This is an automated email from the ASF dual-hosted git repository. coheigea pushed a commit to branch 3.3.x-fixes in repository https://gitbox.apache.org/repos/asf/cxf.git
commit 8c5d3db8ec16b35e43b578c405218678d2e2f562 Author: Colm O hEigeartaigh <[email protected]> AuthorDate: Tue Mar 31 15:52:11 2020 +0100 CXF-8253 - Provide a way to disable TLS trust verification for the OSGi HttpConduitConfigApplier (cherry picked from commit 3157955899bc49e2e0dad145e9e6c52fb82e1d8c) --- .../http/osgi/HttpConduitConfigApplier.java | 10 +- .../cxf/transport/https/InsecureTrustManager.java | 68 +++++++++++++ .../http/osgi/HttpConduitConfigApplierTest.java | 105 +++++++++++++++++++++ .../https/ciphersuites/CipherSuitesTest.java | 39 +------- .../systest/https/clientauth/ClientAuthTest.java | 28 +----- .../cxf/systest/https/trust/TrustManagerTest.java | 31 +----- .../https/trust/client-trust-manager-ref.xml | 2 +- 7 files changed, 193 insertions(+), 90 deletions(-) diff --git a/rt/transports/http/src/main/java/org/apache/cxf/transport/http/osgi/HttpConduitConfigApplier.java b/rt/transports/http/src/main/java/org/apache/cxf/transport/http/osgi/HttpConduitConfigApplier.java index e0fcfe6..ddfa195 100644 --- a/rt/transports/http/src/main/java/org/apache/cxf/transport/http/osgi/HttpConduitConfigApplier.java +++ b/rt/transports/http/src/main/java/org/apache/cxf/transport/http/osgi/HttpConduitConfigApplier.java @@ -38,6 +38,7 @@ import org.apache.cxf.configuration.security.SecureRandomParameters; import org.apache.cxf.configuration.security.TrustManagersType; import org.apache.cxf.transport.http.HTTPConduit; import org.apache.cxf.transport.http.auth.HttpAuthSupplier; +import org.apache.cxf.transport.https.InsecureTrustManager; import org.apache.cxf.transports.http.configuration.ConnectionType; import org.apache.cxf.transports.http.configuration.HTTPClientPolicy; import org.apache.cxf.transports.http.configuration.ProxyServerType; @@ -68,6 +69,8 @@ class HttpConduitConfigApplier { KeyManagersType kmt = null; TrustManagersType tmt = null; boolean enableRevocation = false; + boolean disableTrustVerification = false; + while (keys.hasMoreElements()) { String k = keys.nextElement(); if (k.startsWith("tlsClientParameters.")) { @@ -121,6 +124,9 @@ class HttpConduitConfigApplier { while (st.hasMoreTokens()) { p.getCipherSuites().add(st.nextToken()); } + } else if ("trustManagers.disableTrustVerification".equals(k) + && Boolean.parseBoolean(v)) { + disableTrustVerification = true; } else if (k.startsWith("trustManagers.")) { tmt = getTrustManagers(tmt, k.substring("trustManagers.".length()), @@ -140,7 +146,9 @@ class HttpConduitConfigApplier { if (kmt != null) { p.setKeyManagers(TLSParameterJaxBUtils.getKeyManagers(kmt)); } - if (tmt != null) { + if (disableTrustVerification) { + p.setTrustManagers(InsecureTrustManager.getNoOpX509TrustManagers()); + } else if (tmt != null) { p.setTrustManagers(TLSParameterJaxBUtils.getTrustManagers(tmt, enableRevocation)); } } catch (RuntimeException e) { diff --git a/rt/transports/http/src/main/java/org/apache/cxf/transport/https/InsecureTrustManager.java b/rt/transports/http/src/main/java/org/apache/cxf/transport/https/InsecureTrustManager.java new file mode 100644 index 0000000..e09755c --- /dev/null +++ b/rt/transports/http/src/main/java/org/apache/cxf/transport/https/InsecureTrustManager.java @@ -0,0 +1,68 @@ +/** + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ + +package org.apache.cxf.transport.https; + +import java.security.cert.CertificateException; +import java.security.cert.X509Certificate; +import java.util.logging.Logger; + +import javax.net.ssl.TrustManager; +import javax.net.ssl.X509TrustManager; + +import