SubjectAttributeToUserAttributeCertificateMapperTestCase.java revision ea1068c292e9b341af6d6b563cd8988a96be20a9
/*
* CDDL HEADER START
*
* The contents of this file are subject to the terms of the
* Common Development and Distribution License, Version 1.0 only
* (the "License"). You may not use this file except in compliance
* with the License.
*
* You can obtain a copy of the license at legal-notices/CDDLv1_0.txt
* See the License for the specific language governing permissions
* and limitations under the License.
*
* When distributing Covered Code, include this CDDL HEADER in each
* file and include the License file at legal-notices/CDDLv1_0.txt.
* If applicable, add the following below this CDDL HEADER, with the
* fields enclosed by brackets "[]" replaced with your own identifying
* information:
* Portions Copyright [yyyy] [name of copyright owner]
*
* CDDL HEADER END
*
*
* Copyright 2008 Sun Microsystems, Inc.
* Portions Copyright 2012-2015 ForgeRock AS
* Portions Copyright 2013 Manuel Gaupp
*/
/**
* A set of test cases for the Subject Attribute to User Attribute certificate
* mapper.
*/
extends ExtensionsTestCase
{
/**
* Ensures that the Directory Server is running.
*
* @throws Exception If an unexpected problem occurs.
*/
public void startServer()
throws Exception
{
}
/**
* Retrieves a set of invalid configurations that cannot be used to
* initialize the certificate mapper.
*
* @throws Exception If an unexpected problem occurs.
*/
public Object[][] getInvalidConfigurations()
throws Exception
{
"dn: cn=No Map Attr,cn=Certificate Mappers,cn=config",
"objectClass: top",
"objectClass: ds-cfg-certificate-mapper",
"objectClass: " +
"ds-cfg-subject-attribute-to-user-attribute-certificate-mapper",
"cn: No Map Attr",
"ds-cfg-java-class: org.opends.server.extensions." +
"SubjectAttributeToUserAttributeCertificateMapper",
"ds-cfg-enabled: true",
"",
"dn: cn=No Map Colon,cn=Certificate Mappers,cn=config",
"objectClass: top",
"objectClass: ds-cfg-certificate-mapper",
"objectClass: " +
"ds-cfg-subject-attribute-to-user-attribute-certificate-mapper",
"cn: No Map Colon",
"ds-cfg-java-class: org.opends.server.extensions." +
"SubjectAttributeToUserAttributeCertificateMapper",
"ds-cfg-enabled: true",
"ds-cfg-subject-attribute-mapping: nomapcolon",
"",
"dn: cn=No Map Cert Attr,cn=Certificate Mappers,cn=config",
"objectClass: top",
"objectClass: ds-cfg-certificate-mapper",
"objectClass: " +
"ds-cfg-subject-attribute-to-user-attribute-certificate-mapper",
"cn: No Map Cert Attr",
"ds-cfg-java-class: org.opends.server.extensions." +
"SubjectAttributeToUserAttributeCertificateMapper",
"ds-cfg-enabled: true",
"ds-cfg-subject-attribute-mapping: :cn",
"",
"dn: cn=No Map User Attr,cn=Certificate Mappers,cn=config",
"objectClass: top",
"objectClass: ds-cfg-certificate-mapper",
"objectClass: " +
"ds-cfg-subject-attribute-to-user-attribute-certificate-mapper",
"cn: No Map User Attr",
"ds-cfg-java-class: org.opends.server.extensions." +
"SubjectAttributeToUserAttributeCertificateMapper",
"ds-cfg-enabled: true",
"ds-cfg-subject-attribute-mapping: cn:",
"",
"dn: cn=Undefined User Attr,cn=Certificate Mappers,cn=config",
"objectClass: top",
"objectClass: ds-cfg-certificate-mapper",
"objectClass: " +
"ds-cfg-subject-attribute-to-user-attribute-certificate-mapper",
"cn: Undefined User Attr",
"ds-cfg-java-class: org.opends.server.extensions." +
"SubjectAttributeToUserAttributeCertificateMapper",
"ds-cfg-enabled: true",
"ds-cfg-subject-attribute-mapping: cn:undefined",
"",
"dn: cn=Duplicate Cert Attr,cn=Certificate Mappers,cn=config",
"objectClass: top",
