Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
openanolis
dragonwell8_jdk
提交
9fdca611
D
dragonwell8_jdk
项目概览
openanolis
/
dragonwell8_jdk
通知
4
Star
2
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
D
dragonwell8_jdk
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
提交
Issue看板
提交
9fdca611
编写于
3月 30, 2012
作者:
W
wetmore
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
7142172: Custom TrustManagers that return null for getAcceptedIssuers will NPE
Reviewed-by: xuelei
上级
e192d69f
变更
2
隐藏空白更改
内联
并排
Showing
2 changed file
with
74 addition
and
5 deletion
+74
-5
src/share/classes/sun/security/ssl/SSLContextImpl.java
src/share/classes/sun/security/ssl/SSLContextImpl.java
+8
-5
test/sun/security/ssl/com/sun/net/ssl/internal/ssl/SSLContextImpl/NullGetAcceptedIssuers.java
...l/internal/ssl/SSLContextImpl/NullGetAcceptedIssuers.java
+66
-0
未找到文件。
src/share/classes/sun/security/ssl/SSLContextImpl.java
浏览文件 @
9fdca611
/*
/*
* Copyright (c) 1999, 201
1
, Oracle and/or its affiliates. All rights reserved.
* Copyright (c) 1999, 201
2
, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
*
* This code is free software; you can redistribute it and/or modify it
* This code is free software; you can redistribute it and/or modify it
...
@@ -774,12 +774,8 @@ final class AbstractTrustManagerWrapper extends X509ExtendedTrustManager
...
@@ -774,12 +774,8 @@ final class AbstractTrustManagerWrapper extends X509ExtendedTrustManager
// the delegated trust manager
// the delegated trust manager
private
final
X509TrustManager
tm
;
private
final
X509TrustManager
tm
;
// Cache the trusted certificate to optimize the performance.
private
final
Collection
<
X509Certificate
>
trustedCerts
=
new
HashSet
<>();
AbstractTrustManagerWrapper
(
X509TrustManager
tm
)
{
AbstractTrustManagerWrapper
(
X509TrustManager
tm
)
{
this
.
tm
=
tm
;
this
.
tm
=
tm
;
Collections
.
addAll
(
trustedCerts
,
tm
.
getAcceptedIssuers
());
}
}
@Override
@Override
...
@@ -920,6 +916,13 @@ final class AbstractTrustManagerWrapper extends X509ExtendedTrustManager
...
@@ -920,6 +916,13 @@ final class AbstractTrustManagerWrapper extends X509ExtendedTrustManager
try
{
try
{
// Does the certificate chain end with a trusted certificate?
// Does the certificate chain end with a trusted certificate?
int
checkedLength
=
chain
.
length
-
1
;
int
checkedLength
=
chain
.
length
-
1
;
Collection
<
X509Certificate
>
trustedCerts
=
new
HashSet
<>();
X509Certificate
[]
certs
=
tm
.
getAcceptedIssuers
();
if
((
certs
!=
null
)
&&
(
certs
.
length
>
0
)){
Collections
.
addAll
(
trustedCerts
,
certs
);
}
if
(
trustedCerts
.
contains
(
chain
[
checkedLength
]))
{
if
(
trustedCerts
.
contains
(
chain
[
checkedLength
]))
{
checkedLength
--;
checkedLength
--;
}
}
...
...
test/sun/security/ssl/com/sun/net/ssl/internal/ssl/SSLContextImpl/NullGetAcceptedIssuers.java
0 → 100644
浏览文件 @
9fdca611
/*
* Copyright (c) 2012, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 7142172
* @summary Custom TrustManagers that return null for getAcceptedIssuers
* will NPE.
* SunJSSE does not support dynamic system properties, no way to
* re-use system properties in samevm/agentvm mode.
* @run main/othervm NullGetAcceptedIssuers
*/
import
javax.net.ssl.*
;
public
class
NullGetAcceptedIssuers
{
public
static
void
main
(
String
[]
args
)
throws
Exception
{
SSLContext
sslContext
;
// Create a trust manager that does not validate certificate chains
TrustManager
[]
trustAllCerts
=
new
TrustManager
[]
{
new
X509TrustManager
()
{
public
void
checkClientTrusted
(
java
.
security
.
cert
.
X509Certificate
[]
certs
,
String
authType
)
{
}
public
void
checkServerTrusted
(
java
.
security
.
cert
.
X509Certificate
[]
certs
,
String
authType
)
{
}
// API says empty array, but some custom TMs are
// returning null.
public
java
.
security
.
cert
.
X509Certificate
[]
getAcceptedIssuers
()
{
return
null
;
}
}};
sslContext
=
javax
.
net
.
ssl
.
SSLContext
.
getInstance
(
"SSL"
);
sslContext
.
init
(
null
,
trustAllCerts
,
null
);
}
}
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录