org.apache.cxf.common.logging.LogUtils; + +/** + * This class provides a static method to create an array of TrustManagers, which disables TLS + * trust verification. This is insecure and must not be used in production, only for testing! + */ +public final class InsecureTrustManager { + + private static final Logger LOG = LogUtils.getL7dLogger(InsecureTrustManager.class); + + private InsecureTrustManager() { + // complete + } + + public static TrustManager[] getNoOpX509TrustManagers() { + LOG.warning("This class essentially disables TLS trust verification and is insecure!"); + return new TrustManager[] {new NoOpX509TrustManager()}; + } + + private static final class NoOpX509TrustManager implements X509TrustManager { + + private NoOpX509TrustManager() { + + } + + @Override + public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException { + } + + @Override + public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException { + } + + @Override + public X509Certificate[] getAcceptedIssuers() { + return null; + } + + } +} diff --git a/rt/transports/http/src/test/java/org/apache/cxf/transport/http/osgi/HttpConduitConfigApplierTest.java b/rt/transports/http/src/test/java/org/apache/cxf/transport/http/osgi/HttpConduitConfigApplierTest.java new file mode 100644 index 0000000..53b1917 --- /dev/null +++ b/rt/transports/http/src/test/java/org/apache/cxf/transport/http/osgi/HttpConduitConfigApplierTest.java @@ -0,0 +1,105 @@ +/** + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ + +package org.apache.cxf.transport.http.osgi; + +import java.io.IOException; +import java.util.Dictionary; +import java.util.Hashtable; + +import org.apache.cxf.Bus; +import org.apache.cxf.bus.extension.ExtensionManagerBus; +import org.apache.cxf.service.model.EndpointInfo; +import org.apache.cxf.transport.http.HTTPConduit; +import org.apache.cxf.transport.http.URLConnectionHTTPConduit; +import org.apache.cxf.transport.https.InsecureTrustManager; + +import org.junit.Test; + +import static org.junit.Assert.assertEquals; +import static org.junit.Assert.assertFalse; +import static org.junit.Assert.assertNotNull; +import static org.junit.Assert.assertNull; +import static org.junit.Assert.assertTrue; + +public class HttpConduitConfigApplierTest { + + @Test + public void testNormalTrustLoading() throws IOException { + HttpConduitConfigApplier configApplier = new HttpConduitConfigApplier(); + + Dictionary<String, String> configValues = new Hashtable<>(); + configValues.put("tlsClientParameters.disableCNCheck", "false"); + String address = "https://localhost:12345"; + Bus bus = new ExtensionManagerBus(); + EndpointInfo ei = new EndpointInfo(); + ei.setAddress(address); + HTTPConduit conduit = new URLConnectionHTTPConduit(bus, ei, null); + + configApplier.apply(configValues, conduit, address); + + assertNull(conduit.getTlsClientParameters().getTrustManagers()); + assertFalse(conduit.getTlsClientParameters().isDisableCNCheck()); + } + + @Test + public void testDisableTrustVerification() throws IOException { + HttpConduitConfigApplier configApplier = new HttpConduitConfigApplier(); + + Dictionary<String, String> configValues = new Hashtable<>(); + configValues.put("tlsClientParameters.disableCNCheck", "true"); + configValues.put("tlsClientParameters.trustManagers.disableTrustVerification", "true"); + String address = "https://localhost:12345"; + Bus bus = new ExtensionManagerBus(); + EndpointInfo ei = new EndpointInfo(); + ei.setAddress(address); + HTTPConduit conduit = new URLConnectionHTTPConduit(bus, ei, null); + + configApplier.apply(configValues, conduit, address); + + assertNotNull(conduit.getTlsClientParameters().getTrustManagers()); + assertEquals(conduit.getTlsClientParameters().getTrustManagers().length, 