"objectClass: ds-cfg-certificate-mapper",
"objectClass: " +
"ds-cfg-subject-attribute-to-user-attribute-certificate-mapper",
"cn: Duplicate Cert Attr",
"ds-cfg-java-class: org.opends.server.extensions." +
"SubjectAttributeToUserAttributeCertificateMapper",
"ds-cfg-enabled: true",
"ds-cfg-subject-attribute-mapping: cn:cn",
"ds-cfg-subject-attribute-mapping: cn:sn",
"",
"dn: cn=Duplicate User Attr,cn=Certificate Mappers,cn=config",
"objectClass: top",
"objectClass: ds-cfg-certificate-mapper",
"objectClass: " +
"ds-cfg-subject-attribute-to-user-attribute-certificate-mapper",
"cn: Duplicate User Attr",
"ds-cfg-java-class: org.opends.server.extensions." +
"SubjectAttributeToUserAttributeCertificateMapper",
"ds-cfg-enabled: true",
"ds-cfg-subject-attribute-mapping: cn:cn",
"ds-cfg-subject-attribute-mapping: e:cn",
"",
"dn: cn=Invalid Base DN,cn=Certificate Mappers,cn=config",
"objectClass: top",
"objectClass: ds-cfg-certificate-mapper",
"objectClass: " +
"ds-cfg-subject-attribute-to-user-attribute-certificate-mapper",
"cn: Invalid Base DN",
"ds-cfg-java-class: org.opends.server.extensions." +
"SubjectAttributeToUserAttributeCertificateMapper",
"ds-cfg-enabled: true",
"ds-cfg-subject-attribute-mapping: cn:cn",
"ds-cfg-user-base-dn: invalid",
"",
"dn: cn=Duplicate Cert Attr OID and Name,cn=Certificate Mappers,cn=config",
"objectClass: top",
"objectClass: ds-cfg-certificate-mapper",
"objectClass: " +
"ds-cfg-subject-attribute-to-user-attribute-certificate-mapper",
"cn: Duplicate Cert Attr OID and Name",
"ds-cfg-java-class: org.opends.server.extensions." +
"SubjectAttributeToUserAttributeCertificateMapper",
"ds-cfg-enabled: true",
"ds-cfg-subject-attribute-mapping: cn:cn",
"ds-cfg-subject-attribute-mapping: 2.5.4.3:displayName");
{
}
return configEntries;
}
/**
* Tests initialization with an invalid configuration.
*
* @param e The configuration entry to use to initialize the certificate
* mapper.
*
* @throws Exception If an unexpected problem occurs.
*/
expectedExceptions = { ConfigException.class,
InitializationException.class })
public void testInvalidConfigs(Entry e)
throws Exception
{
getInstance(), e);
}
/**
* Tests a successful mapping using the default configuration.
*
* @throws Exception If an unexpected problem occurs.
*/
@Test
public void testSuccessfulMappingDefaultConfig()
throws Exception
{
enableMapper();
try
{
"dn: uid=test.user,o=test",
"objectClass: top",
"objectClass: person",
"objectClass: organizationalPerson",
"objectClass: inetOrgPerson",
"objectClass: ds-certificate-user",
"uid: test.user",
"givenName: Test",
"sn: User",
"cn: Test User");
{
"--noPropertiesFile",
"-h", "127.0.0.1",
"-Z",
"-K", keyStorePath,
"-W", "password",
"-P", trustStorePath,
"-r",
"-b", "",
"-s", "base",
"(objectClass=*)"
};
}
finally
{
}
}
/**
* Tests a successful mapping using an OID for the mapping.
*
* @throws Exception If an unexpected problem occurs.
*/
@Test
public void testSuccessfulMappingUsingAnOID()
throws Exception
{
enableMapper();
try
{
"dn: uid=test.user,o=test",
"objectClass: top",
"objectClass: person",
"objectClass: organizationalPerson",
"objectClass: inetOrgPerson",
"objectClass: ds-certificate-user",
"uid: test.user",
"givenName: Test",
"sn: User",
"cn: Test User",
"mail: test@example.com");
{
"--noPropertiesFile",
"-h", "127.0.0.1",
"-Z",
"-K", keyStorePath,
"-W", "password",
"-P", trustStorePath,
"-r",
"-b", "",
"-s", "base",
"(objectClass=*)"
};
}
finally
{
}
}
/**
* Tests a successful mapping using the default configuration and a
* certificate containing a subject with an emailAddress.
*
* @throws Exception If an unexpected problem occurs.
