⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 acmdissigningutility.java

📁 一个完整的XACML工程,学习XACML技术的好例子!
💻 JAVA
字号:
/*
* Copyright (c) 2006, University of Kent
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without 
* modification, are permitted provided that the following conditions are met:
*
* Redistributions of source code must retain the above copyright notice, this 
* list of conditions and the following disclaimer.
* 
* Redistributions in binary form must reproduce the above copyright notice, 
* this list of conditions and the following disclaimer in the documentation 
* and/or other materials provided with the distribution. 
*
* 1. Neither the name of the University of Kent nor the names of its 
* contributors may be used to endorse or promote products derived from this 
* software without specific prior written permission. 
*
* 2. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS  
* IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
* THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 
* PURPOSE ARE DISCLAIMED. 
*
* 3. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE 
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 
* INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 
* CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
* POSSIBILITY OF SUCH DAMAGE.
*
* 4. YOU AGREE THAT THE EXCLUSIONS IN PARAGRAPHS 2 AND 3 ABOVE ARE REASONABLE
* IN THE CIRCUMSTANCES.  IN PARTICULAR, YOU ACKNOWLEDGE (1) THAT THIS
* SOFTWARE HAS BEEN MADE AVAILABLE TO YOU FREE OF CHARGE, (2) THAT THIS
* SOFTWARE IS NOT "PRODUCT" QUALITY, BUT HAS BEEN PRODUCED BY A RESEARCH
* GROUP WHO DESIRE TO MAKE THIS SOFTWARE FREELY AVAILABLE TO PEOPLE WHO WISH
* TO USE IT, AND (3) THAT BECAUSE THIS SOFTWARE IS NOT OF "PRODUCT" QUALITY
* IT IS INEVITABLE THAT THERE WILL BE BUGS AND ERRORS, AND POSSIBLY MORE
* SERIOUS FAULTS, IN THIS SOFTWARE.
*
* 5. This license is governed, except to the extent that local laws
* necessarily apply, by the laws of England and Wales.
*/

/*
 * ACMDISSigningUtility.java
 *
 * Created on September 22, 2005, 3:26 PM
 */

package issrg.acm.extensions;

import issrg.acm.EnvironmentalVariables;
import issrg.acm.Registry;
import java.io.BufferedReader;
import java.io.FileInputStream;
import java.io.FileNotFoundException;
import java.io.InputStreamReader;
import java.rmi.RemoteException;
import java.util.Map;
import javax.swing.JOptionPane;
import javax.xml.namespace.QName;

import org.apache.axis.client.Call;
import org.apache.axis.client.Service;

import java.security.KeyStore;
import java.security.Key;
import java.security.cert.Certificate;
import java.io.*;
import java.util.*;


/**
 *
 * @author anhnt
 */
public class ACMDISSigningUtility extends SimpleSigningUtility implements issrg.acm.Utility, issrg.acm.SSLConnection {    
    
    
    /** Creates a new instance of ACMDISSigningUtility */
    public ACMDISSigningUtility() {        
    }
    
    /**
     * This method calls the DIS service for signing (storing) an AC
     *@param endpoint is a string. It is the URL of the DIS service
     *@param certificate is the AC that needs to be signed by the DIS
     *@param vars is the map, that stores the environmental variables
     *@return a string, that tells the result of the signing (storing) process
     */
    
    public String sign(String endpoint, byte[] certificate, Map vars) {
        if (!setProperties(endpoint, vars)) return null;
        try {
            Service  service = new Service();
            Call     call    = (Call) service.createCall();
            call.setTargetEndpointAddress( new java.net.URL(endpoint) );
            call.setOperationName(new QName("http://soapinterop.org/", "storeACForMe"));
            String param = org.apache.axis.encoding.Base64.encode(certificate);
            return (String) call.invoke( new Object[] {param});
        } 
        catch (Exception e) {
            issrg.utils.Util.bewail("Service is not available or wrong service's URL", e, null);
            return null;
        }
    }
    
