149 lines
7.3 KiB
149 lines
7.3 KiB
* Copyright (c) 2022, Oracle and/or its affiliates. All rights reserved.
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
package org.openjdk.bench.java.security;
import java.io.ByteArrayInputStream;
import java.io.IOException;
import java.nio.charset.StandardCharsets;
import java.security.GeneralSecurityException;
import java.security.Key;
import java.security.KeyFactory;
import java.security.KeyStore;
import java.security.cert.Certificate;
import java.security.cert.CertificateFactory;
import java.security.spec.PKCS8EncodedKeySpec;
import java.util.Base64;
* This class contains a 3-certificate chain for use in TLS tests.
* The method {@link #getKeyStore()} returns a keystore with a single entry
* containing one server+one intermediate CA certificate.
* Server's CN and subjectAltName are both set to "client"
* The method {@link #getTrustStore()} returns a keystore with a single entry
* containing the root CA certificate used for signing the intermediate CA.
class TestCertificates {
// "/C=US/ST=CA/O=Test Root CA, Inc."
// basicConstraints=critical, CA:true
// subjectKeyIdentifier = hash
// authorityKeyIdentifier = keyid:always
// keyUsage = keyCertSign
private static final String ROOT_CA_CERT =
"-----BEGIN CERTIFICATE-----\n" +
"Q0EsIEluYy4wIBcNMjIwNDEyMDcxMzMzWhgPMjEyMjAzMTkwNzEzMzNaMDcxCzAJ\n" +
"bmMuMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEBKye/mwO0V0WLr71tf8auFEz\n" +
"EmqhaYWauaP17Fb33fRAeG8aVp9c4B0isv/VgcqSTRMG0SJjbx7ttSYwR/JNhqNg\n" +
"J8zpAiEAzbZQsC/IZ0wVNd4lqHn6/Ih5v7vhCgkg95KCP1NhBnU=\n" +
"-----END CERTIFICATE-----";
// "/C=US/ST=CA/O=Test Intermediate CA, Inc."
// basicConstraints=critical, CA:true, pathlen:0
// subjectKeyIdentifier = hash
// authorityKeyIdentifier = keyid:always
// keyUsage = keyCertSign
private static final String CA_CERT =
"-----BEGIN CERTIFICATE-----\n" +
"Q0EsIEluYy4wIBcNMjIwNDEyMDcxMzM0WhgPMjEyMjAzMTkwNzEzMzRaMD8xCzAJ\n" +
"Wx0gf40N+H/F75w1YmPm6dp2wiQ6JPMN/4En87Ylx0ISJkeXJLxrbLvu2xZ+aonM\n" +
"aivot/zWSMKr8ZkCVzAfBgNVHSMEGDAWgBSl8a3huNp2ZXNZ5cCJIyn2ktREyTAL\n" +
"X+kOc4LGE0R7sMiBAbXuAiBlbNVaskKYRHIEGHEtIWet6Ufi3w9NMrycEbBZ+v5o\n" +
"gA==\n" +
"-----END CERTIFICATE-----";
// "/C=US/ST=CA/O=Test Server/CN=client"
// subjectKeyIdentifier = hash
// authorityKeyIdentifier = keyid:always
// keyUsage = digitalSignature
// subjectAltName = DNS:client
private static final String SERVER_CERT =
"-----BEGIN CERTIFICATE-----\n" +
"MIIB5TCCAYygAwIBAgIUNWe754lZoDc6wNs9Vsev/h9TMicwCgYIKoZIzj0EAwIw\n" +
"o6zUz5QmzmfHL2xRifvaJenggck/Dlu6KC4v4rGXug69R7tWKWuRUsbSFLy29Rii\n" +
"F7V1wjFhsyGAzNyKf/KlmaNiMGAwHQYDVR0OBBYEFHz32VSnXBF4WdLDOe7e3hF9\n" +
"yDxmMB8GA1UdIwQYMBaAFOo/qEHkhutqK+i3/NZIwqvxmQJXMAsGA1UdDwQEAwIH\n" +
"VihcQznvBemWneEcmnp/Bw+lwk86KQ8CIA3loL7P/0/Ft/xXtClxJfyxEoZ/Az1n\n" +
"HTTjbe6ZnN0Y\n" +
"-----END CERTIFICATE-----";
private static final String serverkey =
//"-----BEGIN PRIVATE KEY-----\n" +
"cdCLHpD0poPJ/uAkafGXDJBR67ChRANCAASjrNTPlCbOZ8cvbFGJ+9ol6eCByT8O\n" +
// + "\n-----END PRIVATE KEY-----";
private TestCertificates() {}
public static KeyStore getKeyStore() throws GeneralSecurityException, IOException {
KeyStore result = KeyStore.getInstance("JKS");
result.load(null, null);
CertificateFactory cf = CertificateFactory.getInstance("X.509");
Certificate serverCert = cf.generateCertificate(
new ByteArrayInputStream(
Certificate caCert = cf.generateCertificate(
new ByteArrayInputStream(
KeyFactory kf = KeyFactory.getInstance("EC");
PKCS8EncodedKeySpec ks = new PKCS8EncodedKeySpec(
Key key = kf.generatePrivate(ks);
Certificate[] chain = {serverCert, caCert};
result.setKeyEntry("server", key, new char[0], chain);
return result;
public static KeyStore getTrustStore() throws GeneralSecurityException, IOException {
KeyStore result = KeyStore.getInstance("JKS");
result.load(null, null);
CertificateFactory cf = CertificateFactory.getInstance("X.509");
Certificate rootcaCert = cf.generateCertificate(
new ByteArrayInputStream(
result.setCertificateEntry("testca", rootcaCert);
return result;