*/
@Test
public void testSuccessfulMappingDefaultConfigEmailAddress()
throws Exception
{
enableMapper();
try
{
"dn: uid=test.user,o=test",
"objectClass: top",
"objectClass: person",
"objectClass: organizationalPerson",
"objectClass: inetOrgPerson",
"objectClass: ds-certificate-user",
"uid: test.user",
"givenName: Test",
"sn: User",
"cn: Test User",
"mail: test@example.com");
{
"--noPropertiesFile",
"-h", "127.0.0.1",
"-Z",
"-K", keyStorePath,
"-W", "password",
"-P", trustStorePath,
"-r",
"-b", "",
"-s", "base",
"(objectClass=*)"
};
}
finally
{
}
}
/**
* Tests a successful mapping with multiple attributes.
*
* @throws Exception If an unexpected problem occurs.
*/
@Test
public void testSuccessfulMappingMultipleAttributes()
throws Exception
{
enableMapper();
try
{
"dn: uid=test.user,o=test",
"objectClass: top",
"objectClass: person",
"objectClass: organizationalPerson",
"objectClass: inetOrgPerson",
"objectClass: ds-certificate-user",
"uid: test.user",
"givenName: Test",
"sn: User",
"cn: Test User",
"o: test");
{
"--noPropertiesFile",
"-h", "127.0.0.1",
"-Z",
"-K", keyStorePath,
"-W", "password",
"-P", trustStorePath,
"-r",
"-b", "",
"-s", "base",
"(objectClass=*)"
};
}
finally
{
}
}
/**
* Tests a failed mapping due to no mappable attributes in the certificate.
*
* @throws Exception If an unexpected problem occurs.
*/
@Test
public void testFailedNoMappableAttributes()
throws Exception
{
enableMapper();
try
{
"dn: uid=test.user,o=test",
"objectClass: top",
"objectClass: person",
"objectClass: organizationalPerson",
"objectClass: inetOrgPerson",
"objectClass: ds-certificate-user",
"uid: test.user",
"givenName: Test",
"sn: User",
"cn: Test User",
"o: test");
{
"--noPropertiesFile",
"-h", "127.0.0.1",
"-Z",
"-K", keyStorePath,
"-W", "password",
"-P", trustStorePath,
"-r",
"-b", "",
"-s", "base",
"(objectClass=*)"
};
}
finally
{
}
}
/**
* Tests a failed mapping due to no matching users.
*
* @throws Exception If an unexpected problem occurs.
*/
@Test
public void testFailedMappingNoMatchingUsers()
throws Exception
{
enableMapper();
try
{
"dn: uid=test.user,o=test",
"objectClass: top",
"objectClass: person",
"objectClass: organizationalPerson",
"objectClass: inetOrgPerson",
"objectClass: ds-certificate-user",
"uid: test.user",
"givenName: Test",
"sn: User",
"cn: Not Test User");
{
"--noPropertiesFile",
"-h", "127.0.0.1",
"-Z",
"-K", keyStorePath,
"-W", "password",
"-P", trustStorePath,
"-r",
"-b", "",
"-s", "base",
"(objectClass=*)"
};
}
finally
{
}
}
/**
* Tests a failed mapping due to multiple matching users.
*
* @throws Exception If an unexpected problem occurs.
*/
@Test
public void testFailedMappingMultipleMatchingUsers()
throws Exception
{
enableMapper();
try
{
"dn: uid=test.user1,o=test",
"objectClass: top",
"objectClass: person",
"objectClass: organizationalPerson",
"objectClass: inetOrgPerson",
"objectClass: ds-certificate-user",
"uid: test.user1",
"givenName: Test",
"sn: User",
"cn: Test User",
"",
"dn: uid=test.user2,o=test",
"objectClass: top",
"objectClass: person",
"objectClass: organizationalPerson",
"objectClass: inetOrgPerson",
"objectClass: ds-certificate-user",
"uid: test.user2",
"givenName: Test",
"sn: User",
"cn: Test User");
{
"--noPropertiesFile",
"-h", "127.0.0.1",
"-Z",
"-K", keyStorePath,
"-W", "password",
"-P", trustStorePath,
"-r",
"-b", "",
"-s", "base",
"(objectClass=*)"
};
}
finally
{
}
}
/**
* Tests a failed mapping when there are no users below the configured base
* DNs that match the criteria.
*
* @throws Exception If an unexpected problem occurs.
*/
@Test
public void testFailedMappingNoUserBelowBaseDNs()
throws Exception
{
enableMapper();
try
{
"dn: uid=test.user,o=test",
"objectClass: top",
"objectClass: person",
"objectClass: organizationalPerson",
"objectClass: inetOrgPerson",
"objectClass: ds-certificate-user",
"uid: test.user",
"givenName: Test",
"sn: User",
"cn: Test User");
{
"--noPropertiesFile",
"-h", "127.0.0.1",
"-Z",
"-K", keyStorePath,
"-W", "password",
"-P", trustStorePath,
"-r",
"-b", "",
"-s", "base",
"(objectClass=*)"
};
}
finally
{
}
}
/**
* Tests to ensure that an attempt to remove the subject attribute will fail.
