Commit af426d08 authored by Dave Syer's avatar Dave Syer

Be more defensive about a null password in Undertow SSL

Fixes gh-6387
parent b1dd9288
...@@ -294,14 +294,17 @@ public class UndertowEmbeddedServletContainerFactory ...@@ -294,14 +294,17 @@ public class UndertowEmbeddedServletContainerFactory
} }
KeyStore keyStore = KeyStore.getInstance(keyStoreType); KeyStore keyStore = KeyStore.getInstance(keyStoreType);
URL url = ResourceUtils.getURL(ssl.getKeyStore()); URL url = ResourceUtils.getURL(ssl.getKeyStore());
keyStore.load(url.openStream(), ssl.getKeyStorePassword().toCharArray()); char[] keyStorePassword = ssl.getKeyStorePassword() != null
? ssl.getKeyStorePassword().toCharArray()
: null;
keyStore.load(url.openStream(), keyStorePassword);
// Get key manager to provide client credentials. // Get key manager to provide client credentials.
KeyManagerFactory keyManagerFactory = KeyManagerFactory KeyManagerFactory keyManagerFactory = KeyManagerFactory
.getInstance(KeyManagerFactory.getDefaultAlgorithm()); .getInstance(KeyManagerFactory.getDefaultAlgorithm());
char[] keyPassword = ssl.getKeyPassword() != null char[] keyPassword = ssl.getKeyPassword() != null
? ssl.getKeyPassword().toCharArray() ? ssl.getKeyPassword().toCharArray()
: ssl.getKeyStorePassword().toCharArray(); : keyStorePassword;
keyManagerFactory.init(keyStore, keyPassword); keyManagerFactory.init(keyStore, keyPassword);
return keyManagerFactory.getKeyManagers(); return keyManagerFactory.getKeyManagers();
} }
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment