Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Sign in / Register
Toggle navigation
S
spring-boot
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
DEMO
spring-boot
Commits
62c8ac6e
Commit
62c8ac6e
authored
Jan 15, 2019
by
Raheela
Committed by
Andy Wilkinson
Jan 22, 2019
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Always fail fast when SSL is enabled without a key store
See gh-15709
parent
acf9e8ac
Changes
4
Hide whitespace changes
Inline
Side-by-side
Showing
4 changed files
with
91 additions
and
10 deletions
+91
-10
SslServerCustomizer.java
...ramework/boot/web/embedded/netty/SslServerCustomizer.java
+27
-5
SslBuilderCustomizer.java
...work/boot/web/embedded/undertow/SslBuilderCustomizer.java
+26
-5
SslServerCustomizerTests.java
...ork/boot/web/embedded/netty/SslServerCustomizerTests.java
+17
-0
SslBuilderCustomizerTests.java
...boot/web/embedded/undertow/SslBuilderCustomizerTests.java
+21
-0
No files found.
spring-boot-project/spring-boot/src/main/java/org/springframework/boot/web/embedded/netty/SslServerCustomizer.java
View file @
62c8ac6e
...
...
@@ -16,6 +16,7 @@
package
org
.
springframework
.
boot
.
web
.
embedded
.
netty
;
import
java.io.FileNotFoundException
;
import
java.net.URL
;
import
java.security.KeyStore
;
import
java.util.Arrays
;
...
...
@@ -31,6 +32,7 @@ import reactor.netty.tcp.SslProvider;
import
org.springframework.boot.web.server.Http2
;
import
org.springframework.boot.web.server.Ssl
;
import
org.springframework.boot.web.server.SslStoreProvider
;
import
org.springframework.boot.web.server.WebServerException
;
import
org.springframework.util.ResourceUtils
;
/**
...
...
@@ -38,6 +40,7 @@ import org.springframework.util.ResourceUtils;
* instance.
*
* @author Brian Clozel
* @author Raheela Aslam
*/
public
class
SslServerCustomizer
implements
NettyServerCustomizer
{
...
...
@@ -135,21 +138,40 @@ public class SslServerCustomizer implements NettyServerCustomizer {
if
(
sslStoreProvider
!=
null
)
{
return
sslStoreProvider
.
getTrustStore
();
}
return
load
Key
Store
(
ssl
.
getTrustStoreType
(),
ssl
.
getTrustStoreProvider
(),
return
load
Trust
Store
(
ssl
.
getTrustStoreType
(),
ssl
.
getTrustStoreProvider
(),
ssl
.
getTrustStore
(),
ssl
.
getTrustStorePassword
());
}
private
KeyStore
loadKeyStore
(
String
type
,
String
provider
,
String
resource
,
String
password
)
throws
Exception
{
type
=
(
type
!=
null
)
?
type
:
"JKS"
;
return
loadStore
(
type
,
provider
,
resource
,
password
);
}
private
KeyStore
loadTrustStore
(
String
type
,
String
provider
,
String
resource
,
String
password
)
throws
Exception
{
if
(
resource
==
null
)
{
return
null
;
}
else
{
return
loadStore
(
type
,
provider
,
resource
,
password
);
}
}
private
KeyStore
loadStore
(
String
type
,
String
provider
,
String
resource
,
String
password
)
throws
Exception
{
type
=
(
type
!=
null
)
?
type
:
"JKS"
;
KeyStore
store
=
(
provider
!=
null
)
?
KeyStore
.
getInstance
(
type
,
provider
)
:
KeyStore
.
getInstance
(
type
);
URL
url
=
ResourceUtils
.
getURL
(
resource
);
store
.
load
(
url
.
openStream
(),
(
password
!=
null
)
?
password
.
toCharArray
()
:
null
);
return
store
;
try
{
URL
url
=
ResourceUtils
.
getURL
(
resource
);
store
.
load
(
url
.
openStream
(),
(
password
!=
null
)
?
password
.
toCharArray
()
:
null
);
return
store
;
}
catch
(
FileNotFoundException
ex
)
{
throw
new
WebServerException
(
"Could not load store: "
+
ex
.
getMessage
(),
ex
);
}
}
}
spring-boot-project/spring-boot/src/main/java/org/springframework/boot/web/embedded/undertow/SslBuilderCustomizer.java
View file @
62c8ac6e
...
...
@@ -16,6 +16,7 @@
package
org
.
springframework
.
boot
.
web
.
embedded
.
undertow
;
import
java.io.FileNotFoundException
;
import
java.net.InetAddress
;
import
java.net.Socket
;
import
java.net.URL
;
...
...
@@ -41,12 +42,14 @@ import org.xnio.SslClientAuthMode;
import
org.springframework.boot.web.server.Ssl
;
import
org.springframework.boot.web.server.SslStoreProvider
;
import
org.springframework.boot.web.server.WebServerException
;
import
org.springframework.util.ResourceUtils
;
/**
* {@link UndertowBuilderCustomizer} that configures SSL on the given builder instance.
*
* @author Brian Clozel
* @author Raheela Aslam
*/
class
SslBuilderCustomizer
implements
UndertowBuilderCustomizer
{
...