*
* @throws Exception If an unexpected problem occurs.
*/
@Test
public void testRemoveMapAttribute()
throws Exception
{
"cn=Certificate Mappers,cn=config";
Attribute a =
"ds-cfg-subject-attribute-mapping"));
}
/**
* Tests to ensure that an attempt to set an attribute mapping with no colon
* will fail.
*
* @throws Exception If an unexpected problem occurs.
*/
public void testSetMappingNoColon()
throws Exception
{
}
/**
* Tests to ensure that an attempt to set an attribute mapping with no cert
* attribute will fail.
*
* @throws Exception If an unexpected problem occurs.
*/
public void testSetMappingNoCertAttribute()
throws Exception
{
}
/**
* Tests to ensure that an attempt to set an attribute mapping with no user
* attribute will fail.
*
* @throws Exception If an unexpected problem occurs.
*/
public void testSetMappingNoUserAttribute()
throws Exception
{
}
/**
* Tests to ensure that an attempt to set an attribute mapping with an
* undefined user attribute will fail.
*
* @throws Exception If an unexpected problem occurs.
*/
public void testSetMappingUndefinedUserAttribute()
throws Exception
{
}
/**
* Tests to ensure that an attempt to set an attribute mapping with a
* duplicate cert attribute mapping will fail.
*
* @throws Exception If an unexpected problem occurs.
*/
public void testSetMappingDuplicateCertAttribute()
throws Exception
{
}
/**
* Tests to ensure that an attempt to set an attribute mapping with a
* duplicate user attribute mapping will fail.
*
* @throws Exception If an unexpected problem occurs.
*/
public void testSetMappingDuplicateUserAttribute()
throws Exception
{
}
/**
* Tests to ensure that an attempt to set an invalid base DN will fail.
*
* @throws Exception If an unexpected problem occurs.
*/
public void testSetInvalidBaseDN()
throws Exception
{
}
/**
* Alters the configuration of the SASL EXTERNAL mechanism handler so that it
* uses the Subject Attribute to User Attribute certificate mapper.
*
* @throws Exception If an unexpected problem occurs.
*/
private void enableMapper()
throws Exception
{
"cn=Certificate Mappers,cn=config";
mapperDN)));
}
/**
* Alters the configuration of the SASL EXTERNAL mechanism handler so that it
* uses the Subject Equals DN certificate mapper.
*
* @throws Exception If an unexpected problem occurs.
*/
private void disableMapper()
throws Exception
{
mapperDN)));
}
/**
* Alters the configuration of the Subject Attribute to User Attribute
* certificate mapper so that it will use the specified set of mappings.
*
* @param mappings The specified set of mappings to use.
*
* @throws Exception If an unexpected problem occurs.
*/
throws Exception
{
"cn=Certificate Mappers,cn=config";
"ds-cfg-subject-attribute-mapping");
{
{
}
}
builder.toAttribute()));
}
/**
* Alters the configuration of the Subject Attribute to User Attribute
* certificate mapper so that it will look for matches below the specified set
* of base DNs.
*
* @param baseDNs The set of base DNs to use when mapping certificates to
* users.
*
* @throws Exception If an unexpected problem occurs.
*/
throws Exception
{
"cn=Certificate Mappers,cn=config";
{
{
}
}
builder.toAttribute()));
}
/**
* Tests a successful mapping using the default configuration, and
* verify that user can do a privileged action (read config).
* Verification for issue OPENDJ-459.
*
* @throws Exception If an unexpected problem occurs.
*/
@Test
public void testPrivilegeWithSuccessfulMappingDefaultConfig()
throws Exception
{
enableMapper();
try
{
"dn: uid=test.user,o=test",
"objectClass: top",
"objectClass: person",
"objectClass: organizationalPerson",
"objectClass: inetOrgPerson",
"objectClass: ds-certificate-user",
"uid: test.user",
"givenName: Test",
"sn: User",
"cn: Test User",
"ds-privilege-name: config-read");
{
"--noPropertiesFile",
"-h", "127.0.0.1",
"-Z",
"-K", keyStorePath,
"-W", "password",
"-P", trustStorePath,
"-r",
"-b", "cn=config",
"-s", "sub",
"(objectClass=*)"
};
}
finally
{
}
}
}