From cf5427d3d730bfe18ba0a3a62ce31c7dcacfb15d Mon Sep 17 00:00:00 2001 From: "Alexander.Kass" Date: Fri, 28 Apr 2023 09:37:10 +0300 Subject: [PATCH] DBE-7947 allow passing jks in ca/key fields GitOrigin-RevId: 81d88a6d20454194c70e186372f9e6dc93c6a23e --- .../execution/rmi/ssl/DelegateKeyStore.java | 21 ++++++++--- .../execution/rmi/ssl/SslKeyStore.java | 35 +++++++++++++++---- .../execution/rmi/ssl/SslTrustStore.java | 8 ++--- 3 files changed, 47 insertions(+), 17 deletions(-) diff --git a/platform/util-rt/src/com/intellij/execution/rmi/ssl/DelegateKeyStore.java b/platform/util-rt/src/com/intellij/execution/rmi/ssl/DelegateKeyStore.java index 7aae1a8b3f5a..ede13fe1843e 100644 --- a/platform/util-rt/src/com/intellij/execution/rmi/ssl/DelegateKeyStore.java +++ b/platform/util-rt/src/com/intellij/execution/rmi/ssl/DelegateKeyStore.java @@ -1,10 +1,10 @@ // Copyright 2000-2019 JetBrains s.r.o. Use of this source code is governed by the Apache 2.0 license that can be found in the LICENSE file. package com.intellij.execution.rmi.ssl; -import java.io.File; -import java.io.IOException; -import java.io.InputStream; -import java.io.OutputStream; +import org.jetbrains.annotations.NotNull; +import org.jetbrains.annotations.Nullable; + +import java.io.*; import java.security.*; import java.security.cert.Certificate; import java.security.cert.CertificateException; @@ -181,4 +181,17 @@ public class DelegateKeyStore extends KeyStoreSpi { public void engineLoad(InputStream stream, char[] password) throws IOException, NoSuchAlgorithmException, CertificateException { delegate.load(stream, password); } + + + @Nullable + protected static KeyStore loadKeyStore(@NotNull String path, char[] password) + throws KeyStoreException, IOException, NoSuchAlgorithmException, CertificateException { + File file = new File(path); + if (!file.exists()) return null; + KeyStore tmpStore = KeyStore.getInstance(KeyStore.getDefaultType()); + try (InputStream stream = new FileInputStream(file)) { + tmpStore.load(stream, password); + } + return tmpStore; + } } diff --git a/platform/util-rt/src/com/intellij/execution/rmi/ssl/SslKeyStore.java b/platform/util-rt/src/com/intellij/execution/rmi/ssl/SslKeyStore.java index 094651f876b0..4b5b72fb92a7 100644 --- a/platform/util-rt/src/com/intellij/execution/rmi/ssl/SslKeyStore.java +++ b/platform/util-rt/src/com/intellij/execution/rmi/ssl/SslKeyStore.java @@ -1,19 +1,20 @@ // Copyright 2000-2021 JetBrains s.r.o. Use of this source code is governed by the Apache 2.0 license that can be found in the LICENSE file. package com.intellij.execution.rmi.ssl; +import com.intellij.openapi.util.Pair; import org.jetbrains.annotations.NotNull; import org.jetbrains.annotations.Nullable; +import java.io.File; +import java.io.FileInputStream; import java.io.IOException; import java.io.InputStream; -import java.security.KeyStore; -import java.security.KeyStoreException; -import java.security.NoSuchAlgorithmException; -import java.security.PrivateKey; +import java.security.*; import java.security.cert.Certificate; import java.security.cert.CertificateException; import java.security.cert.X509Certificate; import java.util.ArrayList; +import java.util.Enumeration; import java.util.List; public final class SslKeyStore extends DelegateKeyStore { @@ -38,7 +39,7 @@ public final class SslKeyStore extends DelegateKeyStore { } @Nullable - public static PrivateKey getUserKey() { + public static Key getUserKey() { return ourAdded.isEmpty() ? null : ourAdded.get(0).key; } @@ -79,12 +80,32 @@ public final class SslKeyStore extends DelegateKeyStore { super.engineLoad(null, null); } + public static int appendUserKeyStore(@NotNull String path, char[] password) { + try { + KeyStore tmpStore = loadKeyStore(path, password); + if (tmpStore == null) return 0; + int cnt = 0; + for (Enumeration aliases = tmpStore.aliases(); aliases.hasMoreElements(); ) { + String alias = aliases.nextElement(); + Key key = tmpStore.getKey(alias, null); + if (key == null) continue; + Certificate[] certChain = tmpStore.getCertificateChain(alias); + ourAdded.add(new KeyEntry(alias, key, certChain)); + ++cnt; + } + return cnt; + } + catch (Exception e) { + throw new IllegalStateException(e); + } + } + private static class KeyEntry { private final String alias; - private final PrivateKey key; + private final Key key; private final Certificate[] certChain; - private KeyEntry(@NotNull String alias, @NotNull PrivateKey key, @Nullable Certificate[] certChain) { + private KeyEntry(@NotNull String alias, @NotNull Key key, @Nullable Certificate[] certChain) { this.alias = alias; this.key = key; this.certChain = certChain; diff --git a/platform/util-rt/src/com/intellij/execution/rmi/ssl/SslTrustStore.java b/platform/util-rt/src/com/intellij/execution/rmi/ssl/SslTrustStore.java index 9ae6307e3031..fc29015b56da 100644 --- a/platform/util-rt/src/com/intellij/execution/rmi/ssl/SslTrustStore.java +++ b/platform/util-rt/src/com/intellij/execution/rmi/ssl/SslTrustStore.java @@ -90,12 +90,8 @@ public final class SslTrustStore extends DelegateKeyStore { public static int appendUserTrustStore(@NotNull String path, char[] password) { try { - File file = new File(path); - if (!file.exists()) return 0; - KeyStore tmpStore = KeyStore.getInstance(KeyStore.getDefaultType()); - try (InputStream stream = new FileInputStream(file)) { - tmpStore.load(stream, password); - } + KeyStore tmpStore = loadKeyStore(path, password); + if (tmpStore == null) return 0; int cnt = 0; for (Enumeration aliases = tmpStore.aliases(); aliases.hasMoreElements(); ) { String alias = aliases.nextElement();