Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
R
relaxed-ssl-embedded-jetty
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Analytics
Analytics
CI / CD
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
Claude Brisson
relaxed-ssl-embedded-jetty
Commits
e150f504
Commit
e150f504
authored
Feb 27, 2020
by
Claude Brisson
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
First commit
parents
Changes
4
Expand all
Hide whitespace changes
Inline
Side-by-side
Showing
4 changed files
with
339 additions
and
0 deletions
+339
-0
LICENSE
LICENSE
+0
-0
README.md
README.md
+46
-0
pom.xml
pom.xml
+230
-0
src/main/java/com/republicate/relaxedssljetty/RelaxedSslContextFactory.java
...republicate/relaxedssljetty/RelaxedSslContextFactory.java
+63
-0
No files found.
LICENSE
0 → 100644
View file @
e150f504
This diff is collapsed.
Click to expand it.
README.md
0 → 100644
View file @
e150f504
# Relaxed SSL Embedded Jetty
See
[
jetty-how-to-validate-ssl-client-certs-in-application-code
](
https://stackoverflow.com/a/46813898/710286
)
for usage.
Use class name:
`com.republicate.relaxedssljetty.RelaxedSslContextFactory`
.
In your pom:
<repositories>
<repository>
<id>republicate.com</id>
<url>http://republicate.com/maven2</url>
<releases>
<enabled>false</enabled>
</releases>
<snapshots>
<enabled>true</enabled>
<!-- <updatePolicy>always</updatePolicy> -->
<checksumPolicy>fail</checksumPolicy>
</snapshots>
</repository>
</repositories>
and:
<plugin>
<groupId>org.eclipse.jetty</groupId>
<artifactId>jetty-maven-plugin</artifactId>
<version>${jetty.version}</version>
...
<dependencies>
...
<dependency>
<groupId>com.republicate.relaxed-ssl-jetty</groupId>
<artifactId>relaxed-ssl-context-factory</artifactId>
<version>1.0-SNAPSHOT</version>
</dependency>
</plugin>
In jetty-ssl.xml:
<Configure id="sslContextFactory" class="com.republicate.relaxedssljetty.RelaxedSslContextFactory">
<Set name="TrustAll">true</Set>
...
</Configure>
pom.xml
0 → 100644
View file @
e150f504
<?xml version="1.0" encoding="UTF-8"?>
<!--
Licensed to the Apache Software Foundation (ASF) under one
or more contributor license agreements. See the NOTICE file
distributed with this work for additional information
regarding copyright ownership. The ASF licenses this file
to you under the Apache License, Version 2.0 (the
"License"); you may not use this file except in compliance
with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing,
software distributed under the License is distributed on an
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
KIND, either express or implied. See the License for the
specific language governing permissions and limitations
under the License.
-->
<project
xmlns=
"http://maven.apache.org/POM/4.0.0"
xmlns:xsi=
"http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation=
"http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"
>
<modelVersion>
4.0.0
</modelVersion>
<parent>
<groupId>
org.sonatype.oss
</groupId>
<artifactId>
oss-parent
</artifactId>
<version>
7
</version>
</parent>
<groupId>
com.republicate.relaxed-ssl-jetty
</groupId>
<artifactId>
relaxed-ssl-context-factory
</artifactId>
<version>
1.0-SNAPSHOT
</version>
<packaging>
jar
</packaging>
<name>
${project.groupId}:${project.artifactId}
</name>
<description>
Relaxed SSL Context Factory for Embedded Jetty
</description>
<url>
https://gitlab.renegat.net/claude/relaxed-ssl-embedded-jetty
</url>
<licenses>