1); + assertTrue(conduit.getTlsClientParameters().getTrustManagers()[0].getClass() + .getName().startsWith(InsecureTrustManager.class.getName())); + assertTrue(conduit.getTlsClientParameters().isDisableCNCheck()); + } + + @Test + public void testTrustVerificationEnabled() throws IOException { + HttpConduitConfigApplier configApplier = new HttpConduitConfigApplier(); + + Dictionary<String, String> configValues = new Hashtable<>(); + configValues.put("tlsClientParameters.disableCNCheck", "true"); + configValues.put("tlsClientParameters.trustManagers.disableTrustVerification", "false"); + String address = "https://localhost:12345"; + Bus bus = new ExtensionManagerBus(); + EndpointInfo ei = new EndpointInfo(); + ei.setAddress(address); + HTTPConduit conduit = new URLConnectionHTTPConduit(bus, ei, null); + + configApplier.apply(configValues, conduit, address); + + assertNotNull(conduit.getTlsClientParameters().getTrustManagers()); + assertEquals(conduit.getTlsClientParameters().getTrustManagers().length, 1); + assertFalse(conduit.getTlsClientParameters().getTrustManagers()[0].getClass() + .getName().startsWith(InsecureTrustManager.class.getName())); + assertTrue(conduit.getTlsClientParameters().isDisableCNCheck()); + } + +} \ No newline at end of file diff --git a/systests/transports/src/test/java/org/apache/cxf/systest/https/ciphersuites/CipherSuitesTest.java b/systests/transports/src/test/java/org/apache/cxf/systest/https/ciphersuites/CipherSuitesTest.java index 3370c20..c81f98c 100644 --- a/systests/transports/src/test/java/org/apache/cxf/systest/https/ciphersuites/CipherSuitesTest.java +++ b/systests/transports/src/test/java/org/apache/cxf/systest/https/ciphersuites/CipherSuitesTest.java @@ -20,8 +20,6 @@ package org.apache.cxf.systest.https.ciphersuites; import java.net.URL; -import java.security.cert.CertificateException; -import java.security.cert.X509Certificate; import java.util.Arrays; import java.util.Collection; import java.util.Collections; @@ -30,7 +28,6 @@ import javax.crypto.Cipher; import javax.crypto.SecretKey; import javax.crypto.spec.SecretKeySpec; import javax.net.ssl.TrustManager; -import javax.net.ssl.X509TrustManager; import javax.xml.ws.BindingProvider; import org.apache.cxf.Bus; @@ -42,6 +39,7 @@ import org.apache.cxf.frontend.ClientProxy; import org.apache.cxf.helpers.JavaUtils; import org.apache.cxf.testutil.common.AbstractBusClientServerTestBase; import org.apache.cxf.transport.http.HTTPConduit; +import org.apache.cxf.transport.https.InsecureTrustManager; import org.apache.hello_world.Greeter; import org.apache.hello_world.services.SOAPService; @@ -346,9 +344,7 @@ public class CipherSuitesTest extends AbstractBusClientServerTestBase { HTTPConduit conduit = (HTTPConduit) client.getConduit(); TLSClientParameters tlsParams = new TLSClientParameters(); - X509TrustManager trustManager = new NoOpX509TrustManager(); - TrustManager[] trustManagers = new TrustManager[1]; - trustManagers[0] = trustManager; + TrustManager[] trustManagers = InsecureTrustManager.getNoOpX509TrustManagers(); tlsParams.setTrustManagers(trustManagers); tlsParams.setDisableCNCheck(true); @@ -431,9 +427,7 @@ public class CipherSuitesTest extends AbstractBusClientServerTestBase { HTTPConduit conduit = (HTTPConduit) client.getConduit(); TLSClientParameters tlsParams = new TLSClientParameters(); - X509TrustManager trustManager = new NoOpX509TrustManager(); - TrustManager[] trustManagers = new TrustManager[1]; - trustManagers[0] = trustManager; + TrustManager[] trustManagers = InsecureTrustManager.getNoOpX509TrustManagers(); tlsParams.setTrustManagers(trustManagers); tlsParams.setDisableCNCheck(true); @@ -480,9 +474,7 @@ public class CipherSuitesTest extends AbstractBusClientServerTestBase { HTTPConduit conduit = (HTTPConduit) client.getConduit(); TLSClientParameters tlsParams = new TLSClientParameters(); - X509TrustManager trustManager = new NoOpX509TrustManager(); - TrustManager[] trustManagers = new TrustManager[1]; - trustManagers[0] = trustManager; + TrustManager[] trustManagers = InsecureTrustManager.getNoOpX509TrustManagers(); tlsParams.setTrustManagers(trustManagers); tlsParams.setDisableCNCheck(true); @@ -523,9 +515,7 @@ public class CipherSuitesTest extends AbstractBusClientServerTestBase { HTTPConduit conduit = (HTTPConduit) client.getConduit(); TLSClientParameters tlsParams = new TLSClientParameters(); - X509TrustManager trustManager = new NoOpX509TrustManager(); - TrustManager[] trustManagers = new TrustManager[1]; - trustManagers[0] = trustManager; + TrustManager[] trustManagers = InsecureTrustManager.getNoOpX509TrustManagers(); tlsParams.setTrustManagers(trustManagers); tlsParams.setDisableCNCheck(true); @@ -574,23 +564,4 @@ public class CipherSuitesTest extends AbstractBusClientServerTestBase { bus.shutdown(true); } - private static class NoOpX509TrustManager implements X509TrustManager { - - NoOpX509TrustManager() { - } - - @Override - public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException { - } - - @Override - public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException { - } - - @Override - public X509Certificate[] getAcceptedIssuers() { - return null; - } - - } } diff --git a/systests/transports/src/test/java/org/apache/cxf/systest/https/clientauth/ClientAuthTest.java b/systests/transports/src/test/java/org/apache/cxf/systest/https/clientauth/ClientAuthTest.java index 695f35b..2fa82a5 100644 --- a/systests/transports/src/test/java/org/apache/cxf/systest/https/clientauth/ClientAuthTest.java +++ b/systests/transports/src/test/java/org/apache/cxf/systest/https/clientauth/ClientAuthTest.java @@ -23,8 +23,6 @@ import java.io.InputStream; import java.net.URL; import java.security.KeyStore; import java.security.Security; -import java.security.cert.CertificateException; -import java.security.cert.X509Certificate; import java.util.Arrays; import java.util.Collection; @@ -36,7 +34,6 @@ import javax.net.ssl.SSLContext; import javax.net.ssl.SSLSession; import javax.net.ssl.TrustManager; import javax.net.ssl.TrustManagerFactory; -import javax.net.ssl.X509TrustManager; import javax.xml.ws.BindingProvider; import org.apache.cxf.Bus; @@ -49,6 +46,7 @@ import org.apache.cxf.frontend.ClientProxy; import org.apache.cxf.helpers.JavaUtils; import org.apache.cxf.testutil.common.AbstractBusClientServerTestBase; import org.apache.cxf.transport.http.HTTPConduit; +import org.apache.cxf.transport.https.InsecureTrustManager; import org.apache.hello_world.Greeter; import org.apache.hello_world.services.SOAPService; import org.bouncycastle.jce.provider.BouncyCastleProvider; @@ -414,9 +412,7 @@ public class ClientAuthTest extends AbstractBusClientServerTestBase { assertNotNull("Service is null", service); // Set up (shared) KeyManagers/TrustManagers - X509TrustManager trustManager = new NoOpX509TrustManager(); - TrustManager[] trustManagers = new TrustManager[1]; - trustManagers[0] = trustManager; + TrustManager[] trustManagers = InsecureTrustManager.getNoOpX509TrustManagers(); KeyManagerFactory kmf = KeyManagerFactory.getInstance(KeyManagerFactory.getDefaultAlgorithm()); @@ -490,9 +486,7 @@ public class ClientAuthTest extends AbstractBusClientServerTestBase { assertNotNull("Service is null", service); // Set up (shared) KeyManagers/TrustManagers - X509TrustManager trustManager = new NoOpX509TrustManager(); - TrustManager[] trustManagers = new TrustManager[1]; - trustManagers[0] = trustManager; + TrustManager[] trustManagers = InsecureTrustManager.getNoOpX509TrustManagers(); KeyManagerFactory kmf = KeyManagerFactory.getInstance(KeyManagerFactory.getDefaultAlgorithm()); @@ -650,20 +644,4 @@ public class ClientAuthTest extends AbstractBusClientServerTestBase { }; - private static class NoOpX509TrustManager implements X509TrustManager { - - @Override - public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException { - } - - @Override - public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException { - } - - @Override - public X509Certificate[] getAcceptedIssuers() { - return null; - } - - } } diff --git a/systests/transports/src/test/java/org/apache/cxf/systest/https/trust/TrustManagerTest.java b/systests/transports/src/test/java/org/apache/cxf/systest/https/trust/TrustManagerTest.java index 90030a0..bde5322 100644 --- a/systests/transports/src/test/java/org/apache/cxf/systest/https/trust/TrustManagerTest.java +++ b/systests/transports/src/test/java/org/apache/cxf/systest/https/trust/TrustManagerTest.java @@ -45,6 +45,7 @@ import org.apache.cxf.endpoint.Client; import org.apache.cxf.frontend.ClientProxy; import org.apache.cxf.testutil.common.AbstractBusClientServerTestBase; import org.apache.cxf.transport.http.HTTPConduit; +import org.apache.cxf.transport.https.InsecureTrustManager; import org.apache.hello_world.Greeter; import org.apache.hello_world.services.SOAPService; @@ -124,10 +125,7 @@ public class TrustManagerTest extends AbstractBusClientServerTestBase { } TLSClientParameters tlsParams = new TLSClientParameters(); - X509TrustManager trustManager = new NoOpX509TrustManager(); - TrustManager[] trustManagers = new TrustManager[1]; - trustManagers[0] = trustManager; - tlsParams.setTrustManagers(trustManagers); + tlsParams.setTrustManagers(InsecureTrustManager.getNoOpX509TrustManagers()); tlsParams.setDisableCNCheck(true); Client client = ClientProxy.getClient(port); @@ -441,31 +439,6 @@ public class TrustManagerTest extends AbstractBusClientServerTestBase { bus.shutdown(true); } - public static TrustManager[] getNoOpX509TrustManagers() { - return new TrustManager[] {new NoOpX509TrustManager()}; - } - - public static class NoOpX509TrustManager implements X509TrustManager { - - public NoOpX509TrustManager() { - - } - - @Override - public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException { - } - - @Override - public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException { - } - - @Override - public X509Certificate[] getAcceptedIssuers() { - return null; - } - - } - public static class ServerCertX509TrustManager implements X509TrustManager { private String requiredServerPrincipalName; diff --git a/systests/transports/src/test/resources/org/apache/cxf/systest/https/trust/client-trust-manager-ref.xml b/systests/transports/src/test/resources/org/apache/cxf/systest/https/trust/client-trust-manager-ref.xml index b1dfa47..47803c1 100644 --- a/systests/transports/src/test/resources/org/apache/cxf/systest/https/trust/client-trust-manager-ref.xml +++ b/systests/transports/src/test/resources/org/apache/cxf/systest/https/trust/client-trust-manager-ref.xml @@ -31,7 +31,7 @@ </cxf:features> </cxf:bus> - <bean id="trustManagers" class="org.apache.cxf.systest.https.trust.TrustManagerTest" factory-method="getNoOpX509TrustManagers"/> + <bean id="trustManagers" class="org.apache.cxf.transport.https.InsecureTrustManager" factory-method="getNoOpX509TrustManagers"/> <http:conduit name="https://localhost:.*"> <http:tlsClientParameters disableCNCheck="true">
