1069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project/*
2069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * $HeadURL: http://svn.apache.org/repos/asf/httpcomponents/httpclient/trunk/module-client/src/main/java/org/apache/http/conn/ssl/AbstractVerifier.java $
3069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * $Revision: 653041 $
4069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * $Date: 2008-05-03 03:39:28 -0700 (Sat, 03 May 2008) $
5069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
6069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * ====================================================================
7069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * Licensed to the Apache Software Foundation (ASF) under one
8069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * or more contributor license agreements.  See the NOTICE file
9069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * distributed with this work for additional information
10069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * regarding copyright ownership.  The ASF licenses this file
11069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * to you under the Apache License, Version 2.0 (the
12069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * "License"); you may not use this file except in compliance
13069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * with the License.  You may obtain a copy of the License at
14069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
15069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *   http://www.apache.org/licenses/LICENSE-2.0
16069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
17069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * Unless required by applicable law or agreed to in writing,
18069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * software distributed under the License is distributed on an
19069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
20069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * KIND, either express or implied.  See the License for the
21069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * specific language governing permissions and limitations
22069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * under the License.
23069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * ====================================================================
24069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
25069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * This software consists of voluntary contributions made by many
26069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * individuals on behalf of the Apache Software Foundation.  For more
27069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * information on the Apache Software Foundation, please see
28069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * <http://www.apache.org/>.
29069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
30069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project */
31069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
32069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectpackage org.apache.http.conn.ssl;
33069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
34069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport org.apache.http.conn.util.InetAddressUtils;
35069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
36069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.io.IOException;
37069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.io.InputStream;
38069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.security.cert.Certificate;
39069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.security.cert.CertificateParsingException;
40069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.security.cert.X509Certificate;
41069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.util.Arrays;
42069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.util.Collection;
43069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.util.Iterator;
44069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.util.LinkedList;
45069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.util.List;
46069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.util.Locale;
47069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.util.logging.Logger;
48069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport java.util.logging.Level;
49069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
50ec8c48dd748c81ba2cce518bf83cb9f236c30baeAlex Klyubinimport javax.net.ssl.DistinguishedNameParser;
51069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport javax.net.ssl.SSLException;
52069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport javax.net.ssl.SSLSession;
53069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectimport javax.net.ssl.SSLSocket;
54069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
55069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project/**
56069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * Abstract base class for all standard {@link X509HostnameVerifier}
57069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * implementations.
58069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project *
59069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project * @author Julius Davies
60069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project */
61069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Projectpublic abstract class AbstractVerifier implements X509HostnameVerifier {
62069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
63069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    /**
64069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * This contains a list of 2nd-level domains that aren't allowed to
65069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * have wildcards when combined with country-codes.
66069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * For example: [*.co.uk].
67069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * <p/>
68069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * The [*.co.uk] problem is an interesting one.  Should we just hope
69069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * that CA's would never foolishly allow such a certificate to happen?
70069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * Looks like we're the only implementation guarding against this.
71069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * Firefox, Curl, Sun Java 1.4, 5, 6 don't bother with this check.
