1 package org.cacert.gigi.api;
3 import static org.junit.Assert.*;
5 import java.io.ByteArrayInputStream;
6 import java.io.IOException;
7 import java.io.InputStreamReader;
8 import java.io.OutputStream;
9 import java.net.HttpURLConnection;
11 import java.net.URLEncoder;
12 import java.security.GeneralSecurityException;
13 import java.security.KeyPair;
14 import java.security.PrivateKey;
15 import java.security.cert.CertificateFactory;
16 import java.security.cert.X509Certificate;
18 import org.cacert.gigi.dbObjects.Certificate;
19 import org.cacert.gigi.dbObjects.Certificate.CSRType;
20 import org.cacert.gigi.dbObjects.Certificate.CertificateStatus;
21 import org.cacert.gigi.dbObjects.CertificateProfile;
22 import org.cacert.gigi.dbObjects.Digest;
23 import org.cacert.gigi.dbObjects.Domain;
24 import org.cacert.gigi.dbObjects.Group;
25 import org.cacert.gigi.dbObjects.Name;
26 import org.cacert.gigi.dbObjects.Organisation;
27 import org.cacert.gigi.testUtils.ClientTest;
28 import org.cacert.gigi.testUtils.IOUtils;
29 import org.junit.Test;
31 import sun.security.x509.X500Name;
33 public class IssueCert extends ClientTest {
35 private final PrivateKey pk;
37 private final X509Certificate ce;
39 private final Certificate c;
41 private final KeyPair kp;
45 kp = generateKeypair();
46 String key1 = generatePEMCSR(kp, "EMAIL=testmail@example.com");
47 c = new Certificate(u, u, Certificate.buildDN("EMAIL", "testmail@example.com"), Digest.SHA256, key1, CSRType.CSR, CertificateProfile.getById(1));
49 await(c.issue(null, "2y", u));
51 } catch (Exception e) {
57 public void testIssueCert() throws Exception {
58 String cert = issueCert(generatePEMCSR(kp, "EMAIL=" + email + ",CN=CAcert WoT User"), "profile=client");
60 CertificateFactory cf = CertificateFactory.getInstance("X509");
61 java.security.cert.X509Certificate xcert = (X509Certificate) cf.generateCertificate(new ByteArrayInputStream(cert.getBytes("UTF-8")));
62 assertEquals("CAcert WoT User", ((X500Name) xcert.getSubjectDN()).getCommonName());
67 public void testRevoke() throws Exception {
68 revoke(c.getSerial().toLowerCase());
69 assertEquals(CertificateStatus.REVOKED, c.getStatus());
73 public void testIssueCertAssured() throws Exception {
77 String whishName = n.getFname() + " " + n.getLname();
78 String cert = issueCert(generatePEMCSR(kp, "EMAIL=" + email + ",CN=" + whishName), "profile=client-a");
80 CertificateFactory cf = CertificateFactory.getInstance("X509");
81 java.security.cert.X509Certificate xcert = (X509Certificate) cf.generateCertificate(new ByteArrayInputStream(cert.getBytes("UTF-8")));
82 assertEquals(whishName, ((X500Name) xcert.getSubjectDN()).getCommonName());
87 public void testIssueOrgCert() throws Exception {
89 u.grantGroup(u, Group.ORGASSURER);
91 Organisation o1 = new Organisation("name", "st", "pr", "st", "test@mail", "", "", u);
92 o1.addAdmin(u, u, false);
93 String testdom = createUniqueName() + "-example.com";
94 Domain d2 = new Domain(u, o1, testdom);
97 String whishName = createUniqueName();
98 String cert = issueCert(generatePEMCSR(kp, "EMAIL=test@" + testdom + ",CN=" + whishName), "profile=client-orga&asOrg=" + o1.getId());
100 CertificateFactory cf = CertificateFactory.getInstance("X509");
101 java.security.cert.X509Certificate xcert = (X509Certificate) cf.generateCertificate(new ByteArrayInputStream(cert.getBytes("UTF-8")));
102 assertEquals(whishName, ((X500Name) xcert.getSubjectDN()).getCommonName());
106 private String issueCert(String csr, String options) throws IOException, GeneralSecurityException {
107 HttpURLConnection connection = (HttpURLConnection) new URL("https://" + getServerName().replaceFirst("^www.", "api.") + CreateCertificate.PATH).openConnection();
108 authenticateClientCert(pk, ce, connection);
109 connection.setDoOutput(true);
110 OutputStream os = connection.getOutputStream();
111 os.write((options + "&csr=" + URLEncoder.encode(csr, "UTF-8")).getBytes("UTF-8"));
113 assertEquals(connection.getResponseMessage(), 200, connection.getResponseCode());
114 String cert = IOUtils.readURL(new InputStreamReader(connection.getInputStream(), "UTF-8"));
118 private void revoke(String serial) throws IOException, GeneralSecurityException {
119 HttpURLConnection connection;
121 connection = (HttpURLConnection) new URL("https://" + getServerName().replaceFirst("^www.", "api.") + "/account/certs/revoke").openConnection();
122 authenticateClientCert(pk, ce, connection);
123 connection.setDoOutput(true);
124 os = connection.getOutputStream();
125 os.write(("serial=" + URLEncoder.encode(serial, "UTF-8")).getBytes("UTF-8"));
127 assertEquals(connection.getResponseCode(), 200);