fix "CertificateManager requested as a service"

This commit is contained in:
Vladimir Krivosheev
2015-07-21 15:23:20 +02:00
parent 44571874ec
commit 4fbf9a121b
3 changed files with 54 additions and 29 deletions
@@ -1,10 +1,28 @@
/*
* Copyright 2000-2015 JetBrains s.r.o.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package com.intellij.util.net.ssl;
import com.intellij.openapi.application.Application;
import com.intellij.openapi.application.ApplicationManager;
import com.intellij.openapi.application.ModalityState;
import com.intellij.openapi.application.PathManager;
import com.intellij.openapi.components.*;
import com.intellij.openapi.components.PersistentStateComponent;
import com.intellij.openapi.components.State;
import com.intellij.openapi.components.Storage;
import com.intellij.openapi.components.StoragePathMacros;
import com.intellij.openapi.diagnostic.Logger;
import com.intellij.openapi.ui.DialogWrapper;
import com.intellij.openapi.util.io.FileUtil;
@@ -14,6 +32,7 @@ import com.intellij.util.xmlb.XmlSerializerUtil;
import com.intellij.util.xmlb.annotations.AbstractCollection;
import com.intellij.util.xmlb.annotations.Property;
import com.intellij.util.xmlb.annotations.Tag;
import org.apache.http.conn.ssl.SSLConnectionSocketFactory;
import org.jetbrains.annotations.NonNls;
import org.jetbrains.annotations.NotNull;
import org.jetbrains.annotations.Nullable;
@@ -34,8 +53,6 @@ import java.util.concurrent.TimeUnit;
import java.util.concurrent.atomic.AtomicBoolean;
import java.util.concurrent.atomic.AtomicReference;
import static org.apache.http.conn.ssl.SSLConnectionSocketFactory.BROWSER_COMPATIBLE_HOSTNAME_VERIFIER;
/**
* {@code CertificateManager} is responsible for negotiation SSL connection with server
* and deals with untrusted/self-singed/expired and other kinds of digital certificates.
@@ -66,7 +83,7 @@ import static org.apache.http.conn.ssl.SSLConnectionSocketFactory.BROWSER_COMPAT
name = "CertificateManager",
storages = @Storage(file = StoragePathMacros.APP_CONFIG + "/other.xml")
)
public class CertificateManager implements ApplicationComponent, PersistentStateComponent<CertificateManager.Config> {
public class CertificateManager implements PersistentStateComponent<CertificateManager.Config> {
@NonNls public static final String COMPONENT_NAME = "Certificate Manager";
@NonNls private static final String DEFAULT_PATH = FileUtil.join(PathManager.getSystemPath(), "tasks", "cacerts");
@@ -78,7 +95,7 @@ public class CertificateManager implements ApplicationComponent, PersistentState
* Special version of hostname verifier, that asks user whether he accepts certificate, which subject's common name
* doesn't match requested hostname.
*/
public static final HostnameVerifier HOSTNAME_VERIFIER = new ConfirmingHostnameVerifier(BROWSER_COMPATIBLE_HOSTNAME_VERIFIER);
public static final HostnameVerifier HOSTNAME_VERIFIER = new ConfirmingHostnameVerifier(SSLConnectionSocketFactory.BROWSER_COMPATIBLE_HOSTNAME_VERIFIER);
/**
* Used to check whether dialog is visible to prevent possible deadlock, e.g. when some external resource is loaded by
* {@link java.awt.MediaTracker}.
@@ -86,7 +103,7 @@ public class CertificateManager implements ApplicationComponent, PersistentState
static final long DIALOG_VISIBILITY_TIMEOUT = 5000; // ms
public static CertificateManager getInstance() {
return (CertificateManager)ApplicationManager.getApplication().getComponent(COMPONENT_NAME);
return ApplicationManager.getApplication().getComponent(CertificateManager.class);
}
private final String myCacertsPath;
@@ -108,10 +125,7 @@ public class CertificateManager implements ApplicationComponent, PersistentState
myPassword = DEFAULT_PASSWORD;
myConfig = new Config();
myTrustManager = ConfirmingTrustManager.createForStorage(myCacertsPath, myPassword);
}
@Override
public void initComponent() {
try {
// Don't do this: protocol created this way will ignore SSL tunnels. See IDEA-115708.
// Protocol.registerProtocol("https", CertificateManager.createDefault().createProtocol());
@@ -125,17 +139,6 @@ public class CertificateManager implements ApplicationComponent, PersistentState
}
}
@Override
public void disposeComponent() {
// empty
}
@NotNull
@Override
public String getComponentName() {
return COMPONENT_NAME;
}
/**
* Creates special kind of {@code SSLContext}, which X509TrustManager first checks certificate presence in
* in default system-wide trust store (usually located at {@code ${JAVA_HOME}/lib/security/cacerts} or specified by
@@ -1,3 +1,18 @@
/*
* Copyright 2000-2015 JetBrains s.r.o.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package com.intellij.util.net.ssl;
import com.intellij.openapi.application.Application;
@@ -127,8 +142,7 @@ public class ConfirmingTrustManager extends ClientOnlyTrustManager {
LOG.debug("Image Fetcher thread is detected. Certificate check will be skipped.");
return true;
}
CertificateManager.Config config = CertificateManager.getInstance().getState();
if (app.isUnitTestMode() || app.isHeadlessEnvironment() || config.ACCEPT_AUTOMATICALLY) {
if (app.isUnitTestMode() || app.isHeadlessEnvironment() || CertificateManager.getInstance().getState().ACCEPT_AUTOMATICALLY) {
LOG.debug("Certificate will be accepted automatically");
if (addToKeyStore) {
myCustomManager.addCertificate(endPoint);
@@ -1,10 +1,23 @@
/*
* Copyright 2000-2015 JetBrains s.r.o.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package com.intellij.tasks.impl;
import com.intellij.openapi.components.ServiceManager;
import com.intellij.tasks.TaskRepositoryType;
import com.intellij.tasks.config.TaskSettings;
import com.intellij.util.net.HttpConfigurable;
import com.intellij.util.net.ssl.CertificateManager;
import org.apache.commons.httpclient.*;
import org.apache.commons.httpclient.auth.AuthScope;
import org.jetbrains.annotations.NotNull;
@@ -51,11 +64,6 @@ public abstract class BaseRepositoryImpl extends BaseRepository {
private HttpClient createClient() {
HttpClient client = new HttpClient(new MultiThreadedHttpConnectionManager());
configureHttpClient(client);
// After CertificateManager became application service it no longer "automagically" preliminarily
// initializes default SSL context as required for trackers written in httpclient 3.x.
// Clients that use httpclient 4.x (see NewBaseRepositoryImpl.getHttpClient) install SSL context explicitly though.
// This workaround allows to install context properly as soon as HTTP client is needed.
ServiceManager.getService(CertificateManager.class);
return client;
}