|
|
65e86d |
diff --git a/jdk/src/share/classes/sun/security/ssl/TrustStoreManager.java b/jdk/src/share/classes/sun/security/ssl/TrustStoreManager.java
|
|
|
65e86d |
index e7b4763db53..e8ec8467e6a 100644
|
|
|
65e86d |
--- a/jdk/src/share/classes/sun/security/ssl/TrustStoreManager.java
|
|
|
65e86d |
+++ b/jdk/src/share/classes/sun/security/ssl/TrustStoreManager.java
|
|
|
65e86d |
@@ -31,6 +31,7 @@ import java.security.*;
|
|
|
65e86d |
import java.security.cert.*;
|
|
|
65e86d |
import java.util.*;
|
|
|
65e86d |
import sun.security.action.*;
|
|
|
65e86d |
+import sun.security.tools.KeyStoreUtil;
|
|
|
65e86d |
import sun.security.validator.TrustStoreUtil;
|
|
|
65e86d |
|
|
|
65e86d |
/**
|
|
|
65e86d |
@@ -68,7 +69,7 @@ final class TrustStoreManager {
|
|
|
65e86d |
* The preference of the default trusted KeyStore is:
|
|
|
65e86d |
* javax.net.ssl.trustStore
|
|
|
65e86d |
* jssecacerts
|
|
|
65e86d |
- * cacerts
|
|
|
65e86d |
+ * cacerts (system and local)
|
|
|
65e86d |
*/
|
|
|
65e86d |
private static final class TrustStoreDescriptor {
|
|
|
65e86d |
private static final String fileSep = File.separator;
|
|
|
65e86d |
@@ -76,7 +77,7 @@ final class TrustStoreManager {
|
|
|
65e86d |
GetPropertyAction.privilegedGetProperty("java.home") +
|
|
|
65e86d |
fileSep + "lib" + fileSep + "security";
|
|
|
65e86d |
private static final String defaultStore =
|
|
|
65e86d |
- defaultStorePath + fileSep + "cacerts";
|
|
|
65e86d |
+ KeyStoreUtil.getCacertsKeyStoreFile().getPath();
|
|
|
65e86d |
private static final String jsseDefaultStore =
|
|
|
65e86d |
defaultStorePath + fileSep + "jssecacerts";
|
|
|
65e86d |
|
|
|
65e86d |
@@ -139,6 +140,10 @@ final class TrustStoreManager {
|
|
|
65e86d |
String storePropPassword = System.getProperty(
|
|
|
65e86d |
"javax.net.ssl.trustStorePassword", "");
|
|
|
65e86d |
|
|
|
65e86d |
+ if (SSLLogger.isOn && SSLLogger.isOn("trustmanager")) {
|
|
|
65e86d |
+ SSLLogger.fine("Default store: " + defaultStore);
|
|
|
65e86d |
+ }
|
|
|
65e86d |
+
|
|
|
65e86d |
String temporaryName = "";
|
|
|
65e86d |
File temporaryFile = null;
|
|
|
65e86d |
long temporaryTime = 0L;
|
|
|
65e86d |
@@ -146,21 +151,22 @@ final class TrustStoreManager {
|
|
|
65e86d |
String[] fileNames =
|
|
|
65e86d |
new String[] {storePropName, defaultStore};
|
|
|
65e86d |
for (String fileName : fileNames) {
|
|
|
65e86d |
- File f = new File(fileName);
|
|
|
65e86d |
- if (f.isFile() && f.canRead()) {
|
|
|
65e86d |
- temporaryName = fileName;;
|
|
|
65e86d |
- temporaryFile = f;
|
|
|
65e86d |
- temporaryTime = f.lastModified();
|
|
|
65e86d |
-
|
|
|
65e86d |
- break;
|
|
|
65e86d |
- }
|
|
|
65e86d |
-
|
|
|
65e86d |
- // Not break, the file is inaccessible.
|
|
|
65e86d |
- if (SSLLogger.isOn &&
|
|
|
65e86d |
+ if (fileName != null && !"".equals(fileName)) {
|
|
|
65e86d |
+ File f = new File(fileName);
|
|
|
65e86d |
+ if (f.isFile() && f.canRead()) {
|
|
|
65e86d |
+ temporaryName = fileName;;
|
|
|
65e86d |
+ temporaryFile = f;
|
|
|
65e86d |
+ temporaryTime = f.lastModified();
|
|
|
65e86d |
+
|
|
|
65e86d |
+ break;
|
|
|
65e86d |
+ }
|
|
|
65e86d |
+ // Not break, the file is inaccessible.
