncycastle.asn1.x509.BasicConstraints; -import org.bouncycastle.asn1.x509.Extension; -import org.bouncycastle.asn1.x509.GeneralName; -import org.bouncycastle.asn1.x509.GeneralNames; -import org.bouncycastle.asn1.x509.KeyUsage; -import org.bouncycastle.cert.X509CertificateHolder; -import org.bouncycastle.cert.jcajce.JcaX509CertificateConverter; -import org.bouncycastle.cert.jcajce.JcaX509v3CertificateBuilder; -import org.bouncycastle.operator.ContentSigner; -import org.bouncycastle.operator.jcajce.JcaContentSignerBuilder; - -public class KeyTool { - - private static final long ONE_DAY = 1000L * 60L * 60L * 24L; - - private static final long TEN_YEARS = ONE_DAY * 365L * 10L; - - public KeyAndCert createCA(String ca) throws Exception { - KeyPair keyPair = createKeyPair(); - X509Certificate certificate = createCert(keyPair, ca); - return new KeyAndCert(keyPair, certificate); - } - - public KeyAndCert signCertificate(String subject, KeyAndCert signer) throws Exception { - return signCertificate(createKeyPair(), subject, signer); - } - - public KeyAndCert signCertificate(KeyPair keyPair, String subject, KeyAndCert signer) throws Exception { - X509Certificate certificate = createCert(keyPair.getPublic(), signer.privateKey(), signer.subject(), subject); - KeyAndCert result = new KeyAndCert(keyPair, certificate); - - return result; - } - - public KeyPair createKeyPair() throws Exception { - return createKeyPair(1024); - } - - public KeyPair createKeyPair(int keySize) throws Exception { - KeyPairGenerator gen = KeyPairGenerator.getInstance("RSA"); - gen.initialize(keySize, new SecureRandom()); - return gen.generateKeyPair(); - } - - public X509Certificate createCert(KeyPair keyPair, String ca) throws Exception { - JcaX509v3CertificateBuilder builder = certBuilder(keyPair.getPublic(), ca, ca); - builder.addExtension(Extension.keyUsage, true, new KeyUsage(KeyUsage.keyCertSign)); - builder.addExtension(Extension.basicConstraints, false, new BasicConstraints(true)); - - return signCert(builder, keyPair.getPrivate()); - } - - public X509Certificate createCert(PublicKey publicKey, PrivateKey privateKey, String issuer, String subject) - throws Exception { - JcaX509v3CertificateBuilder builder = certBuilder(publicKey, issuer, subject); - builder.addExtension(Extension.keyUsage, true, new KeyUsage(KeyUsage.digitalSignature)); - builder.addExtension(Extension.basicConstraints, false, new BasicConstraints(false)); - - GeneralName[] names = new GeneralName[] { new GeneralName(GeneralName.dNSName, "localhost") }; - builder.addExtension(Extension.subjectAlternativeName, false, GeneralNames.getInstance(new DERSequence(names))); - - return signCert(builder, privateKey); - } - - private JcaX509v3CertificateBuilder certBuilder(PublicKey publicKey, String issuer, String subject) { - X500Name issuerName = new X500Name(String.format("dc=%s", issuer)); - X500Name subjectName = new X500Name(String.format("dc=%s", subject)); - - long now = System.currentTimeMillis(); - BigInteger serialNum = BigInteger.valueOf(now); - Date notBefore = new Date(now - ONE_DAY); - Date notAfter = new Date(now + TEN_YEARS); - - return new JcaX509v3CertificateBuilder(issuerName, serialNum, notBefore, notAfter, subjectName, publicKey); - } - - private