Path: blob/master/test/jdk/javax/net/ssl/SSLSocket/ClientExcOnAlert.java
41152 views
/*1* Copyright (c) 2020, Oracle and/or its affiliates. All rights reserved.2* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.3*4* This code is free software; you can redistribute it and/or modify it5* under the terms of the GNU General Public License version 2 only, as6* published by the Free Software Foundation.7*8* This code is distributed in the hope that it will be useful, but WITHOUT9* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or10* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License11* version 2 for more details (a copy is included in the LICENSE file that12* accompanied this code).13*14* You should have received a copy of the GNU General Public License version15* 2 along with this work; if not, write to the Free Software Foundation,16* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.17*18* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA19* or visit www.oracle.com if you need additional information or have any20* questions.21*/2223//24// Please run in othervm mode. SunJSSE does not support dynamic system25// properties, no way to re-use system properties in samevm/agentvm mode.26//2728/*29* @test30* @bug 824229431* @summary JSSE Client does not throw SSLException when an alert occurs during32* handshaking.33* @run main/othervm ClientExcOnAlert TLSv1.234* @run main/othervm ClientExcOnAlert TLSv1.335*/3637import java.io.BufferedReader;38import java.io.ByteArrayInputStream;39import java.io.IOException;40import java.io.InputStreamReader;41import java.io.PrintWriter;42import java.net.InetAddress;43import java.security.GeneralSecurityException;44import java.security.KeyStore;45import java.util.Base64;46import java.util.concurrent.locks.Condition;47import java.util.concurrent.locks.Lock;48import java.util.concurrent.locks.ReentrantLock;49import javax.net.ssl.KeyManagerFactory;50import javax.net.ssl.SSLContext;51import javax.net.ssl.SSLException;52import javax.net.ssl.SSLServerSocket;53import javax.net.ssl.SSLServerSocketFactory;54import javax.net.ssl.SSLSocket;55import javax.net.ssl.SSLSocketFactory;5657public class ClientExcOnAlert {58// This is a PKCS#12 keystore created with the following command:59// keytool -genkeypair -alias testcert -keyalg rsa -keysize 204860// -sigalg SHA256withRSA61// -dname "CN=Test TLS Self-Signed Cert, O=Test" -validity 36562// -storetype pkcs12 -keystore p12ks.p1263//64// The resulting keystore was then converted to PEM for inclusion in this65// file.66private static int serverPort = -1;67private static final String KEYSTORE_PASS = "password";68private static final String KEYSTORE_PEM =69"MIIJrwIBAzCCCWgGCSqGSIb3DQEHAaCCCVkEgglVMIIJUTCCBW0GCSqGSIb3DQEH\n" +70"AaCCBV4EggVaMIIFVjCCBVIGCyqGSIb3DQEMCgECoIIE+zCCBPcwKQYKKoZIhvcN\n" +71"AQwBAzAbBBRvyuWzvSCS62cWMeKOcF0JnaYRPgIDAMNQBIIEyMrZGW/sgjhW20Gz\n" +72"fdj/NkWYORRTPCopS/y0NvZpmQgcu5uSbJWsadClnFBMQ2aZDJ5jaa5G2ipcrVSo\n" +73"c7RYSi2vAh2fqGtm25spSKyV/t1q7Z07FBIQWVNMR9IczWmM5fQyeY7V9o2M3DtN\n" +74"3co0RjXEpVQbvxXc5UI3Tbv8q3WKoxadicvm3uMTQCV1/swObYZqHUAMrvwgkXSy\n" +75"omTsCr8JwKvI2ndPA1tD+63h9v+zHK7U6n24DBNJNxZOSmUO7L+WxgQ4COkTXhZj\n" +76"24sYJcBJcGb74p9rv7QQn5WmkJBh+lfCQU+cS0bL6VwRZOyAesniMBpytaR5/SQW\n" +77"UwAk230oy64x0WegG/q4uAIeczBlu2L1HDGJp3KbGwsu5Zwqs3psHjUZJEforWzR\n" +78"RGTU+eBGi0U/BSeyeyY3HRimRrXytmXGcGFy6KcgAGeDwu6tG4hblyK+Fd4+8vw0\n" +79"T3sYOsOPR3NjOFshtcnsTa/Q9lPCAAA3WNieJyWmnh+Zg0EU26GOEeagfZ8JLvfh\n" +80"U1tE6e2j7L4xTt03IR2Z0U1bq+dY9eqfZb4PAqW7Zgv16m586QIjeSUecjlDRrN4\n" +81"OYtOKAbO2qFjevgv/5e8ja4d5rM+xlT8vcOaoLXqGvBzgWvQcDOBp3Bd7I3KuWjZ\n" +82"+i//bK7dnahOJP4Y2swdTy4AYkbNDPRwPmQRi0uwQ+ALH5VOxwa/MslkbmEuxVqw\n" +83"t/F7IP150rIT2GeV3QTE4H6QtIGHcdib72zc3eer+GqxbSCqslaxOLKneSHuFCCo\n" +84"9/jxaYA1i8Gunn16DV19UP8DXsOaW4pHl8FOOvTMEvLNxuXHQrZpltxfibZXW8CL\n" +85"Yo6HX9dXmDsf+L9M0FKOJHwueT6+aWuUzy3Y2MSb2BdxTJYzXzwqaqnsFBVxtlzB\n" +86"WsAoCpmXISqzQcnobqkHJ5BURVGR6o1CM1X7SvxlHV/vMtIsfjiXdWb0oPhO0KHd\n" +87"agOOCg4N8t6vNkj3CXoePZC1n+2+Ldx89rIsebs7Y0PBmtcnW2Ez9q6BekxVNZVJ\n" +88"Mcg5fzZROgQyK5rgy5IuHAUlnK/peYyoIYDLV8uFico7Fx/oIcB44mkAhVyDoP5E\n" +89"FSCJxi5ory1nQ1kxhfVLEPUAbUq+0q2qhx/oagbEhWJxPgkYpqr5TaXG7w3Tf735\n" +90"JH22YvwgfmFp9gwObZY9Ea6cmJb+jgamETLCgo5A+ghg5ecdvg9ivLBxEK1Kmx8y\n" +91"DHlZxm/EQnSXYUD37E0UyFdYMoXmm39avOiOmZn4z22N//WWGvI2NH0B+R9x/i3A\n" +92"TwvpcbJfGx3eYJnizH71GPQZOG0EbU6ctMaZqv6zMijqBwDJadl3q7m4PadJClup\n" +93"NW1Y+J1hJ7XJIzcS/fBTu1GHFpQNkKCuv3Dly3XhkqINGRpunA02BX51mFU3SJM+\n" +94"78cSq4mYt0ej5fO8iaDUEz/izTawZVryW8VvVShfHp5KHBqZEbNsEY7d06DwT+Rk\n" +95"9990eywGasADs0TvNcuSguIfU1WcKaCYBK4fWmy34+aDkwBQalOmzk7fSnzugKBe\n" +96"0mpEDey2SkTOlhX0VkHUd0YDF2hg+FAgZmFkCDqgAE9jYIOdAIYsHFGMp4VebBoM\n" +97"Bg2zaxQ/CCeQ+f85zDFEMB8GCSqGSIb3DQEJFDESHhAAdABlAHMAdABjAGUAcgB0\n" +98"MCEGCSqGSIb3DQEJFTEUBBJUaW1lIDE1ODYxNTM1NzA3NTMwggPcBgkqhkiG9w0B\n" +99"BwagggPNMIIDyQIBADCCA8IGCSqGSIb3DQEHATApBgoqhkiG9w0BDAEGMBsEFJVD\n" +100"mSE6jHuKMglKP2/O43UfmAjUAgMAw1CAggOInN3Hutt24/8YoVksN2hrcqtITqk3\n" +101"mfMJkYg2GtKUoNwjpGC/RB0uyOkkyikupPlv3WmDqQr0Tzrqad3laBwGuN7OWxYh\n" +102"yvuKCyazNT/3rDVVG/pEuvZuyLvwAARhuCnIk1cJMsLiY+4sqz/j0GnIxbhOzN/k\n" +103"ST8lkIekNvE7H6yHZzZ+8TxMSJ3PwCc+oyhY88aHVssOu9oAmSHznJO2prA/vl1A\n" +104"JQ6oODNbslCF35IsajJ2CrJAXKHut0OiBbgioKmlGwyIsFR1GnsEEyV2CcCj1ui1\n" +105"gd7dI/QxJJ5PpEyw/BQi+rmvAmVGTOuBJuJUlHd0JBvZ78fjbMZU7SxWSKB2YVUW\n" +106"1Glxw+F1HVB6kMk/Ucqnzrwns2IuNUdrxFIMo7rpEpq5ySZkeHqvpwwHE2S2XEOg\n" +107"8yM5PYEq6b0/0rrmXL7eoYN0Atk0cUK9lAo19cfrD9GGc7D+lHAJzFY225UP9MfR\n" +108"pT9NAClIbAB7mQnEta3o+MaES9EC2S+8UtcWRlW42vXX80syL08aoZYXFlwJ+9wP\n" +109"oQ7jEC97jH3tEkAhpMcwvDf3C/ftRnX5iOMCdbhxOL8BUMfBPlj667TidJHTb/Lr\n" +110"n/fyxWq/7qPrUdX8/gYCcufexDv0a8HQ8a99HAw+GzQU57jwbrmA2UHVFp/N488Q\n" +111"3T3Ulw2AtrEHgUWPRMokcFAfO1U8/QObOheLGTIQ3VOjwrcxENLYJif4syyrYkOP\n" +112"m/5d/d5TpXtI5GBGOzXjUSbz3KmoYM3MlLHGNUciZufif2lhWVwzgE+P1XLqmo1Z\n" +113"sY3b7CGiRKOwFMvsYfFisen6xiIJdpurE2SypLA1UBmc9QoDGp5mxFG550pRCLGI\n" +114"Zpsrvg16VDqU+WXbzIIu2LaJNWrM3jHnFde1cn2MJEdXchbq5FiajoZ27COUcdp9\n" +115"sxvssAx7Ov9lfYqacWm+bZFOX2NdYUjz3VGk2YehCN7KnegV0a9f9L3eiY8hdfE6\n" +116"4uDw4vIML5wDED6sIPdmywWbWm1PxRHiusWuL8PbApJ5r8cfCAfCqhYJos5TL9VD\n" +117"IaI7jhWPHkiarlMzrpb8XwaY5/0lzYqUNj1/gZUQA2S4PLaQTBZZ8o3HQy91SvJr\n" +118"kVug/6q06Xzyrxm467Q/8xIeIXym26DMp03xHatFSTvpJDxfl14cnbr2vNbPSlEy\n" +119"fp6NbaSzKadTU3yqva1TrEdPlDA+MCEwCQYFKw4DAhoFAAQUtSDOH+RGJI6TAjl1\n" +120"R2HMhteRVSMEFKmTNz/98xQ6XxJiJF5P+7rli4x5AgMBhqA=";121122static final Lock lock = new ReentrantLock();123static final Condition serverReady = lock.newCondition();124125public static void main(String[] args) throws Exception {126Thread serverThread = new Thread(() -> {127try {128doServerSide();129}130catch (Exception exc) {131log("Caught exception: %s", exc);132}133}134);135serverThread.start();136137try {138doClientSide((args == null || args.length < 1) ? null : args[0]);139throw new RuntimeException("Expected SSLException did not occur!");140} catch (SSLException ssle) {141log("Caught expected exception on client: " + ssle);142} finally {143serverThread.join();144}145146}147148static void doServerSide() throws Exception {149Thread.currentThread().setName("ServerThread");150SSLContext sslc = SSLContext.getInstance("TLS");151log("doServerSide start");152KeyManagerFactory kmf = createKeyManagerFactory(KEYSTORE_PEM,153KEYSTORE_PASS);154sslc.init(kmf.getKeyManagers(), null, null);155SSLServerSocketFactory ssf =156(SSLServerSocketFactory)sslc.getServerSocketFactory();157158try (SSLServerSocket sslServerSocket =159(SSLServerSocket)ssf.createServerSocket(0)) {160sslServerSocket.setReuseAddress(true);161// Set the server port and wake up the client thread who is waiting162// for the port to be set.163lock.lock();164try {165serverPort = sslServerSocket.getLocalPort();166log("Server listening on port %d", serverPort);167serverReady.signalAll();168log("Server ready");169} finally {170lock.unlock();171}172173// Go into the accept wait state until the client initiates the174// TLS handshake.175try (SSLSocket sslSocket = (SSLSocket)sslServerSocket.accept();176PrintWriter pw =177new PrintWriter(sslSocket.getOutputStream());178BufferedReader br = new BufferedReader(179new InputStreamReader(sslSocket.getInputStream()))) {180log("Incoming connection from %s",181sslSocket.getRemoteSocketAddress());182String data = br.readLine();183log("Got mesage from client: ", data);184pw.write("I am server\n");185pw.close();186}187}188}189190private static KeyManagerFactory createKeyManagerFactory(191String ksPem, String ksAuth) throws IOException,192GeneralSecurityException {193KeyManagerFactory kmf = null;194if (ksPem != null && ksAuth != null) {195Base64.Decoder b64dec = Base64.getMimeDecoder();196ByteArrayInputStream bais =197new ByteArrayInputStream(b64dec.decode(ksPem));198KeyStore ks = KeyStore.getInstance("PKCS12");199char[] ksPass = ksAuth.toCharArray();200ks.load(bais, ksPass);201202kmf = KeyManagerFactory.getInstance("PKIX");203kmf.init(ks, ksAuth.toCharArray());204}205206return kmf;207}208209static void doClientSide(String proto) throws Exception {210Thread.currentThread().setName("ClientThread");211log("doClientSide start");212213// Wait for the server to be ready and wake up this thread214// so the client knows which port to communicate with215lock.lock();216try {217serverReady.await();218log("Client ready to contact port %d", serverPort);219} finally {220lock.unlock();221}222223SSLSocketFactory sslsf =224(SSLSocketFactory)SSLSocketFactory.getDefault();225try (SSLSocket sslSocket = (SSLSocket)sslsf.createSocket(226InetAddress.getLocalHost(), serverPort);227BufferedReader br = new BufferedReader(228new InputStreamReader(sslSocket.getInputStream()));229PrintWriter pw = new PrintWriter(sslSocket.getOutputStream())) {230231if (proto != null) {232sslSocket.setEnabledProtocols(new String[] { proto });233}234pw.write("I am client\n");235pw.flush();236237String response = br.readLine();238System.out.println("response is: " + response);239}240}241242private static void log(String msgFmt, Object ... args) {243StringBuilder sb = new StringBuilder();244sb.append(String.format("%d | %s | ",245System.currentTimeMillis(), Thread.currentThread().getName()));246sb.append(String.format(msgFmt, args));247System.out.println(sb.toString());248}249}250251252