/*
* Copyright 2006 Sun Microsystems, Inc. All Rights Reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
*
* - Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
*
* - Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
*
* - Neither the name of Sun Microsystems nor the names of its
* contributors may be used to endorse or promote products derived
* from this software without specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS
* IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
* THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
* PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR
* CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
* EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
* PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
* PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
* LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
* NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/importjava.io.BufferedReader;importjava.io.File;importjava.io.FileInputStream;importjava.io.FileOutputStream;importjava.io.InputStream;importjava.io.InputStreamReader;importjava.io.OutputStream;importjava.security.KeyStore;importjava.security.MessageDigest;importjava.security.cert.CertificateException;importjava.security.cert.X509Certificate;importjavax.net.ssl.SSLContext;importjavax.net.ssl.SSLException;importjavax.net.ssl.SSLSocket;importjavax.net.ssl.SSLSocketFactory;importjavax.net.ssl.TrustManager;importjavax.net.ssl.TrustManagerFactory;importjavax.net.ssl.X509TrustManager;publicclassInstallCert{publicstaticvoidmain(String[]args)throwsException{Stringhost;intport;char[]passphrase;if((args.length==1)||(args.length==2)){String[]c=args[0].split(":");host=c[0];port=(c.length==1)?443:Integer.parseInt(c[1]);Stringp=(args.length==1)?"changeit":args[1];passphrase=p.toCharArray();}else{System.out.println("Usage: java InstallCert [:port] [passphrase]");return;}Filefile=newFile("jssecacerts");if(file.isFile()==false){charSEP=File.separatorChar;Filedir=newFile(System.getProperty("java.home")+SEP+"lib"+SEP+"security");file=newFile(dir,"jssecacerts");if(file.isFile()==false){file=newFile(dir,"cacerts");}}System.out.println("Loading KeyStore "+file+"...");InputStreamin=newFileInputStream(file);KeyStoreks=KeyStore.getInstance(KeyStore.getDefaultType());ks.load(in,passphrase);in.close();SSLContextcontext=SSLContext.getInstance("TLS");TrustManagerFactorytmf=TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());tmf.init(ks);X509TrustManagerdefaultTrustManager=(X509TrustManager)tmf.getTrustManagers()[0];SavingTrustManagertm=newSavingTrustManager(defaultTrustManager);context.init(null,newTrustManager[]{tm},null);SSLSocketFactoryfactory=context.getSocketFactory();System.out.println("Opening connection to "+host+":"+port+"...");SSLSocketsocket=(SSLSocket)factory.createSocket(host,port);socket.setSoTimeout(10000);try{System.out.println("Starting SSL handshake...");socket.startHandshake();socket.close();System.out.println();System.out.println("No errors, certificate is already trusted");}catch(SSLExceptione){System.out.println();e.printStackTrace(System.out);}X509Certificate[]chain=tm.chain;if(chain==null){System.out.println("Could not obtain server certificate chain");return;}BufferedReaderreader=newBufferedReader(newInputStreamReader(System.in));System.out.println();System.out.println("Server sent "+chain.length+" certificate(s):");System.out.println();MessageDigestsha1=MessageDigest.getInstance("SHA1");MessageDigestmd5=MessageDigest.getInstance("MD5");for(inti=0;i<chain.length;i++){X509Certificatecert=chain[i];System.out.println(" "+(i+1)+" Subject "+cert.getSubjectDN());System.out.println(" Issuer "+cert.getIssuerDN());sha1.update(cert.getEncoded());System.out.println(" sha1 "+toHexString(sha1.digest()));md5.update(cert.getEncoded());System.out.println(" md5 "+toHexString(md5.digest()));System.out.println();}System.out.println("Enter certificate to add to trusted keystore or 'q' to quit: [1]");Stringline=reader.readLine().trim();intk;try{k=(line.length()==0)?0:Integer.parseInt(line)-1;}catch(NumberFormatExceptione){System.out.println("KeyStore not changed");return;}X509Certificatecert=chain[k];Stringalias=host+"-"+(k+1);ks.setCertificateEntry(alias,cert);OutputStreamout=newFileOutputStream("jssecacerts");ks.store(out,passphrase);out.close();System.out.println();System.out.println(cert);System.out.println();System.out.println("Added certificate to keystore 'jssecacerts' using alias '"+alias+"'");}privatestaticfinalchar[]HEXDIGITS="0123456789abcdef".toCharArray();privatestaticStringtoHexString(byte[]bytes){StringBuildersb=newStringBuilder(bytes.length*3);for(intb:bytes){b&=0xff;sb.append(HEXDIGITS[b>>4]);sb.append(HEXDIGITS[b&15]);sb.append(' ');}returnsb.toString();}privatestaticclassSavingTrustManagerimplementsX509TrustManager{privatefinalX509TrustManagertm;privateX509Certificate[]chain;SavingTrustManager(X509TrustManagertm){this.tm=tm;}publicX509Certificate[]getAcceptedIssuers(){thrownewUnsupportedOperationException();}publicvoidcheckClientTrusted(X509Certificate[]chain,StringauthType)throwsCertificateException{thrownewUnsupportedOperationException();}publicvoidcheckServerTrusted(X509Certificate[]chain,StringauthType)throwsCertificateException{this.chain=chain;tm.checkServerTrusted(chain,authType);}}}
new MyException(key+“:”+e.getMessage);
new MyException(key, e);
原則:print Exception Stack, not just message
原則:
If a client can reasonably be expected to recover from an exception, make it a checked exception. If a client cannot do anything to recover from the exception, make it an unchecked exception.