/**
* This file is part of Graylog.
*
* Graylog is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* Graylog is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with Graylog. If not, see <http://www.gnu.org/licenses/>.
*/
package org.graylog2.shared.security.tls;
import com.google.common.io.Resources;
import org.junit.Test;
import java.net.URL;
import java.nio.file.Path;
import java.nio.file.Paths;
import java.security.Key;
import java.security.KeyStore;
import java.security.cert.Certificate;
import java.security.spec.PKCS8EncodedKeySpec;
import static org.assertj.core.api.Assertions.assertThat;
public class PemKeyStoreTest {
@Test
public void testGenerateKeySpec() throws Exception {
final URL url = Resources.getResource("org/graylog2/shared/security/tls/private.key");
final byte[] privateKey = PemReader.readPrivateKey(Paths.get(url.toURI()));
final PKCS8EncodedKeySpec keySpec = PemKeyStore.generateKeySpec(null, privateKey);
assertThat(keySpec.getFormat()).isEqualTo("PKCS#8");
assertThat(keySpec.getEncoded()).isEqualTo(privateKey);
}
@Test
public void testGenerateKeySpecFromSecurePrivateKey() throws Exception {
final URL url = Resources.getResource("org/graylog2/shared/security/tls/secure.key");
final byte[] privateKey = PemReader.readPrivateKey(Paths.get(url.toURI()));
final PKCS8EncodedKeySpec keySpec = PemKeyStore.generateKeySpec("password".toCharArray(), privateKey);
assertThat(keySpec.getFormat()).isEqualTo("PKCS#8");
assertThat(keySpec.getEncoded()).isNotEmpty();
}
@Test
public void testBuildKeyStore() throws Exception {
final Path certChainFile = Paths.get(Resources.getResource("org/graylog2/shared/security/tls/chain.crt").toURI());
final Path keyFile = Paths.get(Resources.getResource("org/graylog2/shared/security/tls/private.key").toURI());
final KeyStore keyStore = PemKeyStore.buildKeyStore(certChainFile, keyFile, null);
final Certificate[] keys = keyStore.getCertificateChain("key");
assertThat(keys).hasSize(2);
final Key key = keyStore.getKey("key", new char[0]);
assertThat(key.getFormat()).isEqualTo("PKCS#8");
assertThat(key.getEncoded()).isNotEmpty();
}
@Test
public void testBuildKeyStoreWithSecuredPrivateKey() throws Exception {
final Path certChainFile = Paths.get(Resources.getResource("org/graylog2/shared/security/tls/chain.crt").toURI());
final Path keyFile = Paths.get(Resources.getResource("org/graylog2/shared/security/tls/secure.key").toURI());
final KeyStore keyStore = PemKeyStore.buildKeyStore(certChainFile, keyFile, "password".toCharArray());
final Certificate[] keys = keyStore.getCertificateChain("key");
assertThat(keys).hasSize(2);
final Key key = keyStore.getKey("key", "password".toCharArray());
assertThat(key.getFormat()).isEqualTo("PKCS#8");
assertThat(key.getEncoded()).isNotEmpty();
}
}