    /**
     * This method calls the DIS service for revoking an AC
     *@param endpoint is a string. It is the URL of the DIS service
     *@param certificate is the AC that needs to be revoked by the DIS
     *@param vars is the map, that stores the environmental variables
     *@return a string, that tells the result of the revoking process
     */
    
    public String revoke(String endpoint, byte[] certificate, Map vars) {
        if (!setProperties(endpoint, vars)) return null;
        try {
            Service  service = new Service();
            Call     call    = (Call) service.createCall();
            call.setTargetEndpointAddress( new java.net.URL(endpoint) );
            call.setOperationName(new QName("http://soapinterop.org/", "revokeACForMe"));
            String param = org.apache.axis.encoding.Base64.encode(certificate);
            return (String) call.invoke( new Object[] {param});
        } 
        catch (Exception e) {
            issrg.utils.Util.bewail("Service is not available or wrong service's URL", e, null);
            return null;
        }
    }
    
    /**
     * This method sets the parameters for calling the DIS service
     *@param endpoint is a string. It is the URL of the DIS service
     *@vars is the map, that stores the environmental variables
     *@return a boolean value, that tells the result of the process
     */
    
    private boolean setProperties(String endpoint, Map vars) {        
        
        String keyStore = (String) vars.get(issrg.security.DefaultSecurity.LAST_FILE_STRING);
        String trustStore = (String) vars.get(EnvironmentalVariables.TRUSTSTORE);
        char[][] ps = (char[][]) vars.get(issrg.security.DefaultSecurity.PASSWORDS);
        String keyStorePassword = String.valueOf(ps[0]);
        try {
            try {
                FileInputStream fis = new FileInputStream(trustStore);
                fis.close();
                System.setProperty("javax.net.ssl.trustStore", trustStore);
            } catch (FileNotFoundException fnf) {} //default to the system wide trustStore:/java/jre/lib/security/cacerts
            try {
                FileInputStream fis = new FileInputStream("jkskeystore");
                fis.close();
                System.setProperty("javax.net.ssl.keyStore", "jkskeystore");
            } catch (FileNotFoundException fne) {
                System.setProperty("javax.net.ssl.keyStore", createJKS(keyStore, keyStorePassword));
            }
            System.setProperty("javax.net.ssl.keyStorePassword", keyStorePassword);
        } catch (IOException ioe) {
            ioe.printStackTrace();
            return false;
        }
        return true;
    }
    
    /**
     * This method creates a jks keystore from a p12 keystore and returns 
     *a jks filename
     *@param keyStore is the name of the p12 keystore
     *@param keyStorePassword is the password of the p12 keystore
     *@return a string. It is the name of the jks keystore 
     */
    
    private String createJKS(String keyStore, String keyStorePassword) {
        try {
            //System.out.println(keyStore);
            KeyStore inputKeyStore = KeyStore.getInstance("PKCS12");
            FileInputStream fis = new FileInputStream(keyStore);
            char[] nPassword = null;
            if (keyStorePassword.trim().equals("")){
                nPassword = null;
            } else{
                nPassword = keyStorePassword.toCharArray();
            }
            //System.out.println("Prepare to load keystore file");
            inputKeyStore.load(fis, nPassword);
            fis.close();
            KeyStore outputKeyStore = KeyStore.getInstance("JKS");            
            outputKeyStore.load(null, nPassword);
            //System.out.println("keystore file is loaded");
            Enumeration enu = inputKeyStore.aliases();
            while (enu.hasMoreElements()){
                String keyAlias = (String)enu.nextElement();
//                System.out.println("alias=[" + keyAlias + "]");
                if (inputKeyStore.isKeyEntry(keyAlias)){
                    Key key = inputKeyStore.getKey(keyAlias, nPassword);
                    Certificate[] certChain = inputKeyStore.getCertificateChain(keyAlias);
                    outputKeyStore.setKeyEntry(keyAlias, key, nPassword, certChain);
                }
            }
            //System.out.println("write to new keystore file format");
            FileOutputStream out = new FileOutputStream("jkskeystore");
            outputKeyStore.store(out, nPassword);
            out.close();
            return "jkskeystore";
        } catch (Exception e) {
            e.printStackTrace();
        }        
        return null;
    }    
}

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -