1824N/A/*
3476N/A * Copyright (c) 2009, 2011, Oracle and/or its affiliates. All rights reserved.
1824N/A * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
1824N/A *
1824N/A * This code is free software; you can redistribute it and/or modify it
1824N/A * under the terms of the GNU General Public License version 2 only, as
1824N/A * published by the Free Software Foundation.
1824N/A *
1824N/A * This code is distributed in the hope that it will be useful, but WITHOUT
1824N/A * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
1824N/A * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
1824N/A * version 2 for more details (a copy is included in the LICENSE file that
1824N/A * accompanied this code).
1824N/A *
1824N/A * You should have received a copy of the GNU General Public License version
1824N/A * 2 along with this work; if not, write to the Free Software Foundation,
1824N/A * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
1824N/A *
2362N/A * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
2362N/A * or visit www.oracle.com if you need additional information or have any
2362N/A * questions.
1824N/A */
1824N/A
5870N/A// This test case relies on updated static security property, no way to re-use
5870N/A// security property in samevm/agentvm mode.
5870N/A
1824N/A/**
1824N/A * @test
1824N/A *
3476N/A * @bug 6861062 7011497
3476N/A * @summary Disable MD2 support.
3476N/A * New CertPathValidatorException.BasicReason enum constant for
3476N/A * constrained algorithm.
5870N/A * @run main/othervm CPValidatorEndEntity
1824N/A * @author Xuelei Fan
1824N/A */
1824N/A
1824N/Aimport java.io.*;
1824N/Aimport java.net.SocketException;
1824N/Aimport java.util.*;
1824N/Aimport java.security.Security;
1824N/Aimport java.security.cert.*;
3476N/Aimport java.security.cert.CertPathValidatorException.*;
1824N/A
1824N/Apublic class CPValidatorEndEntity {
1824N/A
1824N/A // SHA1withRSA 1024
1824N/A static String trustAnchor_SHA1withRSA_1024 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIICPjCCAaegAwIBAgIBADANBgkqhkiG9w0BAQUFADAfMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTAeFw0wOTA4MDYwMTExNDRaFw0zMDA3MTcwMTExNDRa\n" +
1824N/A "MB8xCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFtcGxlMIGfMA0GCSqGSIb3DQEB\n" +
1824N/A "AQUAA4GNADCBiQKBgQC8UdC863pFk1Rvd7xUYd60+e9KsLhb6SqOfU42ZA715FcH\n" +
1824N/A "E1TRvQPmYzAnHcO04TrWZQtO6E+E2RCmeBnetBvIMVka688QkO14wnrIrf2tRodd\n" +
1824N/A "rZNZEBzkX+zyXCRo9tKEUDFf9Qze7Ilbb+Zzm9CUfu4M1Oz6iQcXRx7aM0jEAQID\n" +
1824N/A "AQABo4GJMIGGMB0GA1UdDgQWBBTn0C+xmZY/BTab4W9gBp3dGa7WgjBHBgNVHSME\n" +
1824N/A "QDA+gBTn0C+xmZY/BTab4W9gBp3dGa7WgqEjpCEwHzELMAkGA1UEBhMCVVMxEDAO\n" +
1824N/A "BgNVBAoTB0V4YW1wbGWCAQAwDwYDVR0TAQH/BAUwAwEB/zALBgNVHQ8EBAMCAgQw\n" +
1824N/A "DQYJKoZIhvcNAQEFBQADgYEAiCXL2Yp4ruyRXAIJ8zBEaPC9oV2agqgbSbly2z8z\n" +
1824N/A "Ik5SeSRysP+GHBpb8uNyANJnQKv+T0GrJiTLMBjKCOiJl6xzk3EZ2wbQB6G/SQ9+\n" +
1824N/A "UWcsXSC8oGSEPpkj5In/9/UbuUIfT9H8jmdyLNKQvlqgq6kyfnskME7ptGgT95Hc\n" +
1824N/A "tas=\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // SHA1withRSA 512
1824N/A static String trustAnchor_SHA1withRSA_512 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIIBuTCCAWOgAwIBAgIBADANBgkqhkiG9w0BAQUFADAfMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTAeFw0wOTA4MDYwMTExNDRaFw0zMDA3MTcwMTExNDRa\n" +
1824N/A "MB8xCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFtcGxlMFwwDQYJKoZIhvcNAQEB\n" +
1824N/A "BQADSwAwSAJBAM0Kn4ieCdCHsrm78ZMMN4jQEEEqACAMKB7O8j9g4gfz2oAfmHwv\n" +
1824N/A "7JH/hZ0Xen1zUmBbwe+e2J5D/4Fisp9Bn98CAwEAAaOBiTCBhjAdBgNVHQ4EFgQU\n" +
1824N/A "g4Kwd47hdNQBp8grZsRJ5XvhvxAwRwYDVR0jBEAwPoAUg4Kwd47hdNQBp8grZsRJ\n" +
1824N/A "5XvhvxChI6QhMB8xCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFtcGxlggEAMA8G\n" +
1824N/A "A1UdEwEB/wQFMAMBAf8wCwYDVR0PBAQDAgIEMA0GCSqGSIb3DQEBBQUAA0EAn77b\n" +
1824N/A "FJx+HvyRvjZYCzMjnUct3Ql4iLOkURYDh93J5TXi/l9ajvAMEuwzYj0qZ+Ktm/ia\n" +
1824N/A "U5r+8B9nzx+j2Zh3kw==\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // SHA1withRSA 1024 signed with RSA 1024
1824N/A static String intermediate_SHA1withRSA_1024_1024 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIICUDCCAbmgAwIBAgIBAjANBgkqhkiG9w0BAQUFADAfMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTAeFw0wOTA4MDYwMTExNDhaFw0yOTA0MjMwMTExNDha\n" +
1824N/A "MDExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFtcGxlMRAwDgYDVQQLEwdDbGFz\n" +
1824N/A "cy0xMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCVOqnlZspyAEr90ELFaUo8\n" +
1824N/A "BF0O2Kn0yTdUeyiLOth4RA3qxWrjxJq45VmEBjZpEzPHfnp3PhnfmLcLfhoPONFg\n" +
1824N/A "bcHzlkj75ZaKCgHoyV456fMBmj348fcoUkH2WdSQ82pmxHOiHqquYNUSTimFIq82\n" +
1824N/A "AayhbKqDmhfx5lJdYNqd5QIDAQABo4GJMIGGMB0GA1UdDgQWBBTfWD9mRTppcUAl\n" +
1824N/A "UqGuu/R5t8CB5jBHBgNVHSMEQDA+gBTn0C+xmZY/BTab4W9gBp3dGa7WgqEjpCEw\n" +
1824N/A "HzELMAkGA1UEBhMCVVMxEDAOBgNVBAoTB0V4YW1wbGWCAQAwDwYDVR0TAQH/BAUw\n" +
1824N/A "AwEB/zALBgNVHQ8EBAMCAgQwDQYJKoZIhvcNAQEFBQADgYEAHze3wAcIe84zNOoN\n" +
1824N/A "P8l9EmlVVoU30z3LB3hxq3m/dC/4gE5Z9Z8EG1wJw4qaxlTZ4dif12nbTTdofVhb\n" +
1824N/A "Bd4syjo6fcUA4q7sfg9TFpoHQ+Ap7PgjK99moMKdMy50Xy8s6FPvaVkF89s66Z6y\n" +
1824N/A "e4q7TSwe6QevGOZaL5N/iy2XGEs=\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // SHA1withRSA 1024 signed with RSA 512
1824N/A static String intermediate_SHA1withRSA_1024_512 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIICDzCCAbmgAwIBAgIBAzANBgkqhkiG9w0BAQUFADAfMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTAeFw0wOTA4MDYwMTExNDlaFw0yOTA0MjMwMTExNDla\n" +
1824N/A "MDExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFtcGxlMRAwDgYDVQQLEwdDbGFz\n" +
1824N/A "cy0xMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCVOqnlZspyAEr90ELFaUo8\n" +
1824N/A "BF0O2Kn0yTdUeyiLOth4RA3qxWrjxJq45VmEBjZpEzPHfnp3PhnfmLcLfhoPONFg\n" +
1824N/A "bcHzlkj75ZaKCgHoyV456fMBmj348fcoUkH2WdSQ82pmxHOiHqquYNUSTimFIq82\n" +
1824N/A "AayhbKqDmhfx5lJdYNqd5QIDAQABo4GJMIGGMB0GA1UdDgQWBBTfWD9mRTppcUAl\n" +
1824N/A "UqGuu/R5t8CB5jBHBgNVHSMEQDA+gBSDgrB3juF01AGnyCtmxEnle+G/EKEjpCEw\n" +
1824N/A "HzELMAkGA1UEBhMCVVMxEDAOBgNVBAoTB0V4YW1wbGWCAQAwDwYDVR0TAQH/BAUw\n" +
1824N/A "AwEB/zALBgNVHQ8EBAMCAgQwDQYJKoZIhvcNAQEFBQADQQCYNmdkONfuk07XjRze\n" +
1824N/A "WQyq2cfdae4uIdyUfa2rpgYMtSXuQW3/XrQGiz4G6WBXA2wo7folOOpAKYgvHPrm\n" +
1824N/A "w6Dd\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // SHA1withRSA 512 signed with RSA 1024
1824N/A static String intermediate_SHA1withRSA_512_1024 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIICDDCCAXWgAwIBAgIBBDANBgkqhkiG9w0BAQUFADAfMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTAeFw0wOTA4MDYwMTExNDlaFw0yOTA0MjMwMTExNDla\n" +
1824N/A "MDExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFtcGxlMRAwDgYDVQQLEwdDbGFz\n" +
1824N/A "cy0xMFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAKubXYoEHZpZkhzA9XX+NrpqJ4SV\n" +
1824N/A "lOMBoL3aWExQpJIgrUaZfbGMBBozIHBJMMayokguHbJvq4QigEgLuhfJNqsCAwEA\n" +
1824N/A "AaOBiTCBhjAdBgNVHQ4EFgQUN0CHiTYPtjyvpP2a6y6mhsZ6U40wRwYDVR0jBEAw\n" +
1824N/A "PoAU59AvsZmWPwU2m+FvYAad3Rmu1oKhI6QhMB8xCzAJBgNVBAYTAlVTMRAwDgYD\n" +
1824N/A "VQQKEwdFeGFtcGxlggEAMA8GA1UdEwEB/wQFMAMBAf8wCwYDVR0PBAQDAgIEMA0G\n" +
1824N/A "CSqGSIb3DQEBBQUAA4GBAE2VOlw5ySLT3gUzKCYEga4QPaSrf6lHHPi2g48LscEY\n" +
1824N/A "h9qQXh4nuIVugReBIEf6N49RdT+M2cgRJo4sZ3ukYLGQzxNuttL5nPSuuvrAR1oG\n" +
1824N/A "LUyzOWcUpKHbVHi6zlTt79RvTKZvLcduLutmtPtLJcM9PdiAI1wEooSgxTwZtB/Z\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // SHA1withRSA 512 signed with RSA 512
1824N/A static String intermediate_SHA1withRSA_512_512 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIIByzCCAXWgAwIBAgIBBTANBgkqhkiG9w0BAQUFADAfMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTAeFw0wOTA4MDYwMTExNDlaFw0yOTA0MjMwMTExNDla\n" +
1824N/A "MDExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFtcGxlMRAwDgYDVQQLEwdDbGFz\n" +
1824N/A "cy0xMFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAKubXYoEHZpZkhzA9XX+NrpqJ4SV\n" +
1824N/A "lOMBoL3aWExQpJIgrUaZfbGMBBozIHBJMMayokguHbJvq4QigEgLuhfJNqsCAwEA\n" +
1824N/A "AaOBiTCBhjAdBgNVHQ4EFgQUN0CHiTYPtjyvpP2a6y6mhsZ6U40wRwYDVR0jBEAw\n" +
1824N/A "PoAUg4Kwd47hdNQBp8grZsRJ5XvhvxChI6QhMB8xCzAJBgNVBAYTAlVTMRAwDgYD\n" +
1824N/A "VQQKEwdFeGFtcGxlggEAMA8GA1UdEwEB/wQFMAMBAf8wCwYDVR0PBAQDAgIEMA0G\n" +
1824N/A "CSqGSIb3DQEBBQUAA0EAoCf0Zu559qcB4xPpzqkVsYiyW49S4Yc0mmQXb1yoQgLx\n" +
1824N/A "O+DCkjG5d14+t1MsnkhB2izoQUMxQ3vDc1YnA/tEpw==\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // MD2withRSA 1024 signed with RSA 1024
1824N/A static String intermediate_MD2withRSA_1024_1024 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIICUDCCAbmgAwIBAgIBBjANBgkqhkiG9w0BAQIFADAfMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTAeFw0wOTA4MDYwMTExNDlaFw0yOTA0MjMwMTExNDla\n" +
1824N/A "MDExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFtcGxlMRAwDgYDVQQLEwdDbGFz\n" +
1824N/A "cy0xMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCVOqnlZspyAEr90ELFaUo8\n" +
1824N/A "BF0O2Kn0yTdUeyiLOth4RA3qxWrjxJq45VmEBjZpEzPHfnp3PhnfmLcLfhoPONFg\n" +
1824N/A "bcHzlkj75ZaKCgHoyV456fMBmj348fcoUkH2WdSQ82pmxHOiHqquYNUSTimFIq82\n" +
1824N/A "AayhbKqDmhfx5lJdYNqd5QIDAQABo4GJMIGGMB0GA1UdDgQWBBTfWD9mRTppcUAl\n" +
1824N/A "UqGuu/R5t8CB5jBHBgNVHSMEQDA+gBTn0C+xmZY/BTab4W9gBp3dGa7WgqEjpCEw\n" +
1824N/A "HzELMAkGA1UEBhMCVVMxEDAOBgNVBAoTB0V4YW1wbGWCAQAwDwYDVR0TAQH/BAUw\n" +
1824N/A "AwEB/zALBgNVHQ8EBAMCAgQwDQYJKoZIhvcNAQECBQADgYEAPtEjwbWuC5kc4DPc\n" +
1824N/A "Ttf/wdbD8ZCdAWzcc3XF9q1TlvwVMNk6mbfM05y6ZVsztKTkwZ4EcvFu/yIqw1EB\n" +
1824N/A "E1zlXQCaWXT3/ZMbqYZV4+mx+RUl8spUCb1tda25jnTg3mTOzB1iztm4gy903EMd\n" +
1824N/A "m8omKDKeCgcw5dR4ITQYvyxe1as=\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // MD2withRSA 1024 signed with RSA 512
1824N/A static String intermediate_MD2withRSA_1024_512 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIICDzCCAbmgAwIBAgIBBzANBgkqhkiG9w0BAQIFADAfMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTAeFw0wOTA4MDYwMTExNDlaFw0yOTA0MjMwMTExNDla\n" +
1824N/A "MDExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFtcGxlMRAwDgYDVQQLEwdDbGFz\n" +
1824N/A "cy0xMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCVOqnlZspyAEr90ELFaUo8\n" +
1824N/A "BF0O2Kn0yTdUeyiLOth4RA3qxWrjxJq45VmEBjZpEzPHfnp3PhnfmLcLfhoPONFg\n" +
1824N/A "bcHzlkj75ZaKCgHoyV456fMBmj348fcoUkH2WdSQ82pmxHOiHqquYNUSTimFIq82\n" +
1824N/A "AayhbKqDmhfx5lJdYNqd5QIDAQABo4GJMIGGMB0GA1UdDgQWBBTfWD9mRTppcUAl\n" +
1824N/A "UqGuu/R5t8CB5jBHBgNVHSMEQDA+gBSDgrB3juF01AGnyCtmxEnle+G/EKEjpCEw\n" +
1824N/A "HzELMAkGA1UEBhMCVVMxEDAOBgNVBAoTB0V4YW1wbGWCAQAwDwYDVR0TAQH/BAUw\n" +
1824N/A "AwEB/zALBgNVHQ8EBAMCAgQwDQYJKoZIhvcNAQECBQADQQBHok1v6xymtpB7N9xy\n" +
1824N/A "0OmDT27uhmzlP0eOzJvXVxj3Oi9TLQJgCUJ9122MzfRAs1E1uJTtvuu+UmI80NQx\n" +
1824N/A "KQdp\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // SHA1withRSA 1024 signed with RSA 1024