...
@@ -166,21 +169,39 @@ class SslBuilderCustomizer implements UndertowBuilderCustomizer {
if
(
sslStoreProvider
!=
null
)
{
return
sslStoreProvider
.
getTrustStore
();
}
return
load
Key
Store
(
ssl
.
getTrustStoreType
(),
ssl
.
getTrustStoreProvider
(),
return
load
Trust
Store
(
ssl
.
getTrustStoreType
(),
ssl
.
getTrustStoreProvider
(),
ssl
.
getTrustStore
(),
ssl
.
getTrustStorePassword
());
}
private
KeyStore
loadKeyStore
(
String
type
,
String
provider
,
String
resource
,
String
password
)
throws
Exception
{
type
=
(
type
!=
null
)
?
type
:
"JKS"
;
return
loadStore
(
type
,
provider
,
resource
,
password
);
}
private
KeyStore
loadTrustStore
(
String
type
,
String
provider
,
String
resource
,
String
password
)
throws
Exception
{
if
(
resource
==
null
)
{
return
null
;
}
else
{
return
loadStore
(
type
,
provider
,
resource
,
password
);
}
}
private
KeyStore
loadStore
(
String
type
,
String
provider
,
String
resource
,
String
password
)
throws
Exception
{
type
=
(
type
!=
null
)
?
type
:
"JKS"
;
KeyStore
store
=
(
provider
!=
null
)
?
KeyStore
.
getInstance
(
type
,
provider
)
:
KeyStore
.
getInstance
(
type
);
URL
url
=
ResourceUtils
.
getURL
(
resource
);
store
.
load
(
url
.
openStream
(),
(
password
!=
null
)
?
password
.
toCharArray
()
:
null
);
return
store
;
try
{
URL
url
=
ResourceUtils
.
getURL
(
resource
);
store
.
load
(
url
.
openStream
(),
(
password
!=
null
)
?
password
.
toCharArray
()
:
null
);
return
store
;
}
catch
(
FileNotFoundException
ex
)
{
throw
new
WebServerException
(
"Could not load store: "
+
ex
.
getMessage
(),
ex
);
}
}
/**
...
...
spring-boot-project/spring-boot/src/test/java/org/springframework/boot/web/embedded/netty/SslServerCustomizerTests.java
View file @
62c8ac6e
...
...
@@ -29,6 +29,7 @@ import static org.junit.Assert.fail;
* Tests for {@link SslServerCustomizer}.
*
* @author Andy Wilkinson
* @author Raheela Aslam
*/
public
class
SslServerCustomizerTests
{
...
...
@@ -68,4 +69,20 @@ public class SslServerCustomizerTests {
}
}
@Test
public
void
keyStoreProviderIsUsedWhenKeyStoreNotContaining
()
throws
Exception
{
Ssl
ssl
=
new
Ssl
();
ssl
.
setKeyPassword
(
"password"
);
SslServerCustomizer
customizer
=
new
SslServerCustomizer
(
ssl
,
null
,
null
);
try
{
customizer
.
getKeyManagerFactory
(
ssl
,
null
);
fail
();
}
catch
(
IllegalStateException
ex
)
{
Throwable
cause
=
ex
.
getCause
();
assertThat
(
cause
).
isInstanceOf
(
IllegalArgumentException
.
class
);
assertThat
(
cause
).
hasMessageContaining
(
"Resource location must not be null"
);
}
}
}
spring-boot-project/spring-boot/src/test/java/org/springframework/boot/web/embedded/undertow/SslBuilderCustomizerTests.java
View file @
62c8ac6e
...
...
@@ -33,6 +33,7 @@ import static org.junit.Assert.fail;
* Tests for {@link SslBuilderCustomizer}
*
* @author Brian Clozel
* @author Raheela Aslam
*/
public
class
SslBuilderCustomizerTests
{
...
...
@@ -88,4 +89,24 @@ public class SslBuilderCustomizerTests {
}
}
@Test
public
void
getKeyManagersWhenKeyStoreIsNotProvided
()
throws
Exception
{
Ssl
ssl
=
new
Ssl
();
ssl
.
setKeyPassword
(
"password"
);
SslBuilderCustomizer
customizer
=
new
SslBuilderCustomizer
(
8080
,
InetAddress
.
getLocalHost
(),
ssl
,
null
);
try
{
KeyManager
[]
keyManagers
=
ReflectionTestUtils
.
invokeMethod
(
customizer
,
"getKeyManagers"
,
ssl
,
null
);
Class
<?>
name
=
Class
.
forName
(
"org.springframework.boot.web.embedded.undertow"
+
".SslBuilderCustomizer$ConfigurableAliasKeyManager"
);
assertThat
(
keyManagers
[
0
]).
isNotInstanceOf
(
name
);
}
catch
(
IllegalStateException
ex
)
{
Throwable
cause
=
ex
.
getCause
();
assertThat
(
cause
).
isInstanceOf
(
IllegalArgumentException
.
class
);
assertThat
(
cause
).
hasMessageContaining
(
"Resource location must not be null"
);
}
}
}
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment