1 /*
   2  * Copyright (c) 2006, 2016, Oracle and/or its affiliates. All rights reserved.
   3  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
   4  *
   5  * This code is free software; you can redistribute it and/or modify it
   6  * under the terms of the GNU General Public License version 2 only, as
   7  * published by the Free Software Foundation.
   8  *
   9  * This code is distributed in the hope that it will be useful, but WITHOUT
  10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
  11  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
  12  * version 2 for more details (a copy is included in the LICENSE file that
  13  * accompanied this code).
  14  *
  15  * You should have received a copy of the GNU General Public License version
  16  * 2 along with this work; if not, write to the Free Software Foundation,
  17  * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
  18  *
  19  * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
  20  * or visit www.oracle.com if you need additional information or have any
  21  * questions.
  22  */
  23 
  24 /*
  25  * @test
  26  * @bug 6269847
  27  * @summary store a NSS PKCS11 PrivateKeyEntry to JKS KeyStore throws confusing NPE
  28  * @author Wang Weijun
  29  * @library ..
  30  * @modules jdk.crypto.pkcs11
  31  * @run main/othervm JksSetPrivateKey
  32  * @run main/othervm JksSetPrivateKey sm policy
  33  */
  34 
  35 import java.io.File;
  36 import java.security.KeyStore;
  37 import java.security.KeyStoreException;
  38 import java.security.PrivateKey;
  39 import java.security.Provider;
  40 import java.security.Security;
  41 import java.security.cert.X509Certificate;
  42 import java.util.Collection;
  43 import java.util.Collections;
  44 import java.util.TreeSet;
  45 
  46 public class JksSetPrivateKey extends SecmodTest {
  47 
  48     public static void main(String[] args) throws Exception {
  49         if (initSecmod() == false) {
  50             return;
  51         }
  52 
  53         String configName = BASE + SEP + "nss.cfg";
  54         Provider p = getSunPKCS11(configName);
  55 
  56         System.out.println(p);
  57         Security.addProvider(p);
  58 
  59         if (args.length > 1 && "sm".equals(args[0])) {
  60             System.setProperty("java.security.policy",
  61                     BASE + File.separator + args[1]);
  62             System.setSecurityManager(new SecurityManager());
  63         }
  64 
  65         KeyStore ks = KeyStore.getInstance("PKCS11", p);
  66         ks.load(null, password);
  67         Collection<String> aliases = new TreeSet<>(Collections.list(ks.aliases()));
  68         System.out.println("entries: " + aliases.size());
  69         System.out.println(aliases);
  70 
  71         PrivateKey privateKey = (PrivateKey)ks.getKey(keyAlias, password);
  72         System.out.println(privateKey);
  73 
  74         X509Certificate[] chain = (X509Certificate[])ks.getCertificateChain(keyAlias);
  75 
  76         KeyStore jks = KeyStore.getInstance("JKS");
  77         jks.load(null, null);
  78 
  79         try {
  80             jks.setKeyEntry("k1", privateKey, "changeit".toCharArray(), chain);
  81             throw new Exception("No, an NSS PrivateKey shouldn't be extractable and put inside a JKS keystore");
  82         } catch (KeyStoreException e) {
  83             System.err.println(e); // This is OK
  84         }
  85 
  86         try {
  87             jks.setKeyEntry("k2", new DummyPrivateKey(), "changeit".toCharArray(), chain);
  88             throw new Exception("No, non-PKCS#8 key shouldn't be put inside a KeyStore");
  89         } catch (KeyStoreException e) {
  90             System.err.println(e); // This is OK
  91         }
  92         System.out.println("OK");
  93 
  94         try {
  95             jks.setKeyEntry("k3", new DummyPrivateKey2(), "changeit".toCharArray(), chain);
  96             throw new Exception("No, not-extractble key shouldn't be put inside a KeyStore");
  97         } catch (KeyStoreException e) {
  98             System.err.println(e); // This is OK
  99         }
 100         System.out.println("OK");
 101     }
 102 }
 103 
 104 class DummyPrivateKey implements PrivateKey {
 105     @Override
 106     public String getAlgorithm() {
 107         return "DUMMY";
 108     }
 109 
 110     @Override
 111     public String getFormat() {
 112         return "DUMMY";
 113     }
 114 
 115     @Override
 116     public byte[] getEncoded() {
 117         return "DUMMY".getBytes();
 118     }
 119 }
 120 
 121 class DummyPrivateKey2 implements PrivateKey {
 122     @Override
 123     public String getAlgorithm() {
 124         return "DUMMY";
 125     }
 126 
 127     @Override
 128     public String getFormat() {
 129         return "PKCS#8";
 130     }
 131 
 132     @Override
 133     public byte[] getEncoded() {
 134         return null;
 135     }
 136 }