aboutsummaryrefslogtreecommitdiff
path: root/test/java/security/cert/PolicyNode/GetPolicyQualifiers.java
blob: b10951bab77e406bd4fd8035cc8e567ee60a4137 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
/*
 * Copyright 2001-2008 Sun Microsystems, Inc.  All Rights Reserved.
 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
 *
 * This code is free software; you can redistribute it and/or modify it
 * under the terms of the GNU General Public License version 2 only, as
 * published by the Free Software Foundation.
 *
 * This code is distributed in the hope that it will be useful, but WITHOUT
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
 * version 2 for more details (a copy is included in the LICENSE file that
 * accompanied this code).
 *
 * You should have received a copy of the GNU General Public License version
 * 2 along with this work; if not, write to the Free Software Foundation,
 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
 *
 * Please contact Sun Microsystems, Inc., 4150 Network Circle, Santa Clara,
 * CA 95054 USA or visit www.sun.com if you need additional information or
 * have any questions.
 */

/**
 * @test
 * @bug 4414263
 * @summary Make sure PolicyNode.getPolicyQualifiers() returns
 *      Set of PolicyQualifierInfos.
 */
import java.io.File;
import java.io.FileInputStream;
import java.security.cert.*;
import java.util.Collections;
import java.util.Iterator;
import java.util.List;
import java.util.Set;

public class GetPolicyQualifiers {

    public static void main(String[] args) throws Exception {

        CertificateFactory cf = CertificateFactory.getInstance("X.509", "SUN");
        File f = new File(System.getProperty("test.src", "."), "speech2speech");
        X509Certificate mostTrustedCaCert = (X509Certificate)
            cf.generateCertificate(new FileInputStream(f));
        Set trustAnchors = Collections.singleton(
            new TrustAnchor(mostTrustedCaCert, null));
        f = new File(System.getProperty("test.src", "."), "speech2eve");
        X509Certificate eeCert = (X509Certificate)
            cf.generateCertificate(new FileInputStream(f));
        CertPathValidator cpv = CertPathValidator.getInstance("PKIX", "SUN");
        PKIXParameters params = new PKIXParameters(trustAnchors);
        params.setPolicyQualifiersRejected(false);
        params.setRevocationEnabled(false);
        List certList = Collections.singletonList(eeCert);
        CertPath cp = cf.generateCertPath(certList);
        PKIXCertPathValidatorResult result =
            (PKIXCertPathValidatorResult) cpv.validate(cp, params);

        PolicyNode policyTree = result.getPolicyTree();
        Iterator children = policyTree.getChildren();
        PolicyNode child = (PolicyNode) children.next();
        Set policyQualifiers = child.getPolicyQualifiers();
        Iterator i = policyQualifiers.iterator();
        while (i.hasNext()) {
            Object next = i.next();
            if (!(next instanceof PolicyQualifierInfo))
                throw new Exception("not a PolicyQualifierInfo");
        }

        params.setPolicyQualifiersRejected(true);
        try {
            result = (PKIXCertPathValidatorResult) cpv.validate(cp, params);
            throw new Exception("Validation of CertPath containing critical " +
                "qualifiers should have failed when policyQualifiersRejected " +
                "flag is true");
        } catch (CertPathValidatorException cpve) {
            if (cpve.getReason() != PKIXReason.INVALID_POLICY) {
                throw new Exception("unexpected reason: " + cpve.getReason());
            }
        }
    }
}