X509Certificate signCert(JcaX509v3CertificateBuilder builder, PrivateKey privateKey) throws Exception { - ContentSigner signer = new JcaContentSignerBuilder("SHA256WithRSA").build(privateKey); - X509CertificateHolder holder = builder.build(signer); - - return new JcaX509CertificateConverter().getCertificate(holder); - } - -} diff --git a/spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/SSHContextFactoryTests.java b/spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/SSHContextFactoryTests.java index 0732d399..6fbcc4c2 100644 --- a/spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/SSHContextFactoryTests.java +++ b/spring-cloud-commons/src/test/java/org/springframework/cloud/configuration/SSHContextFactoryTests.java @@ -16,10 +16,7 @@ package org.springframework.cloud.configuration; -import java.io.File; -import java.io.FileOutputStream; import java.io.IOException; -import java.io.OutputStream; import java.security.GeneralSecurityException; import java.security.Key; import java.security.KeyStore; @@ -27,11 +24,10 @@ import java.security.cert.Certificate; import javax.net.ssl.SSLContext; -import org.junit.jupiter.api.BeforeAll; import org.junit.jupiter.api.BeforeEach; import org.junit.jupiter.api.Test; -import org.springframework.core.io.FileSystemResource; +import org.springframework.core.io.ClassPathResource; import org.springframework.core.io.Resource; import static org.assertj.core.api.Assertions.assertThat; @@ -42,60 +38,22 @@ public class SSHContextFactoryTests { private static final String KEY_PASSWORD = "test-key-password"; - private static KeyAndCert ca; - - private static KeyAndCert cert; - - private static File keyStore; - - private static File trustStore; - private TlsProperties properties; - @BeforeAll - public static void createKeyStoreAndTrustStore() throws Exception { - KeyTool tool = new KeyTool(); - - ca = tool.createCA("MyCA"); - cert = ca.sign("MyCert"); - - keyStore = saveKeyAndCert(cert); - trustStore = saveCert(ca); - } - - private static File saveKeyAndCert(KeyAndCert keyCert) throws Exception { - return saveKeyStore(keyCert.subject(), () -> keyCert.storeKeyAndCert(KEY_PASSWORD)); - } - - private static File saveCert(KeyAndCert keyCert) throws Exception { - return saveKeyStore(keyCert.subject(), keyCert::storeCert); - } - - private static File saveKeyStore(String prefix, KeyStoreSupplier func) throws Exception { - File result = File.createTempFile(prefix, ".p12"); - result.deleteOnExit(); - - try (OutputStream output = new FileOutputStream(result)) { - KeyStore store = func.createKeyStore(); - store.store(output, KEY_STORE_PASSWORD.toCharArray()); - } - return result; - } - @BeforeEach public void createProperties() { properties = new TlsProperties(); properties.setEnabled(true); - properties.setKeyStore(resourceOf(keyStore)); + properties.setKeyStore(resourceOf("MyCert.p12")); properties.setKeyStorePassword(KEY_STORE_PASSWORD); properties.setKeyPassword(KEY_PASSWORD); - properties.setTrustStore(resourceOf(trustStore)); + properties.setTrustStore(resourceOf("MyCA.p12")); properties.setTrustStorePassword(KEY_STORE_PASSWORD); } - private Resource resourceOf(File file) { - return