72069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     */
73069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    private final static String[] BAD_COUNTRY_2LDS =
74069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project          { "ac", "co", "com", "ed", "edu", "go", "gouv", "gov", "info",
75069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            "lg", "ne", "net", "or", "org" };
76069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
77069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    static {
78069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        // Just in case developer forgot to manually sort the array.  :-)
79069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        Arrays.sort(BAD_COUNTRY_2LDS);
80069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
81069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
82069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public AbstractVerifier() {
83069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        super();
84069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
85069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
86069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public final void verify(String host, SSLSocket ssl)
87069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project          throws IOException {
88069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        if(host == null) {
89069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            throw new NullPointerException("host to verify is null");
90069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
91069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
92069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        SSLSession session = ssl.getSession();
93069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        Certificate[] certs = session.getPeerCertificates();
94069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        X509Certificate x509 = (X509Certificate) certs[0];
95069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        verify(host, x509);
96069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
97069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
98069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public final boolean verify(String host, SSLSession session) {
99069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        try {
100069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            Certificate[] certs = session.getPeerCertificates();
101069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            X509Certificate x509 = (X509Certificate) certs[0];
102069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            verify(host, x509);
103069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            return true;
104069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
105069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        catch(SSLException e) {
106069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            return false;
107069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
108069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
109069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
110069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public final void verify(String host, X509Certificate cert)
111069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project          throws SSLException {
112069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        String[] cns = getCNs(cert);
113069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        String[] subjectAlts = getDNSSubjectAlts(cert);
114069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        verify(host, cns, subjectAlts);
115069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
116069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
117069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public final void verify(final String host, final String[] cns,
118069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                             final String[] subjectAlts,
119069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                             final boolean strictWithSubDomains)
120069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project          throws SSLException {
121069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
122069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        // Build the list of names we're going to check.  Our DEFAULT and
123069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        // STRICT implementations of the HostnameVerifier only use the
124069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        // first CN provided.  All other CNs are ignored.
125069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        // (Firefox, wget, curl, Sun Java 1.4, 5, 6 all work this way).
126069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        LinkedList<String> names = new LinkedList<String>();
127069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        if(cns != null && cns.length > 0 && cns[0] != null) {
128069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            names.add(cns[0]);
129069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
130069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        if(subjectAlts != null) {
131069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            for (String subjectAlt : subjectAlts) {
132069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                if (subjectAlt != null) {
133069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                    names.add(subjectAlt);
134069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                }
135069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            }
136069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
137069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
138069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        if(names.isEmpty()) {
139069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            String msg = "Certificate for <" + host + "> doesn't contain CN or DNS subjectAlt";
140069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            throw new SSLException(msg);
141069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
142069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
143069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        // StringBuffer for building the error message.
144069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        StringBuffer buf = new StringBuffer();
145069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
146069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        // We're can be case-insensitive when comparing the host we used to
147069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        // establish the socket to the hostname in the certificate.
148069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        String hostName = host.trim().toLowerCase(Locale.ENGLISH);
149069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        boolean match = false;
150069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        for(Iterator<String> it = names.iterator(); it.hasNext();) {
151069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            // Don't trim the CN, though!
152069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            String cn = it.next();
153069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            cn = cn.toLowerCase(Locale.ENGLISH);
154069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            // Store CN in StringBuffer in case we need to report an error.
155069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            buf.append(" <");
156069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            buf.append(cn);
157069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            buf.append('>');
158069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            if(it.hasNext()) {
159069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                buf.append(" OR");
160069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            }
161069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
162069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            // The CN better have at least two dots if it wants wildcard
163069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            // action.  It also can't be [*.co.uk] or [*.co.jp] or
164069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            // [*.org.uk], etc...
165069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            boolean doWildcard = cn.startsWith("*.") &&
166177cd647c9fa02329fb9800f71282b233170f986Brian Carlstrom                                 cn.indexOf('.', 2) != -1 &&
167069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                                 acceptableCountryWildcard(cn) &&
168069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                                 !InetAddressUtils.isIPv4Address(host);
169069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
170069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            if(doWildcard) {
171069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                match = hostName.endsWith(cn.substring(1));
172069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                if(match && strictWithSubDomains) {
173069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                    // If we're in strict mode, then [*.foo.com] is not
174069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                    // allowed to match [a.b.foo.com]
175069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                    match = countDots(hostName) == countDots(cn);
176069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                }
177069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            } else {
178069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                match = hostName.equals(cn);
179069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            }
180069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            if(match) {
181069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                break;
182069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            }
183069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
184069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        if(!match) {
185069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            throw new SSLException("hostname in certificate didn't match: <" + host + "> !=" + buf);
186069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
187069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
188069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
189069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public static boolean acceptableCountryWildcard(String cn) {
190069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        int cnLen = cn.length();
191069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        if(cnLen >= 7 && cnLen <= 9) {
192069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            // Look for the '.' in the 3rd-last position:
193069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            if(cn.charAt(cnLen - 3) == '.') {
194069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                // Trim off the [*.] and the [.XX].
195069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                String s = cn.substring(2, cnLen - 3);
196069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                // And test against the sorted array of bad 2lds:
197069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                int x = Arrays.binarySearch(BAD_COUNTRY_2LDS, s);
198069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                return x < 0;
199069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            }
200069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
201069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        return true;
202069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
203069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
204069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public static String[] getCNs(X509Certificate cert) {
205ec8c48dd748c81ba2cce518bf83cb9f236c30baeAlex Klyubin        DistinguishedNameParser dnParser =
206ec8c48dd748c81ba2cce518bf83cb9f236c30baeAlex Klyubin                new DistinguishedNameParser(cert.getSubjectX500Principal());
207ec8c48dd748c81ba2cce518bf83cb9f236c30baeAlex Klyubin        List<String> cnList = dnParser.getAllMostSpecificFirst("cn");
208ec8c48dd748c81ba2cce518bf83cb9f236c30baeAlex Klyubin
209069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        if(!cnList.isEmpty()) {
210069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            String[] cns = new String[cnList.size()];
211069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            cnList.toArray(cns);
212069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            return cns;
213069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        } else {
214069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            return null;
215069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
216069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
217069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
218069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
219069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    /**
220069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * Extracts the array of SubjectAlt DNS names from an X509Certificate.
221069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * Returns null if there aren't any.
222069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * <p/>
223069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * Note:  Java doesn't appear able to extract international characters
224069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * from the SubjectAlts.  It can only extract international characters
225069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * from the CN field.
226069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * <p/>
227069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * (Or maybe the version of OpenSSL I'm using to test isn't storing the
228069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * international characters correctly in the SubjectAlts?).
229069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     *
230069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * @param cert X509Certificate
231069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * @return Array of SubjectALT DNS names stored in the certificate.
232069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     */
233069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public static String[] getDNSSubjectAlts(X509Certificate cert) {
234069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        LinkedList<String> subjectAltList = new LinkedList<String>();
235069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        Collection<List<?>> c = null;
236069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        try {
237069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            c = cert.getSubjectAlternativeNames();
238069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
239069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        catch(CertificateParsingException cpe) {
240069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            Logger.getLogger(AbstractVerifier.class.getName())
241069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                    .log(Level.FINE, "Error parsing certificate.", cpe);
242069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
243069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        if(c != null) {
244069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            for (List<?> aC : c) {
245069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                List<?> list = aC;
246069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                int type = ((Integer) list.get(0)).intValue();
247069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                // If type is 2, then we've got a dNSName
248069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                if (type == 2) {
249069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                    String s = (String) list.get(1);
250069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                    subjectAltList.add(s);
251069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                }
252069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            }
253069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
254069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        if(!subjectAltList.isEmpty()) {
255069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            String[] subjectAlts = new String[subjectAltList.size()];
256069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            subjectAltList.toArray(subjectAlts);
257069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            return subjectAlts;
258069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        } else {
259069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            return null;
260069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
261069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
262069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
263069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    /**
264069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * Counts the number of dots "." in a string.
265069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * @param s  string to count dots from
266069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     * @return  number of dots
267069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project     */
268069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    public static int countDots(final String s) {
269069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        int count = 0;
270069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        for(int i = 0; i < s.length(); i++) {
271069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            if(s.charAt(i) == '.') {
272069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project                count++;
273069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project            }
274069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        }
275069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project        return count;
276069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project    }
277069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project
278069490a5ca2fd1988d29daf45d892f47ad665115The Android Open Source Project}
279