|
| 1 | +/**************************************************************************** |
| 2 | + * Copyright (c) 2024 Composent, Inc. and others. |
| 3 | + * |
| 4 | + * This program and the accompanying materials are made |
| 5 | + * available under the terms of the Eclipse Public License 2.0 |
| 6 | + * which is available at https://www.eclipse.org/legal/epl-2.0/ |
| 7 | + * |
| 8 | + * Contributors: Composent, Inc. - initial API and implementation |
| 9 | + * |
| 10 | + * SPDX-License-Identifier: EPL-2.0 |
| 11 | + *****************************************************************************/ |
| 12 | +package org.eclipse.ecf.core.security; |
| 13 | + |
| 14 | +import java.security.*; |
| 15 | +import java.util.Optional; |
| 16 | +import javax.net.ssl.SSLContext; |
| 17 | +import org.eclipse.core.runtime.IStatus; |
| 18 | +import org.eclipse.core.runtime.Status; |
| 19 | +import org.eclipse.ecf.internal.core.identity.Activator; |
| 20 | +import org.osgi.framework.BundleContext; |
| 21 | +import org.osgi.util.tracker.ServiceTracker; |
| 22 | + |
| 23 | +/** |
| 24 | + * @since 3.12 |
| 25 | + */ |
| 26 | +public class ECFSSLContextFactory implements SSLContextFactory { |
| 27 | + |
| 28 | + private final ServiceTracker<Provider, Provider> providerTracker; |
| 29 | + private final String defaultProtocol; |
| 30 | + private final String defaultProviderName; |
| 31 | + |
| 32 | + public ECFSSLContextFactory(BundleContext context, String defaultProtocol) { |
| 33 | + this(context, defaultProtocol, null); |
| 34 | + } |
| 35 | + |
| 36 | + public ECFSSLContextFactory(BundleContext context, String defaultProtocol, String defaultProviderName) { |
| 37 | + this.defaultProtocol = defaultProtocol; |
| 38 | + this.defaultProviderName = defaultProviderName; |
| 39 | + this.providerTracker = new ServiceTracker<Provider, Provider>(context, Provider.class, null); |
| 40 | + this.providerTracker.open(); |
| 41 | + } |
| 42 | + |
| 43 | + @Override |
| 44 | + public SSLContext getDefault() throws NoSuchAlgorithmException, NoSuchProviderException { |
| 45 | + return getInstance0(this.defaultProtocol, this.defaultProviderName); |
| 46 | + } |
| 47 | + |
| 48 | + protected SSLContext getInstance0(String protocol, String providerName) throws NoSuchAlgorithmException, NoSuchProviderException { |
| 49 | + if (protocol == null) { |
| 50 | + return SSLContext.getDefault(); |
| 51 | + } |
| 52 | + Provider provider = findProvider(providerName); |
| 53 | + if (provider == null) |
| 54 | + throw new NoSuchProviderException("No provider registered named '" + providerName + "'"); //$NON-NLS-1$ //$NON-NLS-2$ |
| 55 | + return SSLContext.getInstance(protocol, provider); |
| 56 | + } |
| 57 | + |
| 58 | + @Override |
| 59 | + public SSLContext getInstance(String protocol) throws NoSuchAlgorithmException, NoSuchProviderException { |
| 60 | + return getInstance0(protocol, this.defaultProviderName); |
| 61 | + } |
| 62 | + |
| 63 | + public void close() { |
| 64 | + this.providerTracker.close(); |
| 65 | + } |
| 66 | + |
| 67 | + protected Provider findProvider(String providerName) { |
| 68 | + if (providerName == null) { |
| 69 | + return this.providerTracker.getService(); |
| 70 | + } |
| 71 | + Optional<Provider> optResult = this.providerTracker.getTracked().values().stream().filter(p -> |
| 72 | + // test that providerName is equal to Provider.getName() |
| 73 | + providerName.equals(p.getName())).findFirst(); |
| 74 | + // If there are matching Providers, use first (highest priority from sorted map) and use to create SSLContext. |
| 75 | + // If none, then throw |
| 76 | + if (optResult.isPresent()) { |
| 77 | + return optResult.get(); |
| 78 | + } |
| 79 | + // If providerName is same as current default SSLContext then use it |
| 80 | + try { |
| 81 | + SSLContext defaultContext = SSLContext.getDefault(); |
| 82 | + if (providerName.equals(defaultContext.getProvider().getName())) { |
| 83 | + return defaultContext.getProvider(); |
| 84 | + } |
| 85 | + } catch (NoSuchAlgorithmException e) { |
| 86 | + Activator.getDefault().log(new Status(IStatus.ERROR, Activator.PLUGIN_ID, "Could not get SSLContext.getDefault()", e)); //$NON-NLS-1$ |
| 87 | + } |
| 88 | + return null; |
| 89 | + } |
| 90 | + |
| 91 | + @Override |
| 92 | + public SSLContext getInstance(String protocol, String providerName) throws NoSuchAlgorithmException, NoSuchProviderException { |
| 93 | + return getInstance0(protocol, providerName); |
| 94 | + } |
| 95 | + |
| 96 | +} |
0 commit comments