1069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project/*
2069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * $HeadURL: http://svn.apache.org/repos/asf/httpcomponents/httpclient/trunk/module-client/src/main/java/org/apache/http/conn/ssl/StrictHostnameVerifier.java $
3069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * $Revision: 617642 $
4069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * $Date: 2008-02-01 12:54:07 -0800 (Fri, 01 Feb 2008) $
5069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
6069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * ====================================================================
7069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * Licensed to the Apache Software Foundation (ASF) under one
8069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * or more contributor license agreements.  See the NOTICE file
9069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * distributed with this work for additional information
10069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * regarding copyright ownership.  The ASF licenses this file
11069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * to you under the Apache License, Version 2.0 (the
12069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * "License"); you may not use this file except in compliance
13069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * with the License.  You may obtain a copy of the License at
14069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
15069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *   http://www.apache.org/licenses/LICENSE-2.0
16069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
17069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * Unless required by applicable law or agreed to in writing,
18069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * software distributed under the License is distributed on an
19069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
20069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * KIND, either express or implied.  See the License for the
21069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * specific language governing permissions and limitations
22069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * under the License.
23069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * ====================================================================
24069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
25069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * This software consists of voluntary contributions made by many
26069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * individuals on behalf of the Apache Software Foundation.  For more
27069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * information on the Apache Software Foundation, please see
28069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * <http://www.apache.org/>.
29069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
30069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project */
31069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
32069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectpackage org.apache.http.conn.ssl;
33069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
34069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport javax.net.ssl.SSLException;
35069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
36069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project/**
37069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * The Strict HostnameVerifier works the same way as Sun Java 1.4, Sun
38069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * Java 5, Sun Java 6-rc.  It's also pretty close to IE6.  This
39069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * implementation appears to be compliant with RFC 2818 for dealing with
40069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * wildcards.
41069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * <p/>
42069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * The hostname must match either the first CN, or any of the subject-alts.
43069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * A wildcard can occur in the CN, and in any of the subject-alts.  The
44069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * one divergence from IE6 is how we only check the first CN.  IE6 allows
45069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * a match against any of the CNs present.  We decided to follow in
46069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * Sun Java 1.4's footsteps and only check the first CN.  (If you need
47069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * to check all the CN's, feel free to write your own implementation!).
48069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * <p/>
49069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * A wildcard such as "*.foo.com" matches only subdomains in the same
50069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * level, for example "a.foo.com".  It does not match deeper subdomains
51069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * such as "a.b.foo.com".
52069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
53069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * @author Julius Davies
54069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project */
55069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectpublic class StrictHostnameVerifier extends AbstractVerifier {
56069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
57069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public final void verify(
58069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            final String host,
59069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            final String[] cns,
60069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            final String[] subjectAlts) throws SSLException {
61069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        verify(host, cns, subjectAlts, true);
62069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
63069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
64069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    @Override
65069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public final String toString() {
66069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        return "STRICT";
67069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
68069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
69069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project}
70