1824N/A static String endentiry_SHA1withRSA_1024_1024 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIICNzCCAaCgAwIBAgIBAjANBgkqhkiG9w0BAQUFADAxMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTEQMA4GA1UECxMHQ2xhc3MtMTAeFw0wOTA4MDYwMTEx\n" +
1824N/A "NTBaFw0yOTA0MjMwMTExNTBaMEExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFt\n" +
1824N/A "cGxlMRAwDgYDVQQLEwdDbGFzcy0xMQ4wDAYDVQQDEwVBbGljZTCBnzANBgkqhkiG\n" +
1824N/A "9w0BAQEFAAOBjQAwgYkCgYEAy6/2g3rxQzJEvTyOnBcEnZthmAD0AnP6LG8b35jt\n" +
1824N/A "vh71LHbF1FhkOT42Rfg20aBfWTMRf+FeOJBXpD4gCNjQA40vy8FaQxgYNAf7ho5v\n" +
1824N/A "z6yAEE6SG7YviE+XGcvpQo47w8c6QSQjpBzdw7JxwbVlzUT7pF8x3RnXlGhWnWv6\n" +
1824N/A "c1ECAwEAAaNPME0wCwYDVR0PBAQDAgPoMB0GA1UdDgQWBBSaXXERsow2Wm/6uT07\n" +
1824N/A "OorBleV92TAfBgNVHSMEGDAWgBTfWD9mRTppcUAlUqGuu/R5t8CB5jANBgkqhkiG\n" +
1824N/A "9w0BAQUFAAOBgQAOfIeasDg91CR3jGfuAEVKwncM1OPFmniAUcdPm74cCAyJ90Me\n" +
1824N/A "dhUElWPGoAuXGfiyZlOlGUYWqEroe/dnkmnotJjLWR+MA4ZyX3O1YI8T4W3deWcC\n" +
1824N/A "J4WMCF7mp17SaYYKX9F0AxwNJFpUkbB41IkTxPr0MmzB1871/pbY8dLAvA==\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // SHA1withRSA 1024 signed with RSA 512
1824N/A static String endentiry_SHA1withRSA_1024_512 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIIB9jCCAaCgAwIBAgIBAzANBgkqhkiG9w0BAQUFADAxMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTEQMA4GA1UECxMHQ2xhc3MtMTAeFw0wOTA4MDYwMTEx\n" +
1824N/A "NTBaFw0yOTA0MjMwMTExNTBaMEExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFt\n" +
1824N/A "cGxlMRAwDgYDVQQLEwdDbGFzcy0xMQ4wDAYDVQQDEwVBbGljZTCBnzANBgkqhkiG\n" +
1824N/A "9w0BAQEFAAOBjQAwgYkCgYEAy6/2g3rxQzJEvTyOnBcEnZthmAD0AnP6LG8b35jt\n" +
1824N/A "vh71LHbF1FhkOT42Rfg20aBfWTMRf+FeOJBXpD4gCNjQA40vy8FaQxgYNAf7ho5v\n" +
1824N/A "z6yAEE6SG7YviE+XGcvpQo47w8c6QSQjpBzdw7JxwbVlzUT7pF8x3RnXlGhWnWv6\n" +
1824N/A "c1ECAwEAAaNPME0wCwYDVR0PBAQDAgPoMB0GA1UdDgQWBBSaXXERsow2Wm/6uT07\n" +
1824N/A "OorBleV92TAfBgNVHSMEGDAWgBQ3QIeJNg+2PK+k/ZrrLqaGxnpTjTANBgkqhkiG\n" +
1824N/A "9w0BAQUFAANBADV6X+ea0ftEKXy7yKNAbdIp35893T6AVwbdclomPkeOs86OtoTG\n" +
1824N/A "1BIzWSK9QE7W6Wbf63e2RdcqoLK+DxsuwUg=\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // SHA1withRSA 512 signed with RSA 1024
1824N/A static String endentiry_SHA1withRSA_512_1024 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIIB8zCCAVygAwIBAgIBBDANBgkqhkiG9w0BAQUFADAxMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTEQMA4GA1UECxMHQ2xhc3MtMTAeFw0wOTA4MDYwMTEx\n" +
1824N/A "NTFaFw0yOTA0MjMwMTExNTFaMEExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFt\n" +
1824N/A "cGxlMRAwDgYDVQQLEwdDbGFzcy0xMQ4wDAYDVQQDEwVBbGljZTBcMA0GCSqGSIb3\n" +
1824N/A "DQEBAQUAA0sAMEgCQQCpfQzhld7w2JhW/aRaLkmrLrc/QAsQE+J4DXioXaajsWPo\n" +
