Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -316,7 +316,7 @@ public ConfigChangeResult applyConfigurationChange(LDAPConnectionHandlerCfg conf
private void configureSSL(LDAPConnectionHandlerCfg config) throws DirectoryException {
protocol = config.isUseSSL() ? "LDAPS" : "LDAP";
if (config.isUseSSL() || config.isAllowStartTLS()) {
sslContext = createSSLContext(config);
sslContext = createSSLContext(config, true);
sslEngine = createSSLEngine(config, sslContext);
} else {
sslContext = null;
Expand Down Expand Up @@ -581,7 +581,7 @@ public boolean isConfigurationAcceptable(ConnectionHandlerCfg configuration,
// Check that the SSL configuration is valid.
&& (config.isUseSSL() || config.isAllowStartTLS())) {
try {
createSSLEngine(config, createSSLContext(config));
createSSLEngine(config, createSSLContext(config, false));
} catch (DirectoryException e) {
logger.traceException(e);

Expand Down Expand Up @@ -937,26 +937,39 @@ private SSLEngine createSSLEngine(LDAPConnectionHandlerCfg config, SSLContext ss
}
}

private void disableAndWarnIfUseSSL(LDAPConnectionHandlerCfg config) {
if (config.isUseSSL()) {
private void disableAndWarnIfUseSSL(LDAPConnectionHandlerCfg config, boolean forUse) {
if (forUse && config.isUseSSL()) {
logger.warn(INFO_DISABLE_CONNECTION, friendlyName);
enabled = false;
}
}

private SSLContext createSSLContext(LDAPConnectionHandlerCfg config) throws DirectoryException {
/**
* Creates the SSL context for the provided configuration.
*
* @param config
* the configuration to create the SSL context for
* @param forUse
* {@code true} when the handler is going to use the SSL context, at its start or when a change is
* applied, so that an SSL handler without a usable key is disabled; {@code false} when the SSL context
* only checks a proposed configuration, which must leave the running handler as it is
* @return the SSL context
* @throws DirectoryException
* if the SSL context cannot be created
*/
private SSLContext createSSLContext(LDAPConnectionHandlerCfg config, boolean forUse) throws DirectoryException {
try {
DN keyMgrDN = config.getKeyManagerProviderDN();
final ServerContext serverContext = DirectoryServer.getInstance().getServerContext();
KeyManagerProvider<?> keyManagerProvider = serverContext.getKeyManagerProvider(keyMgrDN);
if (keyManagerProvider == null) {
logger.error(ERR_NULL_KEY_PROVIDER_MANAGER, keyMgrDN, friendlyName);
disableAndWarnIfUseSSL(config);
disableAndWarnIfUseSSL(config, forUse);
keyManagerProvider = new NullKeyManagerProvider();
// The SSL connection is unusable without a key manager provider
} else if (!keyManagerProvider.containsAtLeastOneKey()) {
logger.error(ERR_INVALID_KEYSTORE, friendlyName);
disableAndWarnIfUseSSL(config);
disableAndWarnIfUseSSL(config, forUse);
}

final SortedSet<String> aliases = new TreeSet<>(config.getSSLCertNickname());
Expand All @@ -973,7 +986,7 @@ private SSLContext createSSLContext(LDAPConnectionHandlerCfg config) throws Dire
}

if (aliases.isEmpty()) {
disableAndWarnIfUseSSL(config);
disableAndWarnIfUseSSL(config, forUse);
}
keyManagers = SelectableCertificateKeyManager.wrap(keyManagerProvider.getKeyManagers(), aliases,
friendlyName);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -283,7 +283,7 @@ private void configureSSL(HTTPConnectionHandlerCfg config)
protocol = config.isUseSSL() ? "HTTPS" : "HTTP";
if (config.isUseSSL())
{
sslEngineConfigurator = createSSLEngineConfigurator(config);
sslEngineConfigurator = createSSLEngineConfigurator(config, true);
}
else
{
Expand Down Expand Up @@ -497,7 +497,7 @@ public boolean isConfigurationAcceptable(
{
try
{
createSSLEngineConfigurator(config);
createSSLEngineConfigurator(config, false);
}
catch (DirectoryException e)
{
Expand Down Expand Up @@ -817,7 +817,22 @@ public void toString(StringBuilder buffer)
buffer.append(handlerName);
}

private SSLEngineConfigurator createSSLEngineConfigurator(HTTPConnectionHandlerCfg config) throws DirectoryException
/**
* Creates the SSL engine configurator for the provided configuration.
*
* @param config
* the configuration to create the SSL engine configurator for
* @param forUse
* {@code true} when the handler is going to use the configurator: at its start a handler
* without a usable key is disabled ({@link #applyConfigurationChange} sets {@code enabled}
* from the configuration afterwards); {@code false} when the configurator only checks a
* proposed configuration, which must leave the running handler as it is
* @return the SSL engine configurator, or {@code null} if the configuration does not use SSL
* @throws DirectoryException
* if the SSL context cannot be created
*/
private SSLEngineConfigurator createSSLEngineConfigurator(HTTPConnectionHandlerCfg config, boolean forUse)
throws DirectoryException
{
if (!config.isUseSSL())
{
Expand All @@ -826,7 +841,7 @@ private SSLEngineConfigurator createSSLEngineConfigurator(HTTPConnectionHandlerC

try
{
SSLContext sslContext = createSSLContext(config);
SSLContext sslContext = createSSLContext(config, forUse);
SSLEngineConfigurator configurator = new SSLEngineConfigurator(sslContext);
configurator.setClientMode(false);