<license>
<name>
Apache Licence
</name>
<url>
http://www.apache.org/licenses/LICENSE-2.0
</url>
</license>
</licenses>
<scm>
<connection>
scm:git@gitlab.renegat.net:claude/relaxed-ssl-embedded-jetty.git
</connection>
<developerConnection>
scm:git:git@gitlab.renegat.net:claude/relaxed-ssl-embedded-jetty.git
</developerConnection>
<url>
https://gitlab.renegat.net/claude/relaxed-ssl-embedded-jetty
</url>
</scm>
<developers>
<developer>
<id>
arkanovicz
</id>
<name>
Claude Brisson
</name>
<email>
claude@renegat.net
</email>
<organization>
republicate.com
</organization>
<organizationUrl>
https://republicate.com
</organizationUrl>
</developer>
</developers>
<properties>
<project.build.sourceEncoding>
UTF-8
</project.build.sourceEncoding>
<servlet.version>
3.1.0
</servlet.version>
<jetty.version>
9.4.22.v20191022
</jetty.version>
</properties>
<distributionManagement>
<snapshotRepository>
<id>
ossrh
</id>
<url>
https://oss.sonatype.org/content/repositories/snapshots
</url>
</snapshotRepository>
</distributionManagement>
<build>
<defaultGoal>
install
</defaultGoal>
<plugins>
<!-- validation -->
<plugin>
<groupId>
org.apache.maven.plugins
</groupId>
<artifactId>
maven-enforcer-plugin
</artifactId>
<version>
3.0.0-M3
</version>
<executions>
<execution>
<id>
enforce-bytecode-version
</id>
<goals>
<goal>
enforce
</goal>
</goals>
<configuration>
<rules>
<requireJavaVersion>
<version>
[1.8,)
</version>
</requireJavaVersion>
</rules>
<fail>
true
</fail>
</configuration>
</execution>
<execution>
<id>
ban-known-bad-maven-versions
</id>
<goals>
<goal>
enforce
</goal>
</goals>
<configuration>
<rules>
<requireMavenVersion>
<version>
[3.0.5,)
</version>
<message>
Maven minimal expected version is 3.0.5.
</message>
</requireMavenVersion>
</rules>
</configuration>
</execution>
</executions>
<dependencies>
<dependency>
<groupId>
org.codehaus.mojo
</groupId>
<artifactId>
extra-enforcer-rules
</artifactId>
<version>
1.2
</version>
</dependency>
</dependencies>
</plugin>
<!-- building -->
<plugin>
<groupId>
org.apache.maven.plugins
</groupId>
<artifactId>
maven-compiler-plugin
</artifactId>
<version>
3.8.1
</version>
<configuration>
<showDeprecation>
true
</showDeprecation>
<source>
1.8
</source>
<target>
1.8
</target>
</configuration>
</plugin>
<!-- deployment -->
<plugin>
<groupId>
org.sonatype.plugins
</groupId>
<artifactId>
nexus-staging-maven-plugin
</artifactId>
<version>
1.6.7
</version>
<extensions>
true
</extensions>
<configuration>
<serverId>
ossrh
</serverId>
<nexusUrl>
https://oss.sonatype.org/
</nexusUrl>
</configuration>
</plugin>
<!-- sources jar -->
<plugin>
<groupId>
org.apache.maven.plugins
</groupId>
<artifactId>
maven-source-plugin
</artifactId>
<version>
3.2.0
</version>
<configuration>
<includePom>
false
</includePom>
</configuration>
<executions>
<execution>
<id>
attach-sources
</id>
<goals>
<goal>
jar-no-fork
</goal>
</goals>
</execution>
</executions>
</plugin>
<!-- tests -->
<plugin>
<groupId>
org.apache.maven.plugins
</groupId>
<artifactId>
maven-surefire-plugin
</artifactId>
<version>
3.0.0-M3
</version>
<configuration>
<workingDirectory>
${project.build.testOutputDirectory}
</workingDirectory>
<systemProperties>
<property>
<name>
test.output.dir
</name>
<value>
${project.build.testOutputDirectory}
</value>
</property>
<property>
<name>
org.slf4j.simpleLogger.defaultLogLevel
</name>
<value>
info
</value>
</property>
</systemProperties>
</configuration>
</plugin>