1824N/A "uMmYmuiQolb6OIY/LcivSubKM3G5PkAWoovUPIWLAgMBAAGjTzBNMAsGA1UdDwQE\n" +
1824N/A "AwID6DAdBgNVHQ4EFgQUFWuXLkf4Ji57H9ISycgWi982TUIwHwYDVR0jBBgwFoAU\n" +
1824N/A "31g/ZkU6aXFAJVKhrrv0ebfAgeYwDQYJKoZIhvcNAQEFBQADgYEAUyW8PrEdbzLu\n" +
1824N/A "B+h6UemBOJ024rYq90hJE/5wUEKPvxZ9vPEUgl+io6cGhL3cLfxfh6z5xtEGp4Tb\n" +
1824N/A "NB0Ye3Qi01FBiNDY8s3rQRrmel6VysU8u+0Oi2jmQY6vZXn/zXN5rrTLITCaSicG\n" +
1824N/A "dOMv1xLM83Ee432WWlDwKOUxhzDGpWc=\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // SHA1withRSA 512 signed with RSA 512
1824N/A static String endentiry_SHA1withRSA_512_512 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIIBsjCCAVygAwIBAgIBBTANBgkqhkiG9w0BAQUFADAxMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTEQMA4GA1UECxMHQ2xhc3MtMTAeFw0wOTA4MDYwMTEx\n" +
1824N/A "NTFaFw0yOTA0MjMwMTExNTFaMEExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFt\n" +
1824N/A "cGxlMRAwDgYDVQQLEwdDbGFzcy0xMQ4wDAYDVQQDEwVBbGljZTBcMA0GCSqGSIb3\n" +
1824N/A "DQEBAQUAA0sAMEgCQQCpfQzhld7w2JhW/aRaLkmrLrc/QAsQE+J4DXioXaajsWPo\n" +
1824N/A "uMmYmuiQolb6OIY/LcivSubKM3G5PkAWoovUPIWLAgMBAAGjTzBNMAsGA1UdDwQE\n" +
1824N/A "AwID6DAdBgNVHQ4EFgQUFWuXLkf4Ji57H9ISycgWi982TUIwHwYDVR0jBBgwFoAU\n" +
1824N/A "N0CHiTYPtjyvpP2a6y6mhsZ6U40wDQYJKoZIhvcNAQEFBQADQQBG4grtrVEHick0\n" +
1824N/A "z/6Lcl/MGyHT0c8KTXE0AMVXG1NRjAicAmYno/yDaJ9OmfymObKZKV9fF7yCW/N/\n" +
1824N/A "TMU6m7N0\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // MD2withRSA 1024 signed with RSA 1024
1824N/A static String endentiry_MD2withRSA_1024_1024 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIICNzCCAaCgAwIBAgIBBjANBgkqhkiG9w0BAQIFADAxMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTEQMA4GA1UECxMHQ2xhc3MtMTAeFw0wOTA4MDYwMTEx\n" +
1824N/A "NTFaFw0yOTA0MjMwMTExNTFaMEExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFt\n" +
1824N/A "cGxlMRAwDgYDVQQLEwdDbGFzcy0xMQ4wDAYDVQQDEwVBbGljZTCBnzANBgkqhkiG\n" +
1824N/A "9w0BAQEFAAOBjQAwgYkCgYEAy6/2g3rxQzJEvTyOnBcEnZthmAD0AnP6LG8b35jt\n" +
1824N/A "vh71LHbF1FhkOT42Rfg20aBfWTMRf+FeOJBXpD4gCNjQA40vy8FaQxgYNAf7ho5v\n" +
1824N/A "z6yAEE6SG7YviE+XGcvpQo47w8c6QSQjpBzdw7JxwbVlzUT7pF8x3RnXlGhWnWv6\n" +
1824N/A "c1ECAwEAAaNPME0wCwYDVR0PBAQDAgPoMB0GA1UdDgQWBBSaXXERsow2Wm/6uT07\n" +
1824N/A "OorBleV92TAfBgNVHSMEGDAWgBTfWD9mRTppcUAlUqGuu/R5t8CB5jANBgkqhkiG\n" +
1824N/A "9w0BAQIFAAOBgQBxKsFf8NNQcXjDoKJJSG4Rk6ikcrhiGYuUI32+XHvs6hnav1Zc\n" +
1824N/A "aJUpy7J4gMj/MnysMh/4AF9+m6zEEjuisXKUbYZhgtJxz+ukGSo163mJ8QJiAlRb\n" +
1824N/A "Iwsy81r08mlSCR6jx2YhDAUxJIPC92R5Vb4CEutB7tWTwwz7vIHq330erA==\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A // MD2withRSA 1024 signed with RSA 512
1824N/A static String endentiry_MD2withRSA_1024_512 =
