Package org.opends.server.crypto
Class CryptoManagerImpl
- java.lang.Object
-
- org.opends.server.crypto.CryptoManagerImpl
-
- All Implemented Interfaces:
ConfigurationChangeListener<CryptoManagerCfg>,CryptoManager
public class CryptoManagerImpl extends Object implements ConfigurationChangeListener<CryptoManagerCfg>, CryptoManager
This class implements the Directory Server cryptographic framework, which is described in the CrytpoManager design document.CryptoManagerimplements inter-OpenDJ-instance authentication and authorization using the ADS-based truststore, and secret key distribution. The interface also provides methods for hashing, encryption, and other kinds of cryptographic operations.Note that it also contains methods for compressing and uncompressing data: while these are not strictly cryptographic operations, there are a lot of similarities and it is conceivable at some point that accelerated compression may be available just as it is for cryptographic operations.
Other components of CryptoManager:
-
-
Constructor Summary
Constructors Constructor Description CryptoManagerImpl(ServerContext serverContext, CryptoManagerCfg config)Creates a new instance of this crypto manager object from a given configuration, plus some static member initialization.
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description ConfigChangeResultapplyConfigurationChange(CryptoManagerCfg cfg)Applies the configuration changes to this change listener.intcompress(byte[] src, int srcOff, int srcLen, byte[] dst, int dstOff, int dstLen)Attempts to compress the data in the provided source array into the given destination array.byte[]decrypt(byte[] data)Decrypts the data in the provided byte array using cipher specified by the key identifier prologue to the data.byte[]digest(byte[] data)Retrieves a byte array containing a message digest based on the provided data, using the preferred digest algorithm.byte[]digest(InputStream inputStream)Retrieves a byte array containing a message digest based on the data read from the provided input stream, using the preferred digest algorithm.byte[]digest(String digestAlgorithm, byte[] data)Retrieves a byte array containing a message digest based on the provided data, using the requested digest algorithm.byte[]digest(String digestAlgorithm, InputStream inputStream)Retrieves a byte array containing a message digest based on the data read from the provided input stream, using the requested digest algorithm.byte[]encrypt(byte[] data)Encrypts the data in the provided byte array using the preferred cipher transformation.byte[]encrypt(String cipherTransformation, int keyLengthBits, byte[] data)Encrypts the data in the provided byte array using the requested cipher algorithm.voidensureCipherKeyIsAvailable(String cipherTransformation, int cipherKeyLength)Ensures that a key exists for the provided cipher transformation and key length.CipherInputStreamgetCipherInputStream(InputStream inputStream)Returns a CipherInputStream instantiated with a cipher corresponding to the key identifier prologue to the data.CipherOutputStreamgetCipherOutputStream(OutputStream outputStream)Writes encrypted data to the provided output stream using the preferred cipher transformation.CipherOutputStreamgetCipherOutputStream(String cipherTransformation, int keyLengthBits, OutputStream outputStream)Writes encrypted data to the provided output stream using the requested cipher transformation.static StringgetInstanceKeyID(byte[] instanceKeyCertificate)Return the identifier of an instance's instance key.MacgetMacEngine(String keyEntryID)For the specified key entry identifier, instantiate a MAC engine.StringgetMacEngineKeyEntryID()For the current preferred MAC algorithm and key length, return the identifier of the corresponding key entry.StringgetMacEngineKeyEntryID(String macAlgorithm, int keyLengthBits)For the specified MAC algorithm and key length, return the identifier of the corresponding key entry.MessageDigestgetMessageDigest(String digestAlgorithm)Retrieves aMessageDigestobject that may be used to generate digests using the specified algorithm.MessageDigestgetPreferredMessageDigest()Retrieves aMessageDigestobject that may be used to generate digests using the preferred digest algorithm.StringgetPreferredMessageDigestAlgorithm()Retrieves the name of the preferred message digest algorithm.SortedSet<String>getSslCertNicknames()Get the names of the local certificates to use for SSL.SortedSet<String>getSslCipherSuites()Get the set of enabled SSL cipher suites.SSLContextgetSslContext(String componentName, SortedSet<String> sslCertNicknames)Create an SSL context that may be used for communication to another ADS component.SortedSet<String>getSslProtocols()Get the set of enabled SSL protocols.booleanisConfigurationChangeAcceptable(CryptoManagerCfg cfg, List<org.forgerock.i18n.LocalizableMessage> unacceptableReasons)Indicates whether the proposed change to the configuration is acceptable to this change listener.booleanisSslEncryption()Determine whether SSL encryption is enabled.CryptoSuitenewCryptoSuite(String cipherTransformation, int cipherKeyLength, boolean encrypt)Return a newCryptoSuitefor the cipher and key.intuncompress(byte[] src, int srcOff, int srcLen, byte[] dst, int dstOff, int dstLen)Attempts to uncompress the data in the provided source array into the given destination array.
-
-
-
Constructor Detail
-
CryptoManagerImpl
public CryptoManagerImpl(ServerContext serverContext, CryptoManagerCfg config) throws ConfigException, InitializationException
Creates a new instance of this crypto manager object from a given configuration, plus some static member initialization.- Parameters:
serverContext- The server context.config- The configuration of this crypto manager.- Throws:
ConfigException- If a problem occurs while creating thisCryptoManagerthat is a result of a problem in the configuration.InitializationException- If a problem occurs while creating thisCryptoManagerthat is not the result of a problem in the configuration.
-
-
Method Detail
-
isConfigurationChangeAcceptable
public boolean isConfigurationChangeAcceptable(CryptoManagerCfg cfg, List<org.forgerock.i18n.LocalizableMessage> unacceptableReasons)
Description copied from interface:ConfigurationChangeListenerIndicates whether the proposed change to the configuration is acceptable to this change listener.- Specified by:
isConfigurationChangeAcceptablein interfaceConfigurationChangeListener<CryptoManagerCfg>- Parameters:
cfg- The new configuration containing the changes.unacceptableReasons- A list that can be used to hold messages about why the provided configuration is not acceptable.- Returns:
- Returns
trueif the proposed change is acceptable, orfalseif it is not.
-
applyConfigurationChange
public ConfigChangeResult applyConfigurationChange(CryptoManagerCfg cfg)
Description copied from interface:ConfigurationChangeListenerApplies the configuration changes to this change listener.- Specified by:
applyConfigurationChangein interfaceConfigurationChangeListener<CryptoManagerCfg>- Parameters:
cfg- The new configuration containing the changes.- Returns:
- Returns information about the result of changing the configuration.
-
getInstanceKeyID
public static String getInstanceKeyID(byte[] instanceKeyCertificate) throws CryptoManagerException
Return the identifier of an instance's instance key. An instance-key identifier is a hex string of the MD5 hash of an instance's instance-key public-key certificate.- Parameters:
instanceKeyCertificate- The instance key for which to return an identifier.- Returns:
- The identifier of the supplied instance key.
- Throws:
CryptoManagerException- If there is a problem computing the identifier from the instance key. TODO: Make package-private if ADSContextHelper can get keyID from ADS TODO: suffix: Issue https://opends.dev.java.net/issues/show_bug.cgi?id=2442- See Also:
getInstanceKeyID()
-
getPreferredMessageDigestAlgorithm
public String getPreferredMessageDigestAlgorithm()
Description copied from interface:CryptoManagerRetrieves the name of the preferred message digest algorithm.- Specified by:
getPreferredMessageDigestAlgorithmin interfaceCryptoManager- Returns:
- The name of the preferred message digest algorithm
-
getPreferredMessageDigest
public MessageDigest getPreferredMessageDigest() throws NoSuchAlgorithmException
Description copied from interface:CryptoManagerRetrieves aMessageDigestobject that may be used to generate digests using the preferred digest algorithm.- Specified by:
getPreferredMessageDigestin interfaceCryptoManager- Returns:
- A
MessageDigestobject that may be used to generate digests using the preferred digest algorithm. - Throws:
NoSuchAlgorithmException- If the requested algorithm is not supported or is unavailable.
-
getMessageDigest
public MessageDigest getMessageDigest(String digestAlgorithm) throws NoSuchAlgorithmException
Description copied from interface:CryptoManagerRetrieves aMessageDigestobject that may be used to generate digests using the specified algorithm.- Specified by:
getMessageDigestin interfaceCryptoManager- Parameters:
digestAlgorithm- The algorithm to use to generate the message digest.- Returns:
- A
MessageDigestobject that may be used to generate digests using the specified algorithm. - Throws:
NoSuchAlgorithmException- If the requested algorithm is not supported or is unavailable.