|
|
|
65e86d |
+ if (SSLLogger.isOn &&
|
|
|
65e86d |
SSLLogger.isOn("trustmanager")) {
|
|
|
65e86d |
- SSLLogger.fine(
|
|
|
65e86d |
- "Inaccessible trust store: " +
|
|
|
65e86d |
- storePropName);
|
|
|
65e86d |
+ SSLLogger.fine(
|
|
|
65e86d |
+ "Inaccessible trust store: " +
|
|
|
65e86d |
+ fileName);
|
|
|
65e86d |
+ }
|
|
|
65e86d |
}
|
|
|
65e86d |
}
|
|
|
65e86d |
} else {
|
|
|
65e86d |
diff --git a/jdk/src/share/classes/sun/security/tools/KeyStoreUtil.java b/jdk/src/share/classes/sun/security/tools/KeyStoreUtil.java
|
|
|
65e86d |
index fcc77786da1..f554f83a8b4 100644
|
|
|
65e86d |
--- a/jdk/src/share/classes/sun/security/tools/KeyStoreUtil.java
|
|
|
65e86d |
+++ b/jdk/src/share/classes/sun/security/tools/KeyStoreUtil.java
|
|
|
65e86d |
@@ -33,7 +33,10 @@ import java.io.InputStreamReader;
|
|
|
65e86d |
|
|
|
65e86d |
import java.net.URL;
|
|
|
65e86d |
|
|
|
65e86d |
+import java.security.AccessController;
|
|
|
65e86d |
import java.security.KeyStore;
|
|
|
65e86d |
+import java.security.PrivilegedAction;
|
|
|
65e86d |
+import java.security.Security;
|
|
|
65e86d |
|
|
|
65e86d |
import java.security.cert.X509Certificate;
|
|
|
65e86d |
import java.text.Collator;
|
|
|
65e86d |
@@ -54,6 +57,33 @@ public class KeyStoreUtil {
|
|
|
65e86d |
|
|
|
65e86d |
private static final String JKS = "jks";
|
|
|
65e86d |
|
|
|
65e86d |
+ private static final String PROP_NAME = "security.systemCACerts";
|
|
|
65e86d |
+
|
|
|
65e86d |
+ /**
|
|
|
65e86d |
+ * Returns the value of the security property propName, which can be overridden
|
|
|
65e86d |
+ * by a system property of the same name
|
|
|
65e86d |
+ *
|
|
|
65e86d |
+ * @param propName the name of the system or security property
|
|
|
65e86d |
+ * @return the value of the system or security property
|
|
|
65e86d |
+ */
|
|
|
65e86d |
+ @SuppressWarnings("removal")
|
|
|
65e86d |
+ public static String privilegedGetOverridable(String propName) {
|
|
|
65e86d |
+ if (System.getSecurityManager() == null) {
|
|
|
65e86d |
+ return getOverridableProperty(propName);
|
|
|
65e86d |
+ } else {
|
|
|
65e86d |
+ return AccessController.doPrivileged((PrivilegedAction<String>) () -> getOverridableProperty(propName));
|
|
|
65e86d |
+ }
|
|
|
65e86d |
+ }
|
|
|
65e86d |
+
|
|
|
65e86d |
+ private static String getOverridableProperty(String propName) {
|
|
|
65e86d |
+ String val = System.getProperty(propName);
|
|
|
65e86d |
+ if (val == null) {
|
|
|
65e86d |
+ return Security.getProperty(propName);
|
|
|
65e86d |
+ } else {
|
|
|
65e86d |
+ return val;
|
|
|
65e86d |
+ }
|
|
|
65e86d |
+ }
|
|
|
65e86d |
+
|
|
|
65e86d |
/**
|
|
|
65e86d |
* Returns true if the certificate is self-signed, false otherwise.
|
|
|
65e86d |
*/
|
|
|
65e86d |
@@ -96,20 +126,38 @@ public class KeyStoreUtil {
|
|
|
65e86d |
}
|
|
|
65e86d |
}
|
|
|
65e86d |
|
|
|
65e86d |
+ /**
|
|
|
65e86d |
+ * Returns the path to the cacerts DB
|
|
|
65e86d |
+ */
|
|
|
65e86d |
+ public static File getCacertsKeyStoreFile()
|
|
|
65e86d |
+ {
|
|
|
65e86d |
+ String sep = File.separator;
|
|
|
65e86d |
+ File file = null;
|
|
|
65e86d |
+ /* Check system cacerts DB first, preferring system property over security property */
|
|
|
65e86d |
+ String systemDB = privilegedGetOverridable(PROP_NAME);
|
|
|
65e86d |
+ if (systemDB != null && !"".equals(systemDB)) {
|
|
|
65e86d |
+ file = new File(systemDB);
|
|
|
65e86d |
+ }
|
|
|
65e86d |
+ if (file == null || !file.exists()) {
|
|
|
65e86d |
+ file = new File(System.getProperty("java.home") + sep
|
|
|
65e86d |
+ + "lib" + sep + "security" + sep
|
|
|
65e86d |
+ + "cacerts");
|
|
|
65e86d |
+ }
|
|
|
65e86d |
+ if (file.exists()) {
|
|
|
65e86d |
+ return file;
|
|
|
65e86d |
+ }
|
|
|
65e86d |
+ return null;
|
|
|
65e86d |
+ }
|
|
|
65e86d |
+
|
|
|
65e86d |
/**
|
|
|
65e86d |
* Returns the keystore with the configured CA certificates.
|
|
|
65e86d |
*/
|
|
|
65e86d |
public static KeyStore getCacertsKeyStore()
|
|
|
65e86d |
throws Exception
|
|
|
65e86d |
{
|
|
|
65e86d |
- String sep = File.separator;
|
|
|
65e86d |
- File file = new File(System.getProperty("java.home") + sep
|
|
|
65e86d |
- + "lib" + sep + "security" + sep
|
|
|
65e86d |
- + "cacerts");
|
|
|
65e86d |
- if (!file.exists()) {
|
|
|
65e86d |
- return null;
|
|
|
65e86d |
- }
|
|
|
65e86d |
KeyStore caks = null;
|
|
|
65e86d |
+ File file = getCacertsKeyStoreFile();
|
|
|
65e86d |
+ if (file == null) { return null; }
|
|
|
65e86d |
try (FileInputStream fis = new FileInputStream(file)) {
|
|
|
65e86d |
caks = KeyStore.getInstance(JKS);
|
|
|
65e86d |
caks.load(fis, null);
|
|
|
65e86d |
diff --git a/jdk/src/share/lib/security/java.security-aix b/jdk/src/share/lib/security/java.security-aix
|
|
|
65e86d |
index bfe0c593adb..093bc09bf95 100644
|
|
|
65e86d |
--- a/jdk/src/share/lib/security/java.security-aix
|
|
|
65e86d |
+++ b/jdk/src/share/lib/security/java.security-aix
|
|
|
65e86d |
@@ -294,6 +294,13 @@ security.overridePropertiesFile=true
|
|
|
65e86d |
#
|
|
|
65e86d |
security.useSystemPropertiesFile=false
|
|
|
65e86d |
|
|
|
65e86d |
+#
|
|
|
65e86d |
+# Specifies the system certificate store
|
|
|
65e86d |
+# This property may be disabled using
|
|
|
65e86d |
+# -Djava.security.disableSystemCACerts=true
|
|
|
65e86d |
+#
|
|
|
65e86d |
+security.systemCACerts=${java.home}/lib/security/cacerts
|
|
|
65e86d |
+
|
|
|
65e86d |
#
|
|
|
65e86d |
# Determines the default key and trust manager factory algorithms for
|
|
|
65e86d |
# the javax.net.ssl package.
|
|
|
65e86d |
diff --git a/jdk/src/share/lib/security/java.security-linux b/jdk/src/share/lib/security/java.security-linux
|
|
|
65e86d |
index 9d1c8fe8a8e..16c9281cc1f 100644
|
|
|
65e86d |
--- a/jdk/src/share/lib/security/java.security-linux
|
|
|
65e86d |
+++ b/jdk/src/share/lib/security/java.security-linux
|
|
|
65e86d |
@@ -307,6 +307,13 @@ security.overridePropertiesFile=true
|
|
|
65e86d |
#
|
|
|
65e86d |
security.useSystemPropertiesFile=false
|
|
|
65e86d |
|
|
|
65e86d |
+#
|
|
|
65e86d |
+# Specifies the system certificate store
|
|
|
65e86d |
+# This property may be disabled using
|
|
|
65e86d |
+# -Djava.security.disableSystemCACerts=true
|
|
|
65e86d |
+#
|
|
|
65e86d |
+security.systemCACerts=${java.home}/lib/security/cacerts
|
|
|
65e86d |
+
|
|
|
65e86d |
#
|
|
|
65e86d |
# Determines the default key and trust manager factory algorithms for
|
|
|
65e86d |
# the javax.net.ssl package.
|
|
|
65e86d |
diff --git a/jdk/src/share/lib/security/java.security-macosx b/jdk/src/share/lib/security/java.security-macosx
|
|
|
65e86d |
index 19047c61097..43e034cdeaf 100644
|
|
|
65e86d |
--- a/jdk/src/share/lib/security/java.security-macosx
|
|
|
65e86d |
+++ b/jdk/src/share/lib/security/java.security-macosx
|
|
|
65e86d |
@@ -297,6 +297,13 @@ security.overridePropertiesFile=true
|
|
|
65e86d |
#
|
|
|
65e86d |
security.useSystemPropertiesFile=false
|
|
|
65e86d |
|
|
|
65e86d |
+#
|
|
|
65e86d |
+# Specifies the system certificate store
|
|
|
65e86d |
+# This property may be disabled using
|
|
|
65e86d |
+# -Djava.security.disableSystemCACerts=true
|
|
|
65e86d |
+#
|
|
|
65e86d |
+security.systemCACerts=${java.home}/lib/security/cacerts
|
|
|
65e86d |
+
|
|
|
65e86d |
#
|
|
|
65e86d |
# Determines the default key and trust manager factory algorithms for
|
|
|
65e86d |
# the javax.net.ssl package.
|
|
|
65e86d |
diff --git a/jdk/src/share/lib/security/java.security-solaris b/jdk/src/share/lib/security/java.security-solaris
|
|
|
65e86d |
index 7eda556ae13..325937e97fb 100644
|
|
|
65e86d |
--- a/jdk/src/share/lib/security/java.security-solaris
|
|
|
65e86d |
+++ b/jdk/src/share/lib/security/java.security-solaris
|
|
|
65e86d |
@@ -295,6 +295,13 @@ security.overridePropertiesFile=true
|
|
|
65e86d |
#
|
|
|
65e86d |
security.useSystemPropertiesFile=false
|
|
|
65e86d |
|
|
|
65e86d |
+#
|
|
|
65e86d |
+# Specifies the system certificate store
|
|
|
65e86d |
+# This property may be disabled using
|
|
|
65e86d |
+# -Djava.security.disableSystemCACerts=true
|
|
|
65e86d |
+#
|
|
|
65e86d |
+security.systemCACerts=${java.home}/lib/security/cacerts
|
|
|
65e86d |
+
|
|
|
65e86d |
#
|
|
|
65e86d |
# Determines the default key and trust manager factory algorithms for
|
|
|
65e86d |
# the javax.net.ssl package.
|
|
|
65e86d |
diff --git a/jdk/src/share/lib/security/java.security-windows b/jdk/src/share/lib/security/java.security-windows
|
|
|
65e86d |
index dfa1a669aa9..92ef777e065 100644
|
|
|
65e86d |
--- a/jdk/src/share/lib/security/java.security-windows
|
|
|
65e86d |
+++ b/jdk/src/share/lib/security/java.security-windows
|
|
|
65e86d |
@@ -297,6 +297,13 @@ security.overridePropertiesFile=true
|
|
|
65e86d |
#
|
|
|
65e86d |
security.useSystemPropertiesFile=false
|
|
|
65e86d |
|
|
|
65e86d |
+#
|
|
|
65e86d |
+# Specifies the system certificate store
|
|
|
65e86d |
+# This property may be disabled using
|
|
|
65e86d |
+# -Djava.security.disableSystemCACerts=true
|
|
|
65e86d |
+#
|
|
|
65e86d |
+security.systemCACerts=${java.home}/lib/security/cacerts
|
|
|
65e86d |
+
|
|
|
65e86d |
#
|
|
|
65e86d |
# Determines the default key and trust manager factory algorithms for
|
|
|
65e86d |
# the javax.net.ssl package.
|