new FileSystemResource(file); + private Resource resourceOf(String path) { + return new ClassPathResource(path); } @Test @@ -104,10 +62,10 @@ public class SSHContextFactoryTests { KeyStore store = factory.createKeyStore(); Certificate c = store.getCertificate("MyCert"); - assertThat(c).isEqualTo(cert.certificate()); + assertThat(c).isNotNull(); Key key = store.getKey("MyCert", KEY_PASSWORD.toCharArray()); - assertThat(key).isEqualTo(cert.privateKey()); + assertThat(key).isNotNull(); } @Test @@ -116,7 +74,7 @@ public class SSHContextFactoryTests { KeyStore store = factory.createTrustStore(); Certificate c = store.getCertificate("MyCA"); - assertThat(c).isEqualTo(ca.certificate()); + assertThat(c).isNotNull(); } @Test diff --git a/spring-cloud-commons/src/test/resources/MyCA.p12 b/spring-cloud-commons/src/test/resources/MyCA.p12 new file mode 100644 index 0000000000000000000000000000000000000000..ba068e07f1355b176b39e16629e751bb1a0c8228 GIT binary patch literal 822 zcmXqLVm4x8WHxAGy2Hk))#lOmotKfFaX}N)S(YZIlR)94KztA(#Rinx1Qc4w#K-`o zmLp^s4btEoR$hZh0}BL~$3UA!L@}VPME4x?=}C=$UZ$Pj*nT6B>lG7|x&RZSf&mX3 z2gGtFPF4m3SvJmuHV?*BW)?;*7J-k;ZZf>PtE8AMS7gofcAZ{B6O#d>hn$hq%VYU@ z6%UU55qh+`?OJPOh#jNbwAhCVY_i2~iiElDGFNL2Qx{wQ=;-g~69KY?zkL z4w85%!;~{yaBYp3miBk&yy=;L-fg$uv0ZaTLElsVNwa_J$T@HXdzvk=U%aOM_`@hc zi#r|9Dw_iyzl=?Ex-xzb|;h&F(pNJO1gY#+xtMU;b77 zz0a?Q`OAO5yZ$k|uD`PE)ce!ZTnkiAyc5awI4C^JHmNG$aNSBpmp?5wk9roU{&m{U zIq$^$|Npvs6ZftcJmwr4G^JgQZ)eHXJ-?VUbn?Ub#CVjYlV4OU0?BupcTbdUs*!(I;?`t&oAZyHvDy>u zv*$l}F=pRl{}yFty>M0GV<(0QN)uk6SiQaA@I3yzQ~vr*UNb}S1=H2}FOS`eba=h~ z)~PxtPeEUHgGbF0udljhp77Z6!)xY=mX7wxrMH&vdb8Pb-ZQ19aPjUwPR^*SsbM&5oAe lD>9TbWY@8X6vVlg|EyWCe)igfcY`FI_w1Q8>oq9J0s#1YaCQIy literal 0 HcmV?d00001 diff --git a/spring-cloud-commons/src/test/resources/MyCert.p12 b/spring-cloud-commons/src/test/resources/MyCert.p12 new file mode 100644 index 0000000000000000000000000000000000000000..ed30bb999ffb63fb2340d5ebf31a3191c622275e GIT binary patch literal 1736 zcma)6dpOez7~XF;*C9<;2`Rd;--cPJDON61xn-h>+)}C~jV=zqmXzxf(U^^ALRNE` zQp-syr<+`7a!nSpCn@*GIgaz3^XNH$o%6@{e9!m3-~0Xbz8?sopThwJ2%%4+RkkEJ zCQM@hC4dK^{gDvbcMBf-As~B?Srt z`hcXLqdK@1iJjWo`h+%M&vx2(!RU~ug(ex%a1{Y?|l~w9QSM_fe)<6fk?p{I0X66x~)^f#vZ8ak70DTrB>sdB-FoZa*f9v3Z2^ zIp~LRV^NjzP(QL;V=l0KGo#k#1-0u;TcM=D`**3w8bQ}k3vDCUNuKW4a$K_0eK4qR zZj*uOfEjH1?0TcAFSfeTyR?};JE)stlYo({(gPbmu1@dVh_Q_8J~O-dv=?e-fp`kNRDpVS8dLsKYr;~~*n>kF`7BWP{8l3c7ZAB6o+k7B zz1&<7e7(Kzi(|%#iC0eK7_!0evz`T9LT3IW3f)}gPTi%emCiD!oqC+OP;Nl7wbA@6 zFQ+&MCz^mw$?4=bm+CD}zX-SYUHkf}N*>PU>OPZ%1TW6Zv~xr!lXv6z51qK!?Z%~W z$=izUW2quzvG%>aKio76zJ87u)fZ7SYq;5Fy=vc2Nlpto=){%S^bRQLVll66Wsz0o zilNcZbJ$c8p^5K`WKhozBcyohwOzG=2wK6r;o-oi07PrG80gPO7l3*T@eDqqNDl&x+E_*zaaoDljP%$if0#oK{vm+Y;A#cSxP z!y;fYu%obG*csSa(BLPjgU2GZJM>*I+etL;Q0NCK@u!eU~^mzI>!iy<0VgnHos zY_WCxWPtyQRdr2cUqKi?B`W$tV%;uJ+UMwk>)ndx} z8`L?jEQL$G{>?r<7J#l)H74F83W{xXGq=SxW-%oJHp{{TwOT*2xmH!m z1}VC~)qV_ZOoItO=v%~pn6ANfRQVqX^(LQ~H{5!qs3n9b8Ml_73~McyIu#F|=oKNU z2j9KQzmU9>xx4wCM)0_wgDwXavsXUa?B<>8LV4b$I$39G$eL|DSVars$+_KXO^g*s zN5X=*x2Zm9V)=}nw}{6RM?8A({ILtI+uRygr_2IE2&4sanaO_9n({oQh-@ZU@-nMh zg}&2c?1jIzEnoCnYSs}@?+L7j6s@DWg+?h{;SQsgjY zmV^@Tu;a|$9{j2Od#Dkcn?+yo0Fr+>^h1Oo#uE`f1 zbq+O7DN!l{Mz-;8CHJ$kQOQB~cYQ-*nQAVa+`yH4ocnX)Ypa{