<!-- signing -->
<plugin>
<groupId>
org.apache.maven.plugins
</groupId>
<artifactId>
maven-gpg-plugin
</artifactId>
<version>
1.6
</version>
<executions>
<execution>
<id>
sign-artifacts
</id>
<phase>
verify
</phase>
<goals>
<goal>
sign
</goal>
</goals>
</execution>
</executions>
</plugin>
<!-- javadoc -->
<plugin>
<groupId>
org.apache.maven.plugins
</groupId>
<artifactId>
maven-javadoc-plugin
</artifactId>
<version>
2.10.3
</version>
<executions>
<execution>
<id>
attach-javadocs
</id>
<goals>
<goal>
jar
</goal>
</goals>
</execution>
</executions>
</plugin>
<!-- deployment -->
<plugin>
<groupId>
org.apache.maven.plugins
</groupId>
<artifactId>
maven-deploy-plugin
</artifactId>
<version>
3.0.0-M1
</version>
</plugin>
</plugins>
</build>
<dependencies>
<!-- servlets api -->
<dependency>
<groupId>
javax.servlet
</groupId>
<artifactId>
javax.servlet-api
</artifactId>
<version>
${servlet.version}
</version>
<scope>
provided
</scope>
</dependency>
<dependency>
<groupId>
org.eclipse.jetty
</groupId>
<artifactId>
jetty-util
</artifactId>
<version>
${jetty.version}
</version>
</dependency>
</dependencies>
</project>
src/main/java/com/republicate/relaxedssljetty/RelaxedSslContextFactory.java
0 → 100644
View file @
e150f504
package
com.republicate.relaxedssljetty
;
import
org.eclipse.jetty.util.annotation.ManagedObject
;
import
org.eclipse.jetty.util.ssl.SslContextFactory
;
import
javax.net.ssl.CertPathTrustManagerParameters
;
import
javax.net.ssl.TrustManager
;
import
javax.net.ssl.TrustManagerFactory
;
import
java.security.KeyStore
;
import
java.security.cert.CRL
;
import
java.security.cert.PKIXBuilderParameters
;
import
java.util.Collection
;
import
static
org
.
eclipse
.
jetty
.
util
.
ssl
.
SslContextFactory
.
DEFAULT_KEYMANAGERFACTORY_ALGORITHM
;
import
static
org
.
eclipse
.
jetty
.
util
.
ssl
.
SslContextFactory
.
DEFAULT_TRUSTMANAGERFACTORY_ALGORITHM
;
/**
* SslContextFactoryRelaxed is used to configure SSL connectors
* as well as HttpClient. It holds all SSL parameters and
* creates SSL context based on these parameters to be
* used by the SSL connectors.
*
* TrustAll really means trustAll!
*/
@ManagedObject
public
class
RelaxedSslContextFactory
extends
SslContextFactory
{
private
String
_keyManagerFactoryAlgorithm
=
DEFAULT_KEYMANAGERFACTORY_ALGORITHM
;
private
String
_trustManagerFactoryAlgorithm
=
DEFAULT_TRUSTMANAGERFACTORY_ALGORITHM
;
@Override
protected
TrustManager
[]
getTrustManagers
(
KeyStore
trustStore
,
Collection
<?
extends
CRL
>
crls
)
throws
Exception
{
TrustManager
[]
managers
=
null
;
if
(
trustStore
!=
null
)
{
if
(
isTrustAll
())
{
managers
=
TRUST_ALL_CERTS
;
}
// Revocation checking is only supported for PKIX algorithm
else
if
(
isValidatePeerCerts
()
&&
"PKIX"
.
equalsIgnoreCase
(
getTrustManagerFactoryAlgorithm
()))
{
PKIXBuilderParameters
pbParams
=
newPKIXBuilderParameters
(
trustStore
,
crls
);
TrustManagerFactory
trustManagerFactory
=
TrustManagerFactory
.
getInstance
(
_trustManagerFactoryAlgorithm
);
trustManagerFactory
.
init
(
new
CertPathTrustManagerParameters
(
pbParams
));
managers
=
trustManagerFactory
.
getTrustManagers
();
}
else
{
TrustManagerFactory
trustManagerFactory
=
TrustManagerFactory
.
getInstance
(
_trustManagerFactoryAlgorithm
);
trustManagerFactory
.
init
(
trustStore
);
managers
=
trustManagerFactory
.
getTrustManagers
();
}
}
return
managers
;
}
}
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment