import ;
import ;
import ;
import ;
import ;
import ;
import ;
import ;
import ;
import ;
import .X509Certificate;
import ;
import ;
import ;
import ;
import ;
import ;
import .X509TrustManager;
public class InstallCert {
public static void main(String[] args) throws Exception {
String host;
int port;
char[] passphrase;
if (( == 1) || ( == 2)) {
String[] c = args[0].split(":");
host = c[0];
port = ( == 1) ? 443 : (c[1]);
String p = ( == 1) ? "changeit" : args[1];
passphrase = ();
} else {
.println("Usage: java InstallCert <host>[:port] [passphrase]");
return;
}
File file = new File("jssecacerts");
if (() == false) {
char SEP = ;
File dir = new File(("") + SEP + "lib"
+ SEP + "security");
file = new File(dir, "jssecacerts");
if (() == false) {
file = new File(dir, "cacerts");
}
}
("Loading KeyStore " + file + "...");
InputStream in = new FileInputStream(file);
KeyStore ks = (());
(in, passphrase);
();
SSLContext context = ("TLS");
TrustManagerFactory tmf = TrustManagerFactory
.getInstance(());
(ks);
X509TrustManager defaultTrustManager = (X509TrustManager) tmf
.getTrustManagers()[0];
SavingTrustManager tm = new SavingTrustManager(defaultTrustManager);
(null, new TrustManager[] { tm }, null);
SSLSocketFactory factory = ();
.println("Opening connection to " + host + ":" + port + "...");
SSLSocket socket = (SSLSocket) (host, port);
(10000);
try {
("Starting SSL handshake...");
();
();
();
("No errors, certificate is already trusted");
} catch (SSLException e) {
();
();
}
X509Certificate[] chain = ;
if (chain == null) {
("Could not obtain server certificate chain");
return;
}
BufferedReader reader = new BufferedReader(new InputStreamReader(
));
();
("Server sent " + + " certificate(s):");
();
MessageDigest sha1 = ("SHA1");
MessageDigest md5 = ("MD5");
for (int i = 0; i < ; i++) {
X509Certificate cert = chain[i];
(" " + (i + 1) + " Subject "
+ ());
(" Issuer " + ());
(());
(" sha1 " + toHexString(()));
(());
(" md5 " + toHexString(()));
();
}
.println("Enter certificate to add to trusted keystore or 'q' to quit: [1]");
String line = ().trim();
int k;
try {
k = (() == 0) ? 0 : (line) - 1;
} catch (NumberFormatException e) {
("KeyStore not changed");
return;
}
X509Certificate cert = chain[k];
String alias = host + "-" + (k + 1);
(alias, cert);
OutputStream out = new FileOutputStream("jssecacerts");
(out, passphrase);
();
();
(cert);
();
.println("Added certificate to keystore 'jssecacerts' using alias '"
+ alias + "'");
}
private static final char[] HEXDIGITS = "0123456789abcdef".toCharArray();
private static String toHexString(byte[] bytes) {
StringBuilder sb = new StringBuilder( * 3);
for (int b : bytes) {
b &= 0xff;
(HEXDIGITS[b >> 4]);
(HEXDIGITS[b & 15]);
(' ');
}
return ();
}
private static class SavingTrustManager implements X509TrustManager {
private final X509TrustManager tm;
private X509Certificate[] chain;
SavingTrustManager(X509TrustManager tm) {
this.tm = tm;
}
public X509Certificate[] getAcceptedIssuers() {
throw new UnsupportedOperationException();
}
public void checkClientTrusted(X509Certificate[] chain, String authType)
throws CertificateException {
throw new UnsupportedOperationException();
}
public void checkServerTrusted(X509Certificate[] chain, String authType)
throws CertificateException {
this.chain = chain;
(chain, authType);
}
}
}