Expand Down Expand Up @@ -874,7 +889,16 @@ private SSLEngineConfigurator createSSLEngineConfigurator(HTTPConnectionHandlerC
}
}

private SSLContext createSSLContext(HTTPConnectionHandlerCfg config) throws Exception
private void disableAndWarn(boolean forUse)
{
if (forUse)
{
logger.warn(INFO_DISABLE_CONNECTION, friendlyName);
enabled = false;
}
}

private SSLContext createSSLContext(HTTPConnectionHandlerCfg config, boolean forUse) throws Exception
{
if (!config.isUseSSL())
{
Expand All @@ -886,15 +910,13 @@ private SSLContext createSSLContext(HTTPConnectionHandlerCfg config) throws Exce
if (keyManagerProvider == null)
{
logger.error(ERR_NULL_KEY_PROVIDER_MANAGER, keyMgrDN, friendlyName);
logger.warn(INFO_DISABLE_CONNECTION, friendlyName);
keyManagerProvider = new NullKeyManagerProvider();
enabled = false;
disableAndWarn(forUse);
}
else if (!keyManagerProvider.containsAtLeastOneKey())
{
logger.error(ERR_INVALID_KEYSTORE, friendlyName);
logger.warn(INFO_DISABLE_CONNECTION, friendlyName);
enabled = false;
disableAndWarn(forUse);
}

final SortedSet<String> aliases = new TreeSet<>(config.getSSLCertNickname());
Expand All @@ -916,8 +938,7 @@ else if (!keyManagerProvider.containsAtLeastOneKey())
}
if (aliases.isEmpty())
{
logger.warn(INFO_DISABLE_CONNECTION, friendlyName);
enabled = false;
disableAndWarn(forUse);
}
keyManagers = SelectableCertificateKeyManager.wrap(keyManagerProvider.getKeyManagers(), aliases, friendlyName);
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -331,7 +331,7 @@ private void configureSSL(LDAPConnectionHandlerCfg config)
protocol = config.isUseSSL() ? "LDAPS" : "LDAP";
if (config.isUseSSL() || config.isAllowStartTLS())
{
sslContext = createSSLContext(config);
sslContext = createSSLContext(config, true);
sslEngine = createSSLEngine(config, sslContext);
}
else
Expand Down Expand Up @@ -717,7 +717,7 @@ public boolean isConfigurationAcceptable(ConnectionHandlerCfg configuration,
{
try
{
createSSLEngine(config, createSSLContext(config));
createSSLEngine(config, createSSLContext(config, false));
}
catch (DirectoryException e)
{
Expand Down Expand Up @@ -1291,16 +1291,30 @@ private SSLEngine createSSLEngine(LDAPConnectionHandlerCfg config,
}
}

private void disableAndWarnIfUseSSL(LDAPConnectionHandlerCfg config)
private void disableAndWarnIfUseSSL(LDAPConnectionHandlerCfg config, boolean forUse)
{
if (config.isUseSSL())
if (forUse && config.isUseSSL())
{
logger.warn(INFO_DISABLE_CONNECTION, friendlyName);
enabled = false;
}
}

private SSLContext createSSLContext(LDAPConnectionHandlerCfg config)
/**
* Creates the SSL context for the provided configuration.
*
* @param config
* the configuration to create the SSL context for
* @param forUse
* {@code true} when the handler is going to use the SSL context, at its start or when
* a change is applied, so that an SSL handler without a usable key is disabled;
* {@code false} when the SSL context only checks a proposed configuration, which must
* leave the running handler as it is
* @return the SSL context
* @throws DirectoryException
* if the SSL context cannot be created
*/
private SSLContext createSSLContext(LDAPConnectionHandlerCfg config, boolean forUse)
throws DirectoryException
{
try
Expand All @@ -1311,14 +1325,14 @@ private SSLContext createSSLContext(LDAPConnectionHandlerCfg config)
if (keyManagerProvider == null)
{
logger.error(ERR_NULL_KEY_PROVIDER_MANAGER, keyMgrDN, friendlyName);
disableAndWarnIfUseSSL(config);
disableAndWarnIfUseSSL(config, forUse);
keyManagerProvider = new NullKeyManagerProvider();
// The SSL connection is unusable without a key manager provider
}
else if (! keyManagerProvider.containsAtLeastOneKey())
{
logger.error(ERR_INVALID_KEYSTORE, friendlyName);
disableAndWarnIfUseSSL(config);
disableAndWarnIfUseSSL(config, forUse);
}

final SortedSet<String> aliases = new TreeSet<>(config.getSSLCertNickname());
Expand All @@ -1341,7 +1355,7 @@ else if (! keyManagerProvider.containsAtLeastOneKey())

if (aliases.isEmpty())
{
disableAndWarnIfUseSSL(config);
disableAndWarnIfUseSSL(config, forUse);
}
keyManagers = SelectableCertificateKeyManager.wrap(keyManagerProvider.getKeyManagers(), aliases, friendlyName);
}
Expand Down
Loading
Loading