From 0c499014d45b2dab7ec6784d983cb45147ab7428 Mon Sep 17 00:00:00 2001 From: nickAS21 Date: Thu, 25 Nov 2021 16:56:50 +0200 Subject: [PATCH] lwm2m - trust certificate, add get value by key from Subject Name --- .../lwm2m/secure/TbLwM2MDtlsCertificateVerifier.java | 10 +++------- .../transport/config/ssl/AbstractSslCredentials.java | 12 ++++++++++++ .../common/transport/config/ssl/SslCredentials.java | 1 + 3 files changed, 16 insertions(+), 7 deletions(-) diff --git a/common/transport/lwm2m/src/main/java/org/thingsboard/server/transport/lwm2m/secure/TbLwM2MDtlsCertificateVerifier.java b/common/transport/lwm2m/src/main/java/org/thingsboard/server/transport/lwm2m/secure/TbLwM2MDtlsCertificateVerifier.java index 2251701e23..77d3aada6b 100644 --- a/common/transport/lwm2m/src/main/java/org/thingsboard/server/transport/lwm2m/secure/TbLwM2MDtlsCertificateVerifier.java +++ b/common/transport/lwm2m/src/main/java/org/thingsboard/server/transport/lwm2m/secure/TbLwM2MDtlsCertificateVerifier.java @@ -35,6 +35,7 @@ import org.springframework.beans.factory.annotation.Value; import org.springframework.stereotype.Component; import org.thingsboard.common.util.JacksonUtil; import org.thingsboard.server.common.data.DeviceProfile; +import org.thingsboard.server.common.data.StringUtils; import org.thingsboard.server.common.data.device.credentials.lwm2m.LwM2MSecurityMode; import org.thingsboard.server.common.data.device.credentials.lwm2m.X509ClientCredential; import org.thingsboard.server.common.msg.EncryptionUtil; @@ -57,7 +58,6 @@ import java.security.cert.CertificateNotYetValidException; import java.security.cert.X509Certificate; import java.util.Arrays; import java.util.List; -import java.util.Optional; import static org.thingsboard.server.transport.lwm2m.server.uplink.LwM2mTypeServer.CLIENT; @@ -121,12 +121,8 @@ public class TbLwM2MDtlsCertificateVerifier implements NewAdvancedCertificateVer // verify if trust if (config.getTrustSslCredentials().getTrustedCertificates().length > 0) { if (searchIssuer(cert, config.getTrustSslCredentials().getTrustedCertificates()) != null) { - String [] dns = cert.getSubjectX500Principal().getName().split(","); - Optional cn = (Arrays.stream(dns).filter(dn -> dn.contains("CN="))).findFirst(); - if (cn.isPresent() && cn.get().length()>3){ - String endpoint = cn.get().split("=")[1]; - securityInfo = securityInfoValidator.getEndpointSecurityInfoByCredentialsId(endpoint, CLIENT); - } + String endpoint = config.getTrustSslCredentials().getValueFromSubjectNameByKey(cert.getSubjectX500Principal().getName(), "CN"); + securityInfo = StringUtils.isNotEmpty(endpoint) ? securityInfoValidator.getEndpointSecurityInfoByCredentialsId(endpoint, CLIENT) : null; } } // if not trust or cert trust securityInfo == null diff --git a/common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/config/ssl/AbstractSslCredentials.java b/common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/config/ssl/AbstractSslCredentials.java index 792d46b475..8043396e8d 100644 --- a/common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/config/ssl/AbstractSslCredentials.java +++ b/common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/config/ssl/AbstractSslCredentials.java @@ -31,9 +31,11 @@ import java.security.UnrecoverableEntryException; import java.security.UnrecoverableKeyException; import java.security.cert.Certificate; import java.security.cert.X509Certificate; +import java.util.Arrays; import java.util.Collections; import java.util.Enumeration; import java.util.HashSet; +import java.util.Optional; import java.util.Set; public abstract class AbstractSslCredentials implements SslCredentials { @@ -113,6 +115,7 @@ public abstract class AbstractSslCredentials implements SslCredentials { return this.trusts; } + @Override public TrustManagerFactory createTrustManagerFactory() throws NoSuchAlgorithmException, KeyStoreException { TrustManagerFactory tmFactory = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm()); @@ -127,6 +130,15 @@ public abstract class AbstractSslCredentials implements SslCredentials { return kmf; } + + @Override + public String getValueFromSubjectNameByKey(String subjectName, String key) { + String[] dns = subjectName.split(","); + Optional cn = (Arrays.stream(dns).filter(dn -> dn.contains(key + "="))).findFirst(); + String value = cn.isPresent() ? cn.get().replace(key + "=", "") : null; + return StringUtils.isNotEmpty(value) ? value : null; + } + protected abstract boolean canUse(); protected abstract KeyStore loadKeyStore(boolean isPrivateKeyRequired, char[] keyPasswordArray) throws IOException, GeneralSecurityException; diff --git a/common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/config/ssl/SslCredentials.java b/common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/config/ssl/SslCredentials.java index c6207b877d..49152960fc 100644 --- a/common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/config/ssl/SslCredentials.java +++ b/common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/config/ssl/SslCredentials.java @@ -49,4 +49,5 @@ public interface SslCredentials { KeyManagerFactory createKeyManagerFactory() throws NoSuchAlgorithmException, UnrecoverableKeyException, KeyStoreException; + String getValueFromSubjectNameByKey(String subjectName, String key); }