View Javadoc
1   /*
2    * Copyright (c) 2002-2014, Mairie de Paris
3    * All rights reserved.
4    *
5    * Redistribution and use in source and binary forms, with or without
6    * modification, are permitted provided that the following conditions
7    * are met:
8    *
9    *  1. Redistributions of source code must retain the above copyright notice
10   *     and the following disclaimer.
11   *
12   *  2. Redistributions in binary form must reproduce the above copyright notice
13   *     and the following disclaimer in the documentation and/or other materials
14   *     provided with the distribution.
15   *
16   *  3. Neither the name of 'Mairie de Paris' nor 'Lutece' nor the names of its
17   *     contributors may be used to endorse or promote products derived from
18   *     this software without specific prior written permission.
19   *
20   * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
21   * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22   * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23   * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDERS OR CONTRIBUTORS BE
24   * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25   * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26   * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27   * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28   * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29   * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
30   * POSSIBILITY OF SUCH DAMAGE.
31   *
32   * License 1.0
33   */
34  package fr.paris.lutece.plugins.mylutece.modules.saml.authentication.checkers;
35  
36  import fr.paris.lutece.plugins.mylutece.modules.saml.authentication.engine.BootStrap;
37  import fr.paris.lutece.plugins.mylutece.modules.saml.authentication.engine.SAMLResponseManager;
38  import fr.paris.lutece.plugins.mylutece.modules.saml.authentication.exceptions.CertificateValidationException;
39  import fr.paris.lutece.plugins.mylutece.modules.saml.authentication.exceptions.SAMLParsingException;
40  import fr.paris.lutece.portal.service.util.AppLogService;
41  
42  import java.security.cert.CertificateExpiredException;
43  import java.security.cert.CertificateNotYetValidException;
44  import java.security.cert.X509Certificate;
45  
46  import java.util.List;
47  
48  
49  public class CertificateChecker implements SAMLChecker
50  {
51      public void check( SAMLResponseManager responseManager )
52          throws CertificateValidationException, SAMLParsingException
53      {
54          List<X509Certificate> certWhiteList = BootStrap.getInstance(  ).getIdpMetaDataManager(  )
55                                                         .getCertificateWhiteList(  );
56          X509Certificate responseCert;
57          responseCert = responseManager.getSignatureCertificate(  );
58  
59          // V�rification du certificat (liste blanche)
60          if ( !certWhiteList.contains( responseCert ) )
61          {
62              String message = "Le certificat de signature n'est pas reconnu. DN Certificat=[" +
63                  responseCert.getSubjectX500Principal(  ).getName(  ) + "]";
64              AppLogService.info( message );
65              throw new CertificateValidationException( message );
66          }
67  
68          // Validite certificat
69          try
70          {
71              responseCert.checkValidity(  );
72          }
73          catch ( CertificateExpiredException e )
74          {
75              String message = "Le certificat de signature est expir�. DN Certificat=[" +
76                  responseCert.getSubjectX500Principal(  ).getName(  ) + "]";
77              AppLogService.info( message );
78              throw new CertificateValidationException( message );
79          }
80          catch ( CertificateNotYetValidException e )
81          {
82              String message = "Le certificat de signature n'est pas encore valide. DN Certificat=[" +
83                  responseCert.getSubjectX500Principal(  ).getName(  ) + "]";
84              AppLogService.info( message );
85              throw new CertificateValidationException( message );
86          }
87      }
88  }