1824N/A "-----BEGIN CERTIFICATE-----\n" +
1824N/A "MIIB9jCCAaCgAwIBAgIBBzANBgkqhkiG9w0BAQIFADAxMQswCQYDVQQGEwJVUzEQ\n" +
1824N/A "MA4GA1UEChMHRXhhbXBsZTEQMA4GA1UECxMHQ2xhc3MtMTAeFw0wOTA4MDYwMTEx\n" +
1824N/A "NTFaFw0yOTA0MjMwMTExNTFaMEExCzAJBgNVBAYTAlVTMRAwDgYDVQQKEwdFeGFt\n" +
1824N/A "cGxlMRAwDgYDVQQLEwdDbGFzcy0xMQ4wDAYDVQQDEwVBbGljZTCBnzANBgkqhkiG\n" +
1824N/A "9w0BAQEFAAOBjQAwgYkCgYEAy6/2g3rxQzJEvTyOnBcEnZthmAD0AnP6LG8b35jt\n" +
1824N/A "vh71LHbF1FhkOT42Rfg20aBfWTMRf+FeOJBXpD4gCNjQA40vy8FaQxgYNAf7ho5v\n" +
1824N/A "z6yAEE6SG7YviE+XGcvpQo47w8c6QSQjpBzdw7JxwbVlzUT7pF8x3RnXlGhWnWv6\n" +
1824N/A "c1ECAwEAAaNPME0wCwYDVR0PBAQDAgPoMB0GA1UdDgQWBBSaXXERsow2Wm/6uT07\n" +
1824N/A "OorBleV92TAfBgNVHSMEGDAWgBQ3QIeJNg+2PK+k/ZrrLqaGxnpTjTANBgkqhkiG\n" +
1824N/A "9w0BAQIFAANBAIX63Ypi9P71RnC/pcMbhD+wekRFsTzU593X3MC7tyBJtEXwvAZG\n" +
1824N/A "iMxXF5A+ohlr7/CrkV7ZTL8PLxnJdY5Y8rQ=\n" +
1824N/A "-----END CERTIFICATE-----";
1824N/A
1824N/A private static CertPath generateCertificatePath(String castr,
1824N/A String eestr) throws CertificateException {
1824N/A // generate certificate from cert strings
1824N/A CertificateFactory cf = CertificateFactory.getInstance("X.509");
1824N/A
1824N/A ByteArrayInputStream is;
1824N/A
1824N/A is = new ByteArrayInputStream(castr.getBytes());
1824N/A Certificate cacert = cf.generateCertificate(is);
1824N/A
1824N/A is = new ByteArrayInputStream(eestr.getBytes());
1824N/A Certificate eecert = cf.generateCertificate(is);
1824N/A
1824N/A // generate certification path
1824N/A List<Certificate> list = Arrays.asList(new Certificate[] {
1824N/A eecert, cacert});
1824N/A
1824N/A return cf.generateCertPath(list);
1824N/A }
1824N/A
1824N/A private static Set<TrustAnchor> generateTrustAnchors()
1824N/A throws CertificateException {
1824N/A // generate certificate from cert string
1824N/A CertificateFactory cf = CertificateFactory.getInstance("X.509");
1824N/A HashSet<TrustAnchor> anchors = new HashSet<TrustAnchor>();
1824N/A
1824N/A ByteArrayInputStream is =
1824N/A new ByteArrayInputStream(trustAnchor_SHA1withRSA_1024.getBytes());
1824N/A Certificate cert = cf.generateCertificate(is);
1824N/A TrustAnchor anchor = new TrustAnchor((X509Certificate)cert, null);
1824N/A anchors.add(anchor);
1824N/A
1824N/A is = new ByteArrayInputStream(trustAnchor_SHA1withRSA_512.getBytes());
1824N/A cert = cf.generateCertificate(is);
1824N/A anchor = new TrustAnchor((X509Certificate)cert, null);
1824N/A anchors.add(anchor);
1824N/A
1824N/A return anchors;
1824N/A }
1824N/A
1824N/A public static void main(String args[]) throws Exception {
5870N/A // reset the security property to make sure that the algorithms
5870N/A // and keys used in this test are not disabled.