-
digest
public byte[] digest(byte[] data) throws NoSuchAlgorithmExceptionDescription copied from interface:CryptoManagerRetrieves a byte array containing a message digest based on the provided data, using the preferred digest algorithm.- Specified by:
digestin interfaceCryptoManager- Parameters:
data- The data to be digested.- Returns:
- A byte array containing the generated message digest.
- Throws:
NoSuchAlgorithmException- If the requested algorithm is not supported or is unavailable.
-
digest
public byte[] digest(String digestAlgorithm, byte[] data) throws NoSuchAlgorithmException
Description copied from interface:CryptoManagerRetrieves a byte array containing a message digest based on the provided data, using the requested digest algorithm.- Specified by:
digestin interfaceCryptoManager- Parameters:
digestAlgorithm- The algorithm to use to generate the message digest.data- The data to be digested.- Returns:
- A byte array containing the generated message digest.
- Throws:
NoSuchAlgorithmException- If the requested algorithm is not supported or is unavailable.
-
digest
public byte[] digest(InputStream inputStream) throws IOException, NoSuchAlgorithmException
Description copied from interface:CryptoManagerRetrieves a byte array containing a message digest based on the data read from the provided input stream, using the preferred digest algorithm. Data will be read until the end of the stream is reached.- Specified by:
digestin interfaceCryptoManager- Parameters:
inputStream- The input stream from which the data is to be read.- Returns:
- A byte array containing the generated message digest.
- Throws:
IOException- If a problem occurs while reading data from the provided stream.NoSuchAlgorithmException- If the requested algorithm is not supported or is unavailable.
-
digest
public byte[] digest(String digestAlgorithm, InputStream inputStream) throws IOException, NoSuchAlgorithmException
Description copied from interface:CryptoManagerRetrieves a byte array containing a message digest based on the data read from the provided input stream, using the requested digest algorithm. Data will be read until the end of the stream is reached.- Specified by:
digestin interfaceCryptoManager- Parameters:
digestAlgorithm- The algorithm to use to generate the message digest.inputStream- The input stream from which the data is to be read.- Returns:
- A byte array containing the generated message digest.
- Throws:
IOException- If a problem occurs while reading data from the provided stream.NoSuchAlgorithmException- If the requested algorithm is not supported or is unavailable.
-
getMacEngineKeyEntryID
public String getMacEngineKeyEntryID() throws CryptoManagerException
Description copied from interface:CryptoManagerFor the current preferred MAC algorithm and key length, return the identifier of the corresponding key entry. Note: the result (key identifier) might change across invocations, due to either of the perferred parameters changing, or because the original key was marked compromised and a replacement key generated.- Specified by:
getMacEngineKeyEntryIDin interfaceCryptoManager- Returns:
- A String representation of the identifier of a key entry corresponding to the preferred MAC algorithm and key length.
- Throws:
CryptoManagerException- In case one or more of the key parameters is invalid, or there is a problem instantiating the key entry in case it does not already exist.
-
getMacEngineKeyEntryID
public String getMacEngineKeyEntryID(String macAlgorithm, int keyLengthBits) throws CryptoManagerException
Description copied from interface:CryptoManagerFor the specified MAC algorithm and key length, return the identifier of the corresponding key entry. Note: the result (key identifier) might change across invocations, due to either of the perferred parameters changing, or because the original key was marked compromised and a replacement key generated.- Specified by:
getMacEngineKeyEntryIDin interfaceCryptoManager- Parameters:
macAlgorithm- The algorithm to use for the MAC engine.keyLengthBits- The key length in bits to use with the specified algorithm.- Returns:
- A String representation of the identifier of a key entry corresponding to the specified MAC algorithm and key length.
- Throws:
CryptoManagerException- In case one or more of the key parameters is invalid, or there is a problem instantiating the key entry in case it does not already exist.
-
getMacEngine
public Mac getMacEngine(String keyEntryID) throws CryptoManagerException
Description copied from interface:CryptoManagerFor the specified key entry identifier, instantiate a MAC engine.- Specified by:
getMacEnginein interfaceCryptoManager- Parameters:
keyEntryID- The identifier of the key entry containing the desired MAC algorithm name and key length.- Returns:
- The MAC engine instantiated with the parameters from the referenced key entry, or null if no such entry exists.
- Throws:
CryptoManagerException- In case the key entry identifier is invalid or there is a problem instantiating the MAC engine from the parameters in the referenced key entry.
-
encrypt
public byte[] encrypt(byte[] data) throws GeneralSecurityException, CryptoManagerExceptionDescription copied from interface:CryptoManagerEncrypts the data in the provided byte array using the preferred cipher transformation.- Specified by:
encryptin interfaceCryptoManager- Parameters:
data- The plain-text data to be encrypted.- Returns:
- A byte array containing the encrypted representation of the provided data.
- Throws:
GeneralSecurityException- If a problem occurs while encrypting the data.CryptoManagerException- If a problem occurs managing the encryption key or producing the cipher.
-
encrypt
public byte[] encrypt(String cipherTransformation, int keyLengthBits, byte[] data) throws GeneralSecurityException, CryptoManagerException
Description copied from interface:CryptoManagerEncrypts the data in the provided byte array using the requested cipher algorithm.- Specified by:
encryptin interfaceCryptoManager- Parameters:
cipherTransformation- The algorithm/mode/padding to use for the cipher.keyLengthBits- The length in bits of the encryption key this method is to use. Note the specified key length and transformation must be compatible.data- The plain-text data to be encrypted.- Returns:
- A byte array containing the encrypted representation of the provided data.
- Throws:
GeneralSecurityException- If a problem occurs while encrypting the data.CryptoManagerException- If a problem occurs managing the encryption key or producing the cipher.
-
getCipherOutputStream
public CipherOutputStream getCipherOutputStream(OutputStream outputStream) throws CryptoManagerException
Description copied from interface:CryptoManagerWrites encrypted data to the provided output stream using the preferred cipher transformation.- Specified by:
getCipherOutputStreamin interfaceCryptoManager- Parameters:
outputStream- The output stream to be wrapped by the returned cipher output stream.- Returns:
- The output stream wrapped with a CipherOutputStream.
- Throws:
CryptoManagerException- If a problem occurs managing the encryption key or producing the cipher.
-
getCipherOutputStream
public CipherOutputStream getCipherOutputStream(String cipherTransformation, int keyLengthBits, OutputStream outputStream) throws CryptoManagerException
Description copied from interface:CryptoManagerWrites encrypted data to the provided output stream using the requested cipher transformation.- Specified by:
getCipherOutputStreamin interfaceCryptoManager- Parameters:
cipherTransformation- The algorithm/mode/padding to use for the cipher.keyLengthBits- The length in bits of the encryption key this method will generate. Note the specified key length must be compatible with the transformation.outputStream- The output stream to be wrapped by the returned cipher output stream.- Returns:
- The output stream wrapped with a CipherOutputStream.
- Throws:
CryptoManagerException- If a problem occurs managing the encryption key or producing the cipher.
-
ensureCipherKeyIsAvailable
public void ensureCipherKeyIsAvailable(String cipherTransformation, int cipherKeyLength) throws CryptoManagerException
Description copied from interface:CryptoManagerEnsures that a key exists for the provided cipher transformation and key length. If none exists, a new one will be created.Newly created keys will be published and propagated to the replication topology.
- Specified by:
ensureCipherKeyIsAvailablein interfaceCryptoManager- Parameters:
cipherTransformation- cipher transformation string specificationcipherKeyLength- length of key in bits- Throws:
CryptoManagerException- If a problem occurs managing the encryption key
-
decrypt
public byte[] decrypt(byte[] data) throws GeneralSecurityException, CryptoManagerExceptionDescription copied from interface:CryptoManagerDecrypts the data in the provided byte array using cipher specified by the key identifier prologue to the data. cipher.- Specified by:
decryptin interfaceCryptoManager- Parameters:
data- The cipher-text data to be decrypted.- Returns:
- A byte array containing the clear-text representation of the provided data.
- Throws:
GeneralSecurityException- If a problem occurs while encrypting the data.CryptoManagerException- If a problem occurs reading the key identifier or initialization vector from the data prologue, or using these values to initialize a Cipher.
-
getCipherInputStream
public CipherInputStream getCipherInputStream(InputStream inputStream) throws CryptoManagerException
Description copied from interface:CryptoManagerReturns a CipherInputStream instantiated with a cipher corresponding to the key identifier prologue to the data.- Specified by:
getCipherInputStreamin interfaceCryptoManager- Parameters:
inputStream- The input stream be wrapped with the CipherInputStream.- Returns:
- The CiperInputStream instantiated as specified.
- Throws:
CryptoManagerException- If there is a problem reading the key ID or initialization vector from the input stream, or using these values to inititalize a Cipher.
-
compress
public int compress(byte[] src, int srcOff, int srcLen, byte[] dst, int dstOff, int dstLen)Description copied from interface:CryptoManagerAttempts to compress the data in the provided source array into the given destination array. If the compressed data will fit into the destination array, then this method will return the number of bytes of compressed data in the array. Otherwise, it will return -1 to indicate that the compression was not successful. Note that if -1 is returned, then the data in the destination array should be considered invalid.- Specified by:
compressin interfaceCryptoManager- Parameters:
src- The array containing the raw data to compress.srcOff- The start offset of the source data.srcLen- The maximum number of source data bytes to compress.dst- The array into which the compressed data should be written.dstOff- The start offset of the compressed data.dstLen- The maximum number of bytes of compressed data.- Returns:
- The number of bytes of compressed data, or -1 if it was not possible to actually compress the data.
-
uncompress
public int uncompress(byte[] src, int srcOff, int srcLen, byte[] dst, int dstOff, int dstLen) throws DataFormatExceptionDescription copied from interface:CryptoManagerAttempts to uncompress the data in the provided source array into the given destination array. If the uncompressed data will fit into the given destination array, then this method will return the number of bytes of uncompressed data written into the destination buffer. Otherwise, it will return a negative value to indicate that the destination buffer was not large enough. The absolute value of that negative return value will indicate the buffer size required to fully decompress the data. Note that if a negative value is returned, then the data in the destination array should be considered invalid.- Specified by:
uncompressin interfaceCryptoManager- Parameters:
src- The array containing the raw data to compress.srcOff- The start offset of the source data.srcLen- The maximum number of source data bytes to compress.dst- The array into which the compressed data should be written.dstOff- The start offset of the compressed data.dstLen- The maximum number of bytes of compressed data.- Returns:
- A positive value containing the number of bytes of uncompressed data written into the destination buffer, or a negative value whose absolute value is the size of the destination buffer required to fully decompress the provided data.
- Throws:
DataFormatException- If a problem occurs while attempting to uncompress the data.
-
getSslContext
public SSLContext getSslContext(String componentName, SortedSet<String> sslCertNicknames) throws ConfigException
Description copied from interface:CryptoManagerCreate an SSL context that may be used for communication to another ADS component.- Specified by:
getSslContextin interfaceCryptoManager- Parameters:
componentName- Name of the component to which is associated this SSL Context.sslCertNicknames- The names of the local certificates to use, or null if none is specified.- Returns:
- A new SSL Context.
- Throws:
ConfigException- If the context could not be created.
-
getSslCertNicknames
public SortedSet<String> getSslCertNicknames()
Description copied from interface:CryptoManagerGet the names of the local certificates to use for SSL.- Specified by:
getSslCertNicknamesin interfaceCryptoManager- Returns:
- The names of the local certificates to use for SSL.
-
isSslEncryption
public boolean isSslEncryption()
Description copied from interface:CryptoManagerDetermine whether SSL encryption is enabled.- Specified by:
isSslEncryptionin interfaceCryptoManager- Returns:
- true if SSL encryption is enabled.
-
getSslProtocols
public SortedSet<String> getSslProtocols()
Description copied from interface:CryptoManagerGet the set of enabled SSL protocols.- Specified by:
getSslProtocolsin interfaceCryptoManager- Returns:
- The set of enabled SSL protocols.
-
getSslCipherSuites
public SortedSet<String> getSslCipherSuites()
Description copied from interface:CryptoManagerGet the set of enabled SSL cipher suites.- Specified by:
getSslCipherSuitesin interfaceCryptoManager- Returns:
- The set of enabled SSL cipher suites.
-
newCryptoSuite
public CryptoSuite newCryptoSuite(String cipherTransformation, int cipherKeyLength, boolean encrypt)
Description copied from interface:CryptoManagerReturn a newCryptoSuitefor the cipher and key.- Specified by:
newCryptoSuitein interfaceCryptoManager- Parameters:
cipherTransformation- cipher transformation string specificationcipherKeyLength- length of key in bitsencrypt- true if the user of the crypto suite needs encryption- Returns:
- a new
CryptoSuitefor the cipher and key
-
-