5870N/A Security.setProperty("jdk.certpath.disabledAlgorithms", "MD2");
5870N/A
1824N/A try {
1824N/A validate(endentiry_SHA1withRSA_1024_1024,
1824N/A intermediate_SHA1withRSA_1024_1024);
1824N/A validate(endentiry_SHA1withRSA_1024_512,
1824N/A intermediate_SHA1withRSA_512_1024);
1824N/A validate(endentiry_SHA1withRSA_512_1024,
1824N/A intermediate_SHA1withRSA_1024_1024);
1824N/A validate(endentiry_SHA1withRSA_512_512,
1824N/A intermediate_SHA1withRSA_512_1024);
1824N/A } catch (CertPathValidatorException cpve) {
1824N/A throw new Exception(
1824N/A "unexpect exception, it is valid cert", cpve);
1824N/A }
1824N/A
1824N/A try {
1824N/A validate(endentiry_MD2withRSA_1024_1024,
1824N/A intermediate_SHA1withRSA_1024_1024);
1824N/A throw new Exception("expected algorithm disabled exception");
1824N/A } catch (CertPathValidatorException cpve) {
3476N/A // we may get ClassCastException here
3476N/A BasicReason reason = (BasicReason)cpve.getReason();
3476N/A if (reason != BasicReason.ALGORITHM_CONSTRAINED) {
3476N/A throw new Exception(
3476N/A "Expect to get ALGORITHM_CONSTRAINED CPVE", cpve);
3476N/A }
3476N/A
1824N/A System.out.println("Get the expected exception " + cpve);
1824N/A }
1824N/A
1824N/A try {
1824N/A validate(endentiry_MD2withRSA_1024_512,
1824N/A intermediate_SHA1withRSA_512_1024);
1824N/A throw new Exception("expected algorithm disabled exception");
1824N/A } catch (CertPathValidatorException cpve) {
3476N/A // we may get ClassCastException here
3476N/A BasicReason reason = (BasicReason)cpve.getReason();
3476N/A if (reason != BasicReason.ALGORITHM_CONSTRAINED) {
3476N/A throw new Exception(
3476N/A "Expect to get ALGORITHM_CONSTRAINED CPVE", cpve);
3476N/A }
3476N/A
1824N/A System.out.println("Get the expected exception " + cpve);
1824N/A }
1824N/A }
1824N/A
1824N/A private static void validate(String eecert, String cacert)
1824N/A throws CertPathValidatorException, Exception {
1824N/A
1824N/A CertPath path = generateCertificatePath(cacert, eecert);
1824N/A Set<TrustAnchor> anchors = generateTrustAnchors();
1824N/A
1824N/A PKIXParameters params = new PKIXParameters(anchors);
1824N/A
1824N/A // disable certificate revocation checking
1824N/A params.setRevocationEnabled(false);
1824N/A
1824N/A // set the validation time
1824N/A params.setDate(new Date(109, 9, 1)); // 2009-09-01
1824N/A
1824N/A CertPathValidator validator = CertPathValidator.getInstance("PKIX");
1824N/A
1824N/A validator.validate(path, params);
1824N/A }
